Skip to content
DocGen
Trust, compliance & configuration

The questions your solicitor will ask.

DocGen handles public records, so it's built like one: a full audit trail, records that can't quietly change, and every rule configurable to your jurisdiction. Here's exactly how.

Record integrity

Audit & the meeting record

Public business deserves a record no one can quietly change. DocGen enforces that at the server, not just in the interface.

Is there an audit trail?
Yes — on everything. Every lifecycle action (submit, approve, publish, start, end, reopen), every vote, motion, walk-on item, public comment, and every edit to the minutes is logged with who did it, when, and the detail. The full history is one click from any meeting, and entries that modify an already-final record are flagged.
Can a published agenda be quietly edited?
No. Once an agenda publishes, it's final — editing requires pulling it back to draft, and that action is always written to the audit log. Jurisdictions whose rules require it can turn on a stricter setting: modifying a published agenda then requires a recorded motion (mover, seconder, and outcome), which is captured in the history verbatim.
What happens to the record when the meeting ends?
It seals. After the clerk ends a meeting, nothing about it can be changed — not the agenda, not the votes, not the comments. The software rejects the change at the server even if someone bypasses the interface.
Can a sealed record ever be corrected?
Only deliberately, and never silently. An administrator can reopen a concluded meeting — a reason is required and the reopening is permanently logged — make the correction, and re-close it. Amendments to the written minutes are likewise allowed after conclusion (clerks correct minutes in the real world) and every amendment is logged as a modification of the record.
Can a meeting be deleted?
Draft meetings, yes — they're working documents. Once a meeting publishes it becomes part of the record and can no longer be deleted, only unpublished (logged) or carried through to conclusion.
What happens when a board member leaves office?
You retire them, and the record does the right thing on its own. A retired member disappears from new roll calls, but every past vote, motion, and second keeps their name — marked as retired on old records. Members with recorded votes can't be deleted at all; the roster refuses, because a roll call should never lose a name.
Is there a review step before an agenda goes public?
If your rules call for one. With the approval workflow on, one person submits the agenda and a different person must approve it before it can publish — the submitter can never approve their own work, and the agenda is locked against edits while it's under review so the approval covers exactly what was reviewed.
Are the minutes archival quality? Our retention schedule says PDF/A.
Yes. Minutes are permanent-retention records in most states, so DocGen renders them as PDF/A-2b (ISO 19005-2) — fonts embedded, color profile included, archival metadata stamped — the format state records programs direct permanent electronic records to. No extra step: every minutes download is the archival copy.
How do we get the record OUT — for our records office, or if we ever leave?
One click per meeting: the records archive is a ZIP holding the PDF/A minutes (official and redacted public copies), every exhibit exactly as uploaded plus its sealed redacted version, the audit trail, the public-comment record, and a SHA-256 manifest — so an auditor can verify no file changed after export. Your record is yours; there is no lock-in by design. The Records Vault add-on goes further: every concluded meeting auto-replicates its archive to storage your own IT controls (any S3-compatible bucket).
Transparency

Public records & open meetings

Built for boards that operate under open-meeting and public-records laws — the public side is a first-class surface, not an afterthought.

What do residents see?
A clean public reader with the published agenda, the plain-language summaries, and — if you enable them — the exhibits, roll-call results, and public comment. During a live meeting the reader updates on its own: votes, motions, and walk-on items appear as they're recorded, no refreshing. Drafts and internal working notes never appear publicly: the server strips them from the public payload rather than hiding them in the browser.
Are the minutes public?
That's your call, reflected in one setting. Turn on public minutes and the recap becomes readable by residents automatically once the meeting concludes — matching the disclosure many jurisdictions are required to make. Leave it off and the recap stays internal, shareable manually as a branded PDF.
How is public comment handled?
Public comment is part of the record in every view. It can be captured per meeting or against a specific agenda item, optionally with the speaker's address for jurisdictions that record it, and it's woven into the AI-drafted recap alongside the motions and votes.
Does the live meeting show publicly?
Yes — a published agenda stays visible to residents while the meeting runs and after it concludes. The record never disappears from public view once it's out.
Was this designed with Sunshine / open-meeting laws in mind?
Yes. The lifecycle (draft → review → published → live → concluded), the sealed record, the audit trail, public comment capture, and the public-minutes option all map to how open-meeting law expects public bodies to operate. And because rules differ by state and by body, each of those behaviors is configurable per jurisdiction.
Privacy & security

Keeping the private parts private

Not everything in a packet belongs in public — and jurisdictions shouldn't share anything with each other.

How do we keep sensitive material out of the public view?
Three layers. Individual agenda items can be marked non-public. Exhibits can be redacted — draw a box over anything private and the public is served a permanently blacked-out copy while your board keeps the original. And the public data feed is filtered on the server, so nothing internal ever reaches a resident's browser to begin with.
Is our data isolated from other jurisdictions?
Completely. Every workspace is scoped to its own jurisdiction — users, meetings, documents, settings, and usage are partitioned per tenant, and every query runs inside that scope. One login can belong to multiple jurisdictions (a solicitor who serves two townships, say), but each membership has its own role and sees only its own workspace.
Who can do what?
Roles are enforced on the server. Administrators and clerks author and run meetings; board members read the packet, keep private notes, and see the internal record; viewers read internally; residents get the public view. Board members' personal notes are private to each member — they're not part of the record and no one else sees them.
Where does the data live?
On Cloudflare's network — the application, database, and document storage all run there, encrypted in transit. Each jurisdiction's documents are stored under its own workspace and served only through the permission checks above.
AI

What the AI does — and doesn't

AI does the busywork. People make the decisions and own the record.

What does the AI actually do?
It drafts. It reads your uploaded packet documents and proposes agenda lines, motions, and clerk's notes; it drafts plain-language summaries for residents; it answers questions grounded in the exhibit with page citations; and it drafts the recap from the recorded motions, roll calls, and comments. Every draft lands in front of a person for review.
Can the AI publish or change the record on its own?
No. The AI never publishes, votes, approves, or modifies the record. Publishing, starting and ending meetings, and every write to the record are human actions — gated by role, gated by lifecycle phase, and logged.
Is our data used to train AI models?
No. Documents are processed through Anthropic's Claude API, which does not use customer API data to train its models. Your packet stays your packet.
What if the AI gets something wrong?
That's why the workflow is review-first: generated items carry a confidence indicator and a reviewed/unreviewed status, unreviewed AI content is withheld from the public view, and an optional pre-publish readiness check flags gaps — like a motion without a mover — before the agenda goes out.
Configuration

Configured to your jurisdiction's rules

No two boards run meetings the same way. The rules above aren't hard-coded — they're settings your administrator controls.

Which rules can we configure?

Most of them. Each jurisdiction's administrator controls, among others:

  • Whether publishing requires a second person's approval
  • Whether modifying a published agenda requires a recorded motion
  • Whether the recap generates automatically when the meeting ends
  • Whether the minutes become public once the meeting concludes
  • The ballot itself — aye, nay, abstain, recuse, absent, present — and whether motions need a mover and seconder
  • Whether items can be added during a live meeting, and whether doing so requires a motion
  • Whether tabling an item or adjourning early requires a recorded vote
  • What the public sees — exhibits, roll-call results, public comment — and how the public reader presents
  • Section numbering style, nested sub-items, agenda templates, and public-comment capture rules
Can it carry our name and letterhead?
Yes. Your jurisdiction's name, logo, and letterhead lines appear across the workspace, the public reader, and every exported packet and minutes PDF — it presents as your system of record.
We're a small township. Is this overkill?
The defaults are deliberately simple: draft the agenda, publish it, run the meeting, get the recap. The compliance machinery — approvals, motions to modify, public minutes — switches on only if your rules need it.

Have a question we didn't cover?

Ask us directly — or open a meeting and see the audit trail for yourself.