Public-employee reporting.
Design v0.1 · Draft · 2026-08-30 · Insider submission path not yet enabled
A DPW inspector who saw the deferred-maintenance list. A city IT manager who knows which forms are broken. A school facilities lead who knows the elevator inspection lapsed. A public housing authority employee who can identify which units have mold. Public employees frequently know infrastructure failures that residents cannot see, and the internal channels for surfacing those failures often don’t work — either because the failure implicates the reporter’s supervisor, or because the internal process routes to the same office that created the problem. This page is Fault Line’s design commitment for how public employees can safely report infrastructure conditions through the platform.
This is not a whistleblower channel in the specialized sense. Fault Line is not equipped to handle classified information, allegations of criminal misconduct against named individuals, personnel grievances, or claims of retaliation. Those categories require specialized legal counsel and dedicated whistleblower channels — not a civic infrastructure app. This page is about a narrower and useful thing: allowing public employees to file the same kind of infrastructure-condition report residents file, with additional insider context, under a safer submission model. We take that narrow scope seriously precisely because we don’t want to promise more than we can deliver.
1. What’s in scope, what’s out of scope
✓ In scope
- Physical infrastructure conditions the employee observed in the course of work (deteriorated road segments, failing bridges, broken accessibility features)
- Facility safety issues (broken elevators, expired inspections, ADA-noncompliant remediation)
- Digital infrastructure failures the employee has internal visibility into (forms known to be broken, systems that have been reported and ignored)
- Environmental hazards observed in the course of work (chemical spills that weren’t remediated, air-quality issues in facilities)
- Access, equity, and language-access failures observed in service delivery (residents turned away, applications rejected without meaningful review)
- Public health infrastructure gaps observed in the course of work
✗ Out of scope
- Personnel grievances (hostile work environment, harassment, discrimination against you personally) — go to state EEOC / civil rights office / union counsel
- Allegations of criminal misconduct against named individuals — go to state Inspector General, Attorney General’s office, or FBI
- Classified or security-sensitive information
- Retaliation claims — consult a licensed whistleblower attorney; state and federal whistleblower protections have specific procedural requirements
- Policy disagreements or budget allocation disputes (these are not infrastructure failures — they’re political questions)
- Anything you have a duty of confidentiality about (attorney work-product, HIPAA-covered medical records, personnel records of others)
2. The legal-protection landscape — briefly
Whistleblower protections for public employees vary enormously by state, level of government, and category of report. A partial summary of what’s generally true:
- Federal-level public employees have protections under the Whistleblower Protection Act (5 U.S.C. § 2302) with specific procedural requirements filed through the Office of Special Counsel or Merit Systems Protection Board.
- State and municipal public employees are covered by state whistleblower protection statutes. Massachusetts has M.G.L. c. 149, § 185; Rhode Island has the Rhode Island Whistleblowers’ Protection Act (R.I. Gen. Laws § 28-50-1 et seq.); New Hampshire has RSA 275-E. All three protect employees who report violations of law, rule, or regulation.
- Reports “in the course of official duties” are treated differently from independent reports. Under Garcetti v. Ceballos (547 U.S. 410, 2006), speech pursuant to official duties is not protected by the First Amendment, even if it exposes government wrongdoing. State whistleblower statutes generally provide broader protection than the First Amendment does, but the interaction is jurisdiction-specific.
- Anonymous reporting does not by itself create legal protection. If an employer discovers the source of an anonymous report, retaliation is still legally actionable but requires evidence, which anonymity by design makes harder to establish.
Consult an attorney before making an insider report if you have any concern about retaliation. The National Whistleblower Center (whistleblowers.org) and Government Accountability Project (whistleblower.org) both maintain referral networks for whistleblower attorneys and provide guidance on how to preserve legal protections. Fault Line is not a substitute for that counsel.
3. What Fault Line can and cannot do technically
What we can do
- Accept reports with no account, no PII. Anonymous reporting is a first-class citizen on Fault Line for every report type. Insider reports are just a category of anonymous report with additional context fields.
- Avoid logging IP addresses of anonymous submitters. The submission path can be configured to strip IP at the edge before the request hits our application layer. Standard practice, but worth naming.
- Accept submissions over Tor. Fault Line’s public web app is reachable via Tor Browser without special configuration. We do not block Tor exit nodes; we do not require CAPTCHAs that would fail under Tor.
- Strip metadata from uploaded evidence. Photos submitted with a report can have EXIF metadata (GPS coordinates, device model, timestamps) stripped before storage. Insider reporters concerned about metadata can request stripping at submission time.
- Provide a public URL for the report that’s indistinguishable from a resident report at the URL level. Nothing in the public presentation identifies a report as from an insider.
What we cannot do
- Guarantee legal protection. Legal whistleblower protection comes from state and federal statutes, not from technical anonymity. Anonymous submission is not the same as legally protected disclosure.
- Guarantee absolute technical anonymity. We commit to industry-standard privacy practices (no IP logging, HTTPS-only, Tor-compatible). But no online service can guarantee that a determined adversary with subpoena power, network-level observation, or a browser exploit couldn’t identify a specific submitter. If your safety depends on absolute technical anonymity, use a dedicated leaks platform designed for that threat model (SecureDrop, GlobaLeaks) — not Fault Line.
- Verify the source without identifying you. A resident report gets verified by other residents in the same neighborhood. An insider report can’t be verified that way — the whole point is that residents can’t see the problem. We can accept the report, but its evidentiary weight is different from a community-verified resident report.
- Route around normal escalation. Insider reports go through the same escalation pipeline as resident reports. That means the responsible authority receives the report. If the responsible authority is the source of the problem the insider is reporting, that’s a limitation Fault Line cannot solve alone — it’s where the Inspector General / Attorney General / independent oversight channels become necessary.
4. Additional context fields (optional) for insider reports
Insider reporters can optionally attach context that residents can’t — without revealing identity:
- Category of insider knowledge: which functional area gives the reporter visibility (public works · IT · facilities · public housing · transit · etc.). Not a role, not an employer — a category.
- Duration of the observed condition: “this has been on the deferred-maintenance list for 18 months” is context a resident cannot provide.
- Prior internal reports: “this was reported through internal channel X on approximately Y date; no visible response” establishes the failure of internal remediation.
- Documentary reference: a redacted work order number, inspection reference, or budget-line identifier that a knowledgeable recipient could look up on their side.
These fields are optional. Insider reporters concerned about identification through granular context can omit them without penalty — the underlying infrastructure observation is still submittable as a plain report.
5. What happens to an insider report
- Enters the report queue as anonymous. No public marker distinguishes it from a resident report.
- Cluster analysis runs normally. If the observation aligns with existing resident reports, it’s counted toward the cluster verification threshold — residents plus insider observation is stronger evidence than either alone.
- Escalation runs normally. When threshold conditions are met, the responsible authority receives the escalation. Insider context (if provided) is included in the demand-letter body as part of the observation narrative.
- Response tracking runs normally. Statutory deadlines apply. Rapid Response Roll qualifies. Shame Index calculation includes.
- If the insider report doesn’t align with any existing cluster (i.e., no resident has yet observed this), the report sits in the map with a longer verification window — up to 180 days — giving residents time to independently observe. If no confirmation arrives, the report expires without escalation. Insider-only observations without any resident confirmation are not sufficient for a demand letter.
6. Your rights matter more than this feature
Before you file
Check your state’s whistleblower protection statute. If you’re in MA, RI, or NH: the statutes cited above generally protect reports of “violations of law, rule, or regulation.” A dangerous infrastructure condition that violates a statutory duty (defective highway statute, ADA compliance, HUD Housing Quality Standards) qualifies. A policy disagreement about budget priorities does not.
Preserve evidence separately from the Fault Line submission. If your report ever becomes the basis of a formal complaint or a legal action, you may need to authenticate the underlying observations. Keep dated notes in a location outside your employer’s systems. Do not use employer email or employer-issued devices for anything related to the report.
Consult a whistleblower attorney if there is any risk of retaliation. Both the National Whistleblower Center and the Government Accountability Project maintain attorney referral networks. Many whistleblower attorneys offer a free initial consultation.
Do not send Fault Line documents you have a duty of confidentiality about. Attorney-client materials, HIPAA-covered records, personnel records of other employees, and classified information are not appropriate for a Fault Line submission and can create liability for the reporter. Describe the underlying infrastructure condition; do not send internal documents.
7. Guardrails
- Nothing on this page implies protection Fault Line cannot deliver. Technical anonymity is not legal protection. Every relevant assertion above is qualified honestly.
- No named individuals in insider reports. The reporting flow rejects submissions that name specific individuals as the target of the report. Fault Line is documenting infrastructure conditions, not accusing employees.
- No use as a personnel-grievance channel. The reporting flow surfaces the “out of scope” list at submission time. Attempted submissions in out-of-scope categories are refused with an explanation and referral to the appropriate channel (state EEOC, Inspector General, union counsel).
- Right of reply preserved for authorities. Insider-context reports that escalate include the same 24-hour authority pre-notification as press-summary flows (see /briefing-packets). Authorities can respond, dispute, or correct before public distribution.
- No public identification of insider category. The reporting UI collects insider-context fields optionally, but the fields are not displayed publicly. They’re used to enrich the demand letter and internal cluster analysis; they don’t appear on the resident-facing map.
8. What still needs to happen before this ships
- Legal review of the whistleblower-protection landscape in MA / RI / NH, and by extension the other states in Fault Line’s coverage roadmap. Same qualified-reviewer standard as the statute dataset (attorney admitted in the state, or a credentialed legal researcher with whistleblower-protection specialization).
- Additional context fields in the report submission schema (insider-category enum, duration observation, prior-internal-report reference field, documentary-reference free-text field).
- Longer verification window (up to 180 days) for insider-only observations that lack resident confirmation.
- EXIF-stripping option in the photo upload flow.
- Confirmation the public web app is fully usable over Tor (already largely the case, but formal verification needed).
- Referral copy in the reporting UI: for out-of-scope categories, direct users to the appropriate channel with jurisdiction-specific links.
Full engineering scope in DEFERRED.md #29.
9. Grant relevance
Insider infrastructure reporting is a genuine gap in the civic-tech landscape. Government transparency and accountability funders (Sunlight Foundation successor orgs, OpenGov Foundation, Knight Foundation democracy programs) have historically funded whistleblower-adjacent infrastructure. Fault Line’s carefully-scoped approach — infrastructure only, honest technical claims, referral to real whistleblower counsel for anything larger — is a more grant-worthy posture than tools that overclaim what they can protect.
Not legal advice. This page describes Fault Line’s design commitments for a specific report type; it does not create legal rights, does not establish an attorney-client relationship, and does not substitute for consultation with a licensed whistleblower attorney. Legal protection for public-employee reporting varies by state, level of government, and category of report — consult qualified counsel before acting on anything described here.