Product Enhancements
1.1 New Consultations Workflow
ID# 1275604
We have introduced a new approach to Consultations by enabling page-level selections in a more efficient UI.
There are separate permissions for the old workflow and the new workflow, enabling you to use the new workflow from certain areas while still using the old workflow from other areas.

To enable the old Consultations workflow, navigate to Administration> Document Management> File Cabinet Drawer Roles> Role and select Send/Save Consultations. Click Save. If you use consultations, you must enable this permission.
Similarly, to enable the new Consultations workflow, navigate to Administration> Document
Management> File Cabinet Drawer Roles> Role and select Page-level Consultations. Click
Save. This will enable the new page-level workflow from only specific areas. You must also have the Send/Save Consultations permission enabled.
Once a consultation package has been created for a request, there will be a tab called Consultations within the request that allows you to manage the consultations.
There are two ways to create a consultation package:
Search and select documents from Document Management. Select one or more pages, or a document, and right-click to select Save/Send for Consultation.
Alternatively, from within a request, using the Review Log, select one or more documents and click on open documents. Then select one or more pages, or a document, and right-click to select Save/Send for Consultation
Click the Plus button to create a new consultation package
Complete the rest of the form and details, then click Save
You can now manage these consultations from the Consultations tab from within a request with the following capabilities:
You can withdraw a consultation package that has already been sent from the Consultation tab
You can add more documents to an existing package
To remove pages from a consultation package which has not been sent or has been withdrawn, click on the Consultations tab within the request, and click Edit

Click the Gear icon to delete or modify pages. You can also modify package details such as Program Office, Consultation Mode, etc.
You can delete page-level and legacy (old workflow) consultation packages directly from the Consultations grid if they have not been sent or if they have been withdrawn
The Consultations grid now includes all page-level and legacy (old workflow) consultations, along with all necessary fields such as Contact Name, Review ID, Last Action Date, etc., providing a holistic view
You can perform various actions from the Consultations grid such as Delete, Edit, Send, Preview, View, view Messages, and view Actions Logs. Depending on the consultation type and status, relevant actions will be displayed
You can now view all Action Logs across all consultations for a selected request, improving transparency and traceability
1.2 Enhanced Application Logs
ID# 1275264
With our continued commitment to provide logs throughout the system, we have stayed focused on implementing logs for the majority of items in the FOIAXpress.
1.3 Improved Review Flag behavior for āDuplicateā and āNot Relevantā flags
ID# 1278036
With this feature, we have enhanced the behavior of review flags. When āDuplicateā and āNot
Relevantā flags are applied to a document and then actions such as applying redaction from Document Management or Find and Redact is performed, the system will not automatically change these flags.
1.4 Eliminate separate installation of Java Server - CoreNLP
ID# 1298442
With this feature, the CoreNLP redaction service has been integrated into the NextGEN API, eliminating the need for separate installation. Thus, the AI API URL configuration has been removed from the General Configuration in FOIAXpress, as it is no longer required.

Security Updates
Weāve made the following security updates in this version of FOIAXpress:
ID | Description |
1308406 | Sanitized all user inputs rendered into HTML, used templating engines with auto-escaping, and limited rendering of untrusted content. |
1308408 1308412 1308416 | Introduced output encoding (e.g., HTML entity encoding), input validation, and Content Security Policy (CSP) headers. |
1311328 | Reviewed and corrected access control policies, implemented deny-bydefault strategies, and validated user roles per request. |
1306813 | Enforced MFA, applied rate-limiting, secured session tokens, and adopted robust password policies. |