Reporting and appeals
ProductAtlas lets anyone privately report a concern about one exact public Blueprint Release. A report asks ProductAtlas to review the concern. It does not prove a violation, give the reporter control over the Blueprint, open a moderation case, notify the Publisher, or trigger enforcement.
Report the exact Release
Open the public Release you want to report and select Report this Blueprint. A modal opens on the same page and identifies the selected semantic version. If you selected a historical version, the report remains bound to that historical Release rather than the latest version.
Choose one category:
- ProductAtlas terms or policy
- Restricted-license reupload
- Copyright
- Deceptive or removed provenance
- Malware or malicious links
- Prompt injection
- Exposed secrets or personal data
- Privacy
- Impersonation
- Spam
Describe the concern in 20–8,000 characters. You may add up to ten evidence
links. Each link must be an absolute https:// URL no longer than 2,048
characters, without embedded credentials or a #fragment.
ProductAtlas does not accept evidence uploads. Do not include passwords, tokens, private keys, or unnecessary personal data in your statement or links.
Save the private receipt
After submission, ProductAtlas shows a receipt reference and a private status link. Save that link somewhere secure. Anyone who has it can view the limited reporter-safe status.
The secret portion follows # in the link. Your browser removes it from the
address bar before exchanging it for a short-lived private status session. Do
not paste the link into public issues, chats, screenshots, or analytics tools.
The status page intentionally shows only:
- Received
- Under review
- Resolved — action taken
- Resolved — no violation found
- Closed
It may also show a short safe message. It does not reveal internal case details, other reports, staff identity, private rationale, Publisher communication, or enforcement details.
Optional email
Email is optional. If you provide an address, ProductAtlas sends a verification message so you can prove control of it. Apart from that verification message, ProductAtlas sends no report-status email until verification succeeds.
The address is kept separate from the Publisher case and is not shown to the Publisher. If you do not provide or verify an email, keep the private receipt link to check status yourself.
What happens after submission
Reports are reviewed privately and remain independent, even when several people report the same Release. ProductAtlas may close an invalid, duplicate, spam, or otherwise unactionable report without opening a case.
An administrator must manually:
- begin reviewing a report;
- open a new investigation or link the report to a matching exact-Release investigation; and
- separately decide whether to notify the Publisher.
Opening an investigation does not notify the Publisher. A Publisher sees a case only after ProductAtlas completes the separate notification step.
Publisher response
A notified Publisher receives a safe summary and response deadline in Publisher Studio. The Publisher may submit one bounded response with up to ten safe HTTPS references before that deadline.
The Publisher does not receive reporter contact details or private reporter evidence through this view. ProductAtlas keeps staff identity and private rationale out of the Publisher projection as well.
One appeal
After ProductAtlas records a decision for a notified case, the Publisher may submit one structured appeal. The appeal uses the same 20–8,000-character statement and ten-link bounds as the response.
ProductAtlas may uphold, modify, or reverse the decision. The appeal decision is recorded separately and does not rewrite the original decision or action history. A Publisher restriction on ordinary content changes does not remove access to the notified case, response, or one appeal.
Release history remains immutable
Moderation does not edit a published Blueprint Release. ProductAtlas may change current availability, quarantine an asset, restrict Publisher mutations, or hide a revoked trust-badge presentation, but the historical Release content, version, digest, and bundle bytes are not rewritten.
Restoring an asset does not automatically restore a withdrawn Release. Each restoration is a separate ProductAtlas decision.
Agent access
The anonymous ProductAtlas MCP endpoint remains read-only. It has no report, moderation, response, or appeal tool. Use the web Release detail and Publisher Studio surfaces for these workflows.