Help
Troubleshoot the core workflow
Find the symptom you are seeing and the fix that goes with it, from connecting Microsoft 365 through to delivering a response.
Start with these three checks
Most reports resolve here.
- Check your role. Viewers can read cases but cannot act on them, and some actions need the Admin role. A missing or greyed-out button is usually a permission, not a fault.
- Read the exact message, including any Error code and any Reference. Those three things determine everything below.
- Try again once. Transient errors are retried automatically, and a second attempt often succeeds.
Messages that can appear anywhere
| Message | What to do |
|---|---|
Your session has expired. Please sign in again. | Sign in again, then repeat the action. |
You do not have permission to perform this action. | Ask an Admin, or ask to have your role changed. |
Unable to connect to the server. Please check your internet connection. | Check your connection and retry. |
Too many requests. Please wait a moment and try again. | Wait, then retry. |
An unexpected error occurred. Please try again later. | Retry once. If it persists, send the Reference to product support. |
Microsoft 365 connector problems
Connectors live on the Integrations page. Some messages in the product still say "Settings" — go to Integrations.
Connecting fails with "Failed to connect Microsoft 365"
Failures in the Connect Data Source wizard appear as this toast with the reason after the colon:
Connector already exists for this organization— an organisation can hold one connector of each type at a time. Disconnect the existing one first.OAuth state has expired,OAuth state is invalid, orOAuth state already used— the authorisation link timed out or was reused. Restart the wizard and complete it in one pass, within a few minutes.OAuth tenant mismatch— you signed in to a different Microsoft 365 tenant from the one configured. Sign in with an account in the correct tenant.You don't have permission to perform this action.— connecting requires the Admin role.- Any other wording is passed through from Microsoft. The usual cause is that admin consent was declined, or the signed-in account cannot consent for the whole tenant. The connector needs organisation-level consent to read Exchange mail, OneDrive and SharePoint files, and the user directory.
The connector shows Error
Select Test Connection on the connector card. The result appears as Connection test failed: followed by the underlying status:
401 Unauthorized: InvalidAuthenticationToken— access to the tenant is no longer valid, usually because the grant was revoked or credentials were rotated in Microsoft Entra.403 Forbidden— the consented permissions no longer cover what was asked for.429 Too Many Requestsor a5xxstatus — Microsoft 365 is throttling or unavailable. Wait and test again before changing anything.
There is no reconnect action on the connector card. To recover a connector stuck at Error, select Disconnect, then run the Connect Data Source wizard again and re-grant admin consent. See Connect Microsoft 365.
You cannot see or add a connector
You don't have permission to view integrations. means your role cannot see Integrations. Data connectors require a Growth or Pro plan, or a message about the maximum number of connectors, means the limit is your organisation's plan rather than your role.
Discovery problems
Start Discovery is disabled
The note under the button says which requirement is unmet: the Microsoft 365 connector is not connected, identity verification is not complete, or you do not have permission to start discovery. Resolve that one thing and the button becomes available.
Discovery failed with an error code
Discovery failed shows the error and an Error code. Transient problems are retried automatically first, so a code you can see means the problem persisted.
| Error code | What it means | What to do |
|---|---|---|
UNAUTHORIZED | The connector's access to Microsoft 365 is no longer valid. | Test the connector, re-create it if needed, then Retry Discovery. |
FORBIDDEN | Microsoft 365 refused access to a mailbox or site. The product cannot tell you which one. | Ask your Microsoft 365 administrator to confirm the consented permissions still apply tenant-wide. |
RATE_LIMITED | Microsoft 365 throttled the search even after automatic retries. | Wait, then Retry Discovery. Narrow the run if it recurs. |
TIMEOUT | The run exceeded its time limit. | Narrow the sources, terms, or date range and run again. |
UPSTREAM_5XX, UPSTREAM_ERROR | Microsoft 365 returned an error. | Retry later. |
NOT_FOUND, BAD_REQUEST | The search could not be carried out as specified. | Check the case's subject details, then retry. |
DISCOVERY_SCHEDULING_FAILED | The run could not be queued. | Start it again. |
If starting a run produces only Failed to start discovery, it never began and no detail is available. Try once more, then contact product support with the case reference and the time.
Discovery found nothing
No data found. Please verify search parameters. means the run completed with zero items. Check the subject name and email held on the case, widen or remove the date range, and remove narrowing search terms before re-running. If the tenant genuinely holds nothing, use Manual Upload or Continue Anyway, and record what was searched.
Discovery finished with partial results
Discovery completed with partial results means the run stopped after finding some items. Review what was recovered, then choose Retry Discovery for a full run or Use partial results. Do not treat partial results as a complete search without recording why that was reasonable.
Discovery completed but material is missing
A run can stop early at a service limit — a maximum number of items, a maximum file size, or a time limit — and is still reported as completed. Oversized files appear as excluded items with a reason on the item card. Discovery searches every mailbox and site the connector can reach, with no per-mailbox or per-site picker, and the subject name and email cannot be edited from the discovery dialog — correct the case's subject details first if they are wrong.
Re-run with a narrower date range or more specific terms so the run completes inside the limits, and add anything discovery cannot reach through Add and organise documents.
UK GDPR context
You must make a reasonable and proportionate search and be able to show what you did. Because a run can stop at a service limit without saying so, do not treat "Discovery completed" as evidence that everything was found. Record the sources, terms, and date range you used, what came back, and the reason for any gap you knowingly accepted — that record, not the product's status, is what demonstrates the search you carried out.
This is operational guidance for UK organisations, not legal advice.
Document problems
A file was refused before it uploaded
Files listed under Some files could not be added were rejected on inspection: over 50MB, an unsupported type, or has an invalid file type signature because the contents do not match the extension. Archives such as .zip and executable or script files are always blocked — extract an archive and upload its contents individually. Supported types are listed in Add and organise documents.
A document is stuck or shows an error status
| What you see | What to do |
|---|---|
| The upload failed part way | Select Retry next to the file in the upload dialog. |
Timed out waiting for scan status | The scan did not finish in time. Reload the tab to see the document's current status before uploading again. |
The document stays at Ready for analysis | Analysis has not started. Select Start AI Analysis. |
Blocked - file scan in progress | The malware scan is still running. Wait and try again. |
The document shows infected, or Blocked - file failed malware scan | Permanently blocked. Get a clean copy from the source, delete the blocked document, and upload the clean copy. |
The document shows failed, or Blocked - file scan failed | Processing cannot be resumed, and there is no reprocess or replace action. Delete the document and upload the file again. |
If the same file fails repeatedly, tell support the file's type and size — never send the file.
Document actions are unavailable
A Read-only notice with You don't have permission to perform document management actions. means your role cannot manage documents. If actions are unavailable across the whole organisation, your organisation's subscription may have lapsed into read-only mode; an Admin can restore access.
Review and redaction problems
Analysis will not start or finish
Start AI Analysis appears only while a document is ready for analysis or already analysing. If it fails, the button reads Analysis failed and a toast says Analysis failed. The reason shown on the redaction job is commonly an OCR failure or an Office document too large to convert; delete and re-upload the document, or convert it to PDF yourself first.
Document status did not update — Analysis completed, but the document did not transition to ready for review. Please refresh. — means exactly that. Refresh the page, and report it if it recurs.
Analysis finished with no suggestions
No suggestions found. Run AI analysis to detect PII. after a completed run means the analysis detected nothing. Scanned images and documents with no recoverable text often produce this. Read the document yourself and add manual redactions; an empty suggestion list is not a finding that the document contains no personal data.
You cannot draw a manual redaction
Draw mode unavailable — Start AI analysis to enable draw mode. means no redaction job exists yet, so run analysis first. If the message says the job must be in review state, the job has not reached review or has already been finalised.
You cannot finalise a document or a case
- Finalize unavailable —
This document must be ready for review before it can be finalized.Wait for processing and analysis to finish. - On the Review Checklist,
Review all documents before finalizingmeans Finalize Review stays disabled until every document on the case has been finalised. - A message that only Admin and DPO roles can finalise case reviews means you need the Admin role.
The unreviewed-suggestions warning does not stop you
When you finalise a document, DSAR Respond warns you if you have looked at only some of the AI suggestions — You've only reviewed X of Y suggestions. Are you sure? — and then lets you continue anyway. Suggestions are treated as accepted unless you reject them, so finalising without reading them releases whatever the model proposed. Treat that prompt as a stop, not a formality: AI-assisted redaction always needs human review before anything leaves your organisation.
Response and delivery problems
Output generation failed
Output generation failed on Case outputs means the redacted package could not be built, and the banner shows why. Generation deliberately fails rather than releasing an uncertain result — for example when a document has no redaction job, a job is not in a deliverable state, or a redaction falls outside a document's pages. Resolve the document the message names, then select Generate redacted outputs again.
No delivery yet with The case must be finalized before a response package is generated means the review is not complete.
The requester cannot open or download the response
The Delivery panel shows the state of the secure download:
| What the panel shows | What to do |
|---|---|
| Download Expired or Downloads Exhausted | Select Re-issue Download to open a new 7-day window with a new password. The requester must verify their identity again to see it. |
| Build Failed | Generate the outputs again. If an earlier archive is still available, the panel says so. |
| Password already revealed | The password can be shown to the requester only once. Select Regenerate Password to issue a new one; the old password stops working. |
Important
Never email a response package, a download password, a secure link, or a one-time code to work around a failed download. Re-issue the download in the product instead. If the requester cannot use the portal at all, agree a different delivery method with them and record the decision on the case — a portal is only an appropriate route where the person can actually access it.
The response email bounced
The Correspondence tab shows a delivery badge for each message: Sent, Delivered, Bounced, Failed, or Complained. A failed entry reads Delivery failed — with the reason. An address that bounces permanently is suppressed and no further email is sent to it.
Confirm the correct address with the requester through another channel. Once it is fixed, select Mark address fixed / un-suppress on the entry. The Correspondence tab is read-only otherwise — you cannot compose or reply from it.
Portal problems
The requester says their link does not work
Ask them for the wording on the page. Each message maps to a different fix:
| What the requester sees | What it means | What to do |
|---|---|---|
| Link expired | The access window has passed. | Re-issue Download on the case. |
| Download limit reached | The permitted number of downloads is used up. | Re-issue Download. |
| Access revoked | The link was disabled. | Issue a new one only if access is still appropriate. |
| Invalid portal link | The address is wrong or incomplete. | Ask them to open the original link again, without editing it. |
| Too many attempts detected | Rate limiting. | Ask them to wait a few minutes. |
The requester cannot submit a request through the portal
- A message about not being able to verify the request from their browser points to strict privacy settings, a VPN, or an extension. Ask them to reload the page and try again, or to use a different browser.
Too many attempts. Please wait a moment and try again.is rate limiting; they should wait.- If they cannot use the portal at all, record the request manually. The portal is never mandatory — see Receive and record a request.
The requester cannot complete identity verification
- Link Expired or Invalid Link on a verification page means the 7-day link is no longer usable. Start verification again from the case to send a fresh link.
Invalid verification codeorMaximum attempts exceededmeans the code was entered incorrectly. Attempts are counted across resends, so resending does not reset them — start verification again.- Verification uploads accept JPEG, PNG, or PDF files, up to 10 MB each and no more than three. See Verify identity or representative authority.
The requester cannot find their request
We could not find a request matching the details you provided. on Check Request Status usually means the reference or email does not match the case. Confirm both against the case rather than sending case details by email.
Still stuck
Work through the checks at the top of this page, then see Contact product support for what to include — and what must never be sent. Product faults belong with support; decisions about clarification, extensions, fees, refusal, exemptions, or third-party information belong with your own advisers, as set out in Clarification, extensions, refusal, and specialist advice.
Official sources
What happens next
What happens next
If you cannot resolve a problem here, contact product support.
Last reviewed . UK regulatory context.