Zum Hauptinhalt springen
DocumentMS

Records management

Records management software with retention and disposition

Records management software governs how long a document is kept and what happens at the end. DocumentMS attaches a retention rule to each document type, surfaces records due for disposition review rather than deleting silently, and supports legal holds that suspend disposal while litigation is live.

Who this is for

Records management is the part of document management that gets deferred, and the part that regulators ask about first.
  • Records managers and information governance teams maintaining a retention schedule
  • Legal teams that need disposal suspended when litigation becomes reasonably anticipated
  • Data protection officers balancing erasure requests against statutory retention obligations
  • Organisations holding decades of records because nobody was confident enough to delete any

Capabilities

Retention rules attached to document types, not folders

A retention rule belongs to a kind of record, not to a location. An employment contract is kept for the same period whether it sits in an HR folder or a legal one, and attaching the rule to the document type means moving a document cannot accidentally change how long it is kept.

Each rule defines a trigger event, a period, and what happens at the end. The trigger is the part organisations get wrong: "seven years" is meaningless without saying seven years from what — creation, last action, contract termination, or the end of the financial year in which the record was closed. DocumentMS requires the trigger to be stated, because a schedule that does not state it cannot be applied consistently.

  • Retention period with an explicit trigger event
  • Disposition action: review, destroy, or transfer to archive
  • Rules applied automatically when a document reaches its approved state
  • Retention class visible on the document and searchable as a filter

Disposition review, not silent deletion

When a retention period expires, DocumentMS raises a disposition review rather than deleting the record. Someone with authority confirms the disposal, and that confirmation is recorded with their name, the date and the rule that triggered it.

Automatic deletion is the feature most requested and least advisable. Retention periods are estimates of legal exposure made years earlier, circumstances change, and a system that destroys records on a timer will eventually destroy one you needed. A review step costs minutes and converts an irreversible automated action into a defensible human decision.

Legal holds that override everything

A legal hold suspends disposal for a defined set of records, regardless of what their retention rules say, and cannot be removed by the people whose records are held. Holds are applied by search — a matter, a date range, a custodian — so the scope can be described the way lawyers describe it.

Destroying records after litigation becomes reasonably anticipated is a separate and more serious problem than keeping them too long. The hold therefore takes precedence over automated retention, and the application and release of every hold is recorded.

Where erasure and retention collide

An erasure request under the GDPR or a comparable regime does not automatically defeat a statutory retention obligation, and a system that deletes on request without checking will put you in breach of one law while complying with another.

DocumentMS surfaces the retention rule and any legal hold when a deletion is attempted, so the conflict is visible at the point of decision. The decision itself, and its reasoning, is recorded — which is what you will be asked for if the requester complains.

Reporting on what you hold

A retention schedule is only as good as your ability to see whether it is being followed. Records can be reported by retention class, by upcoming disposition date, by hold status and by age, which turns the schedule from a document into an operational view.

The most useful report is usually the least flattering: records with no retention class assigned. That number is the honest measure of how complete your programme is, and it should be visible rather than derived on request.

In the product

What this looks like in use

DocumentMS records management view listing documents by retention class with upcoming disposition review dates and legal hold status
DocumentMS records management view listing documents by retention class with upcoming disposition review dates and legal hold status
client verification — interface wireframe. Replace with a capture of the real retention view.

How it works

How a record reaches disposal

Four stages, of which only the last requires a human — and deliberately so.
  1. Step 1: Classify

    The document type determines the retention class, which attaches automatically when the document reaches its approved state.

  2. Step 2: Start the clock

    The rule’s trigger event — creation, closure, contract termination, financial year end — sets the retention expiry and the disposition review date.

  3. Step 3: Hold if required

    A legal hold applied by matter, date range or custodian suspends disposal for the records in scope until it is explicitly released.

  4. Step 4: Review and dispose

    On expiry a review task is raised. An authorised user confirms destruction, transfer or extension, and the decision is recorded with their name and reasoning.

Specifications

Technical specifications

The numbers a technical evaluation asks for, stated rather than described. Where a limit is configurable, the default and the ceiling are both given.
Records management specifications
PropertyValue
Rule attachmentPer document type, so relocation cannot change retention
Trigger eventsCreation, last action, closure, contract termination, financial year end
Disposition actionsReview, destroy, transfer to archive
Default behaviour at expiryRaise a review task — never automatic destruction
Legal holdsApplied by search scope; override retention rules; cannot be released by held custodians
Erasure conflict handlingRetention rule and hold status surfaced at the point of deletion
ReportingBy retention class, upcoming disposition date, hold status, age, and unclassified records
EvidenceEvery classification, hold, release and disposal recorded in the immutable audit trail
Schedule importBulk import from CSV or XLSX, with a dry-run that reports unmapped record series before anything is applied
WORM storageSupported on Enterprise via S3 Object Lock in compliance mode or Azure immutable blob policy, which is what SEC 17a-4(f) and FINRA 4511 require

Security

Security notes

Records management controls destruction, which makes its permissions more consequential than most.

Read the trust centre

  • Confirming a disposal is a distinct permission, separate from the ability to delete an individual document
  • Legal holds cannot be released by users whose own records are subject to the hold
  • Permanent deletion under a retention rule is logged with the rule, the approver and the reasoning
  • Changing a retention rule is an audited action, so a shortened period is visible after the fact
  • The audit trail outlives the record: entries about a disposed document remain after the document is gone

Integrations

Integration notes

Retention decisions often depend on data held elsewhere — an HR system knows when someone left, a finance system knows when a contract closed.

FAQ

Records management: common questions

Answers to what procurement, IT and compliance teams ask us about this module.
Why not delete records automatically when retention expires?

Because retention periods are judgements about legal exposure made years before the expiry date, and circumstances change. A timer that destroys records will eventually destroy one you needed, and the resulting conversation is much worse than the cost of a review step. Automatic destruction is available for high-volume, low-risk classes, but it is not the default and we would not recommend it as one.

How do legal holds interact with retention rules?

The hold wins. Disposal is suspended for every record in scope until the hold is explicitly released, regardless of what the retention schedule says. Destroying records after litigation is reasonably anticipated is a materially worse problem than over-retention, so the precedence is deliberate.

What happens if someone requests erasure of a record we must keep?

DocumentMS surfaces the retention rule and any hold at the point the deletion is attempted, so the conflict is visible before a decision is made rather than after. The decision and its reasoning are recorded, which is the evidence you need if the requester challenges the refusal.

Can we import our existing retention schedule?

Yes — CSV or XLSX, with a dry run that lists every unmapped row before anything is committed. In practice the bigger task is not the import but the mapping: most schedules are written in terms of record series that do not correspond one-to-one to the document types a system uses, and that reconciliation is worth doing deliberately rather than forcing a match. The dry run exists to make the mismatches visible while they are still cheap to resolve.

How do we find records with no retention class?

There is a report for exactly that, and it is the number worth watching. Unclassified records are the honest measure of how complete a retention programme is, and they are the ones that turn into an unbounded archive.

Eine 30-minütige Sitzung mit einem Solutions Engineer, mit einer Ordnerstruktur und Freigabekette, die Ihren ähneln — kein allgemeiner Demo-Mandant.