Ir al contenido principal
DocumentMS

Glossary

Document management glossary

Vendors and standards use the same words to mean different things, which makes requirements documents ambiguous. Each entry here gives a short definition first, then what the term means when you have to configure or audit it, and which standard defines it where one does.

Jump to a letter

62 términos definidos. Terms are auto-linked on first mention across the guides and blog, so you rarely need to come here directly.

#

21 CFR Part 11
21 CFR Part 11 is the FDA regulation governing electronic records and electronic signatures in regulated life sciences.

A

Access review
An access review is a periodic check that the people who have access to something still need it.
API key
An API key authenticates a program rather than a person.
Approval workflow
An approval workflow is a configured path a document must clear before it can be relied on, defining the steps, the approvers and the order.
Audit trail
An audit trail is an append-only record of every action taken on a document — views, downloads, edits, approvals, permission changes and deletions — with the acting user, timestamp and affected version.

B

Break-glass access
Break-glass access is a deliberate, time-boxed grant of permissions a user does not normally hold, for genuine emergencies.
Business associate agreement
A business associate agreement is the contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf.

C

Chain of custody
Chain of custody is the documented, unbroken record of who has held, accessed or altered an item of evidence, and when.
Check-in / check-out
Check-out locks a document for editing by one person and shows others who holds it; check-in releases the lock and creates a new version.
Common data environment
A common data environment is the agreed single source of information for a project, through which all information is collected, managed and shared.
Contract lifecycle management
Contract lifecycle management covers the whole life of an agreement: request, drafting, negotiation, approval, signature, storage, obligation tracking and renewal.

D

Data processing addendum
A data processing addendum is the contract between a controller and a processor governing how personal data is handled.
Data residency
Data residency is the commitment that data is stored and processed within a specified country or region.
Disposition
Disposition is what happens to a record when its retention period expires: destruction, transfer to an archive, or a decision to extend.
Document capture
Document capture is the process of getting documents into a system and making them usable: scanning or importing, recognising text, classifying, extracting fields and applying metadata.
Document control
Document control is the discipline of ensuring only approved documents are in use, superseded ones cannot be mistaken for current, and every change is authorised and recorded.
Document generation
Document generation produces a finished document by merging structured data into an approved template.
Document management system
A document management system is software that captures, stores, versions, secures and retrieves an organisation's documents from one repository.
Document migration
Document migration is the movement of documents, their metadata and their version history from one system to another.
Document numbering
Document numbering assigns each document a unique identifier, generated by the system according to rules configured per document type.
Document type
A document type classifies what a document is — a contract, a policy, an invoice, a batch record.
Duplicate detection
Duplicate detection identifies documents whose content is already present in the repository, normally by comparing a cryptographic hash of the file.

E

e-Form
An e-form captures structured data through defined fields with validation, rather than collecting it as text inside a document.
eIDAS
eIDAS is the EU regulation establishing a framework for electronic identification and trust services.
Electronic signature
An electronic signature is data attached to or logically associated with a document that indicates the signer's approval of it.
Email-to-folder import
Email-to-folder import monitors a mailbox and files incoming messages and their attachments into a specified folder automatically.
Encryption at rest
Encryption at rest protects stored data by encrypting it on disk, so that physical access to the storage medium does not yield readable content.
Enterprise content management
Enterprise content management is the broader discipline covering documents, records, web content, capture, archiving and business process automation across an organisation.
Escalation
Escalation is the automatic reassignment or notification that occurs when a workflow step is not actioned within a defined period.
ESIGN Act
The ESIGN Act is the US federal statute giving electronic signatures and records the same legal effect as paper, provided the parties intended to sign and consented to transact electronically.

F

Full-text search
Full-text search queries the words inside documents rather than only their names and metadata.

G

GDPR
The General Data Protection Regulation governs the processing of personal data in the EU, with an equivalent UK regime.
Golden thread
The golden thread is the requirement, introduced by the UK Building Safety Act 2022, to create and maintain accurate building safety information for higher-risk buildings throughout their life.

H

HIPAA
HIPAA is the US framework governing protected health information.

I

Information governance
Information governance is the framework of accountability, policies and controls determining how an organisation creates, uses, retains and disposes of its information.
Intelligent document processing
Intelligent document processing combines optical character recognition with machine learning to classify a document, extract named fields from it and route it onward.
ISO/IEC 27001
ISO/IEC 27001 is the international standard for information security management systems.

L

Legal hold
A legal hold suspends the routine destruction of records that may be relevant to litigation, an investigation or an audit.

M

Metadata
Metadata is structured information about a document rather than inside it: its type, owner, date, status, retention class and any fields specific to its kind.

O

Optical character recognition
Optical character recognition converts an image of text into machine-readable characters.

P

Permission inheritance
Permission inheritance means a document takes its access rights from the folder containing it, rather than being permissioned individually.
Policy acknowledgement
Policy acknowledgement is a recorded attestation that a named individual has read a specific version of a specific policy, at a given time.

R

Records management
Records management governs how long a document is kept and what happens at the end of that period.
Recycle bin
A recycle bin holds deleted documents so they can be restored.
Redaction
Redaction is the permanent removal of information from a copy of a document before it is disclosed, leaving the original intact.
Retention schedule
A retention schedule sets out, for each class of record, how long it is kept, what event starts the clock and what happens when the period expires.
Right to erasure
The right to erasure allows an individual to require deletion of their personal data in defined circumstances.
Role-based access control
Role-based access control grants permissions to roles rather than to individuals, and assigns people to roles.

S

SEC Rule 17a-4
SEC Rule 17a-4 governs how broker-dealers preserve their records.
Semantic search
Semantic search matches meaning rather than exact strings, using vector representations of text.
Single sign-on
Single sign-on lets users authenticate to an application using an identity provider they already use.
SOC 2
SOC 2 is an attestation report in which an independent accounting firm describes and tests a service organisation's controls against the AICPA trust services criteria.
Spoliation
Spoliation is the destruction, alteration or failure to preserve evidence that is relevant to litigation.
Statement of applicability
A statement of applicability lists every Annex A control in ISO/IEC 27001, states whether each one is applicable, and justifies the decision either way.
Sub-processor
A sub-processor is a third party a processor engages to help process personal data on a controller's behalf.
Subject access request
A subject access request is an individual's request for a copy of the personal data an organisation holds about them, together with information about how it is used.

T

Taxonomy
A taxonomy is the structure by which documents are organised and found — folders, categories, document types and the metadata that describes them.
Two-factor authentication
Two-factor authentication requires a second proof of identity beyond a password, typically a time-based code or a hardware key.

V

Version control
Version control keeps every revision of a document as part of one record rather than as separate files, marks which version is currently in force, and retains superseded versions as evidence.

W

Watermarking
Watermarking applies a visible marker to a document preview or download — draft status, confidentiality level, or recipient identity.
Webhook
A webhook is an HTTP request a system sends to a URL you nominate when an event occurs, so your application is told rather than having to ask.
WORM storage
WORM storage is a medium that permits data to be written once and read many times, but never altered or erased before its retention period expires.
Una sesión de 30 minutos con un ingeniero de soluciones, sobre una estructura de carpetas y una cadena de aprobación parecidas a las suyas, no un entorno de demostración genérico.