Loading

Retention & Legal Hold

Schedule how long records are kept, block disposal while a matter is live, and dispose of what should go.

Retention Schedules

A retention schedule says how long a kind of record is kept and from when. It is the difference between a policy and a document describing a policy.

Where to find it

These features have no dedicated Architect Panel section of their own. They are configured through their datastores, opened from All Datastores, and most of what a caseworker sees appears on the record itself rather than on an admin screen.

The trigger matters as much as the period

"Seven years" is meaningless without saying seven years from what. Case closure, last activity, a child reaching 25, the end of a contract — the trigger determines the date, and getting it wrong is how records are destroyed early or kept for decades.

Map to your existing schedule

Most organisations already have a retention schedule written by somebody who understood the obligations. Implement that rather than inventing one here. Where it is ambiguous, that ambiguity is worth resolving with the person who owns it before it is encoded.

Review before disposal

Configure a review step for anything consequential. Disposal is irreversible, and a schedule that goes straight from due to destroyed gives nobody the chance to notice that a case is still live. The review should be a real look, not a bulk approve.

The task

The Retention and Disposal task assesses what is due, raises reviews and carries out disposal. It ships disabled and runs daily. Enable it only once your schedules and review steps are configured and tested — this is the one task whose mistakes cannot be undone.

Test it on something safe

Run it against a small, non-sensitive category first and confirm what it proposes matches what you expect. A schedule with the wrong trigger looks completely reasonable right up until it disposes of the wrong thing.

Legal Hold and Disposal

Legal hold suspends the retention schedule for records that must not be destroyed, however overdue they are.

Where to find it

These features have no dedicated Architect Panel section of their own. They are configured through their datastores, opened from All Datastores, and most of what a caseworker sees appears on the record itself rather than on an admin screen.

Why hold overrides the schedule

Destroying records relevant to litigation, an investigation or an information request is a serious matter regardless of the fact that a schedule said they were due. Hold takes precedence, and the ordering is not configurable for good reason.

Applying a hold

Apply it as soon as you are on notice, not when proceedings begin. The obligation usually starts at the point litigation is reasonably anticipated, which is earlier than most people assume. Record why the hold exists and who applied it — a hold nobody can explain will eventually be lifted by somebody tidying up.

Lifting a hold

Lifting is a deliberate act, and once lifted the record returns to its schedule and may become immediately due for disposal. Confirm the matter is genuinely concluded before lifting; a hold lifted while an appeal window is open is a hold lifted too early.

Genuine disposal

Disposal means the record is gone, not flagged as deleted. That distinction matters because a soft-deleted record still exists, is still discoverable, and is still personal data you are holding — so a retention policy implemented as a flag has not been implemented at all.

Keep the disposal record

What is destroyed should leave evidence that it was destroyed: what, when, under which schedule, authorised by whom. That record is what demonstrates the policy operates, and it is what an information request or an audit will ask for. Keeping it is not in tension with disposal — it holds the fact of destruction, not the content.