Records management
Records management is about being able to prove two opposite things: that something was kept for as long as it had to be, and that it was destroyed when it had to be. ADM has features for both, and both are enforced by the product rather than by policy: a document under a legal hold cannot be deleted by anybody, administrators included.
| Feature | Guarantees |
|---|---|
| Retention policies | A document is not deleted before its date, and is deleted on it. |
| Legal hold | A document cannot be deleted at all until the hold is lifted. |
| Audit trail | Every action on every document, with who and when. |
| Access control | Only the right people could reach it in the first place. |
| Versioning | The document’s history, not just its current state. |
Retention policies
Section titled “Retention policies”A retention policy puts a date on a document. Until that date it cannot be deleted; on it, the daily job deletes it automatically.
begin adm_context_api.system_user_login('JDOE');
adm_document_api.add_file_retention( p_document_id => l_document_id , p_retention_delete_date => add_months(systimestamp, 120) -- ten years , p_retention_category => 'TAX' -- optional, free text );
commit;end;/The optional retention category classifies why the document is being retained. It is free text
on the document and it is queryable, so “everything retained under TAX” is a where clause.
select document_name , retention_category , retention_delete_date from adm_documents where retention_delete_date is not null and deleted_flag = 'N' order by retention_delete_date;Remove a policy with remove_file_retention — which is itself an audited action, so a removal is
part of the record.
Setting retention requires owner rights on the document (administrators have them everywhere). It cannot be applied to a trashed document, or to one already under a legal hold.
Legal hold
Section titled “Legal hold”A legal hold blocks deletion indefinitely — for litigation, an audit, an investigation. There is no date and no automatic expiry; somebody has to lift it.
begin adm_context_api.system_user_login('JDOE');
adm_document_api.add_legal_hold(p_document_id => l_document_id); -- ... later, when the matter is closed adm_document_api.lift_legal_hold(p_document_id => l_document_id);
commit;end;/Both require owner rights, and both are audited. While a hold is on:
- Trashing the document fails with
c_err_legal_hold_active. - Permanent deletion fails.
- Retention cannot be applied on top of it.
- The document is otherwise normal — readable, editable, shareable.
-- everything currently on holdselect document_name , user_owner , group_owner from adm_documents where legal_hold_flag = 'Y';Audit trail
Section titled “Audit trail”Retention and legal hold changes are audited as first-class actions — ADD_FILE_RETENTION,
REMOVE_FILE_RETENTION, ADD_LEGAL_HOLD, LIFT_LEGAL_HOLD, FILE_RETENTION_DELETE — alongside
every access, share and modification.
select action_date , action_type , user_id , document_name , action_details from adm_report_audit_log_v where action_type in ('ADD_LEGAL_HOLD', 'LIFT_LEGAL_HOLD', 'ADD_FILE_RETENTION', 'REMOVE_FILE_RETENTION', 'FILE_RETENTION_DELETE') order by action_date desc;The audit log itself has no retention job — see Administration.
Three kinds of deletion
Section titled “Three kinds of deletion”Three different things are all called “delete”:
| Effect | Reversible | |
|---|---|---|
| Trash | Moved to the user’s trash folder | Yes, until the trash is emptied |
| Trash expiry | Permanently deleted after CLEAN_TRASH_DAYS | No |
| Retention deletion | Permanently deleted on the retention date | No |
A permanent deletion also revokes every share, link share and embed token that pointed at the document, so nothing keeps resolving to a file that is gone. See Sharing.