Skip to content

Records management

Records management is about being able to prove two opposite things: that something was kept for as long as it had to be, and that it was destroyed when it had to be. ADM has features for both, and both are enforced by the product rather than by policy: a document under a legal hold cannot be deleted by anybody, administrators included.

FeatureGuarantees
Retention policiesA document is not deleted before its date, and is deleted on it.
Legal holdA document cannot be deleted at all until the hold is lifted.
Audit trailEvery action on every document, with who and when.
Access controlOnly the right people could reach it in the first place.
VersioningThe document’s history, not just its current state.

A retention policy puts a date on a document. Until that date it cannot be deleted; on it, the daily job deletes it automatically.

begin
adm_context_api.system_user_login('JDOE');
adm_document_api.add_file_retention(
p_document_id => l_document_id
, p_retention_delete_date => add_months(systimestamp, 120) -- ten years
, p_retention_category => 'TAX' -- optional, free text
);
commit;
end;
/

The optional retention category classifies why the document is being retained. It is free text on the document and it is queryable, so “everything retained under TAX” is a where clause.

select document_name
, retention_category
, retention_delete_date
from adm_documents
where retention_delete_date is not null
and deleted_flag = 'N'
order by retention_delete_date;

Remove a policy with remove_file_retention — which is itself an audited action, so a removal is part of the record.

Setting retention requires owner rights on the document (administrators have them everywhere). It cannot be applied to a trashed document, or to one already under a legal hold.

A legal hold blocks deletion indefinitely — for litigation, an audit, an investigation. There is no date and no automatic expiry; somebody has to lift it.

begin
adm_context_api.system_user_login('JDOE');
adm_document_api.add_legal_hold(p_document_id => l_document_id);
-- ... later, when the matter is closed
adm_document_api.lift_legal_hold(p_document_id => l_document_id);
commit;
end;
/

Both require owner rights, and both are audited. While a hold is on:

  • Trashing the document fails with c_err_legal_hold_active.
  • Permanent deletion fails.
  • Retention cannot be applied on top of it.
  • The document is otherwise normal — readable, editable, shareable.
-- everything currently on hold
select document_name
, user_owner
, group_owner
from adm_documents
where legal_hold_flag = 'Y';

Retention and legal hold changes are audited as first-class actions — ADD_FILE_RETENTION, REMOVE_FILE_RETENTION, ADD_LEGAL_HOLD, LIFT_LEGAL_HOLD, FILE_RETENTION_DELETE — alongside every access, share and modification.

select action_date
, action_type
, user_id
, document_name
, action_details
from adm_report_audit_log_v
where action_type in ('ADD_LEGAL_HOLD', 'LIFT_LEGAL_HOLD',
'ADD_FILE_RETENTION', 'REMOVE_FILE_RETENTION',
'FILE_RETENTION_DELETE')
order by action_date desc;

The audit log itself has no retention job — see Administration.

Three different things are all called “delete”:

EffectReversible
TrashMoved to the user’s trash folderYes, until the trash is emptied
Trash expiryPermanently deleted after CLEAN_TRASH_DAYSNo
Retention deletionPermanently deleted on the retention dateNo

A permanent deletion also revokes every share, link share and embed token that pointed at the document, so nothing keeps resolving to a file that is gone. See Sharing.