Help and records policy

How records behave in happierdocs, and the rules the system enforces on your behalf.

The retention schedule

Every document type carries a retention class. The class sets the trigger event, the period and the disposition action. A record reaching its date joins a work list; it is never deleted on a timer, and no timer anywhere in this platform deletes anything.

Open the schedule report

Legal hold

A hold suspends disposition for as long as the matter is open and overrides the retention schedule. A held record still appears on the work list, marked as held, because a records officer has to be able to see that a date was reached and the action was suspended. It cannot enter a decision set at all.

See held records

The audit trail

Capture, view, edit, approve, move, export and disposition all write an audit event. The trail is append-only in the database itself. Once an entry is written, no role can change it or delete it, administrators included.

See the administration log

Disposition and certificates

A destroy action runs only after the approval route completes. A submitted decision set always waits for approval first, every time. Each completed run issues a certificate of destruction listing the records, the approvers and the witness.

Open the work list

Where the storage coordinate is, and is not

Box, rack and shelf resolve for a custodian. Everyone else is told a record is in the archive and nothing finer. The platform applies that masking itself, so it holds in every application that reads these records. An auditor reaches the coordinate on the chain-of-custody report and nowhere else, and that read is itself written to the audit log. Where a screen shows nothing in place of a coordinate, it says the coordinate is withheld: a blank would read as “this record sits nowhere”, which is a different and untrue statement.