Govern · Retention & Purge
Nothing is destroyed until two people agree — and then it's certified
Retention templates citing their statutes, a sweep that logs its exemptions instead of skipping them silently, dual-controlled suppression, four layers of destruction — and a certificate that queries the index before it says anything.
Where it starts
Everything ships out of force, and that is the safe state: a new archive keeps everything, and the screen says so — 'No retention rule is in force, so nothing is ever disposed of.' Destruction begins only when you decide the schedule.
How it runs
- 01
Enable rules with their citations
Ten templates, six citing their statute — SEC 17a-4(a)/(b), FINRA 4511(c), SOX §802, HIPAA, MiFID II. Two principles are stated before you enable anything: the longest applicable rule wins, and the clock runs from when this archive took custody — counting from the message date would make migrated mail disposable on arrival.
- 02
Preview before anything is in force
A rule can be scoped and previewed while disabled: what it governs, what is past retention, where the cutoff falls — and when another rule blankets it, the screen names the blocker in a sentence rather than showing a mysterious zero.
- 03
Sweep, and read the exemptions
The sweep disposes only when retention has expired and no hold applies. Exemptions are logged, not skipped silently — one ledger entry per hold, because customers under scrutiny must prove they preserved everything under hold, and those entries are that proof.
- 04
Suppress under dual control
Suppression stages the documents under an approval request — 'Nothing has been destroyed yet — no key has been touched' — for a different person to approve within 24 hours. The requester cannot approve it, and neither can anyone else who asked for the same act.
- 05
Reclaim, then certify
Crypto-shred first (the record key dies; the sealed container is untouched), then physical reclamation from the lakehouse and index. Only after reclamation is the certificate issued.
Why it holds up
What you hand the regulator
A workflow that ends on a screen isn’t finished. This one ends in a document.
Issued only after physical reclamation, and honest about everything a challenge would probe: what was destroyed, what could not yet be, and what the index said when asked.
- documents destroyed · not yet certifiable · shared natives retained (named)
- method: the four destruction layers, stated
- index verification at issue: clear / residual / unverified
- suppressed_at · reclaimed_at · the gap disclosed
- ledger verification: chain intact at issue
Adjacent workflows
See it run on your data scenario
The demo form asks which workflows you want to see — name this one and we’ll stage it.