Governance: retention, holds, and an audit trail
Governance is the difference between a pile of files and a system of record. It is the set of guarantees that lets you tell a board, an auditor, or a donor’s family that a document was kept as long as it should be, deleted only when it should be, and seen only by the people who should see it. PaperlessZen™ builds those guarantees in rather than leaving them to policy documents nobody follows.
A pile of files
Keeping and purging depend on someone remembering the policy.
One misclick can destroy a record for good.
Who saw a file is a reconstruction you attempt after the fact.
A document shared last week is out of your hands forever.
A system of record
Retention schedules run on their own; permanent records stay permanent.
Deletes are soft, and legal holds freeze what a matter requires.
Every view, share, and download is logged as it happens.
External shares are single-use tokens you can revoke immediately.
Retention that runs on its own
Some records are permanent. Others should live for a defined number of years and then go. PaperlessZen lets you lock a record to a retention schedule, so it lives exactly as long as your policy requires and no less. Permanent records stay permanent. Scheduled records are tracked to their date. You are not relying on someone to remember what to keep and what to purge.
Legal holds that freeze the right documents
When a matter requires it, a legal hold freezes a document in place, overriding any retention or deletion until the hold is lifted. That is how you make sure the documents relevant to a dispute or an investigation are preserved exactly as they are, without a scramble and without the risk that a routine retention rule quietly removes something you needed.
Deletion is reversible, governance is not
Even an ordinary delete is a soft-delete: the underlying file is retained, not destroyed. Combined with retention and holds, this means the failure modes people fear, “we lost it” and “someone deleted it,” stop being real risks. The dangerous actions are the governed ones, and those are held behind a separate permission so they cannot happen by accident.
Every action on the record
Every view, share, and download is logged. When someone needs to know who accessed a document, when, and under what authority, that trail is a record you produce, not a reconstruction you attempt. That matters for institutions that get audited, and for anyone who needs to show a confidential file was handled properly.
The audit trail turns a stressful question into a calm answer.
Sharing you can take back
Governance extends to how documents leave the building. External shares use a single-use token that resolves to a short-lived link, and any share can be revoked immediately. A document shared last week can be closed off the moment it should no longer be open. There is more detail on our security page.
Governance underpins everything else: approvals, obligation tracking, and the gift agreement workflow. It also follows documents recovered from other systems, like the attachments extracted out of Dynamics 365. Read more on keeping the obligations you promised.
Frequently asked questions
What stops an important record from being deleted?
Records can be locked to a retention schedule and placed under a legal hold, both of which override deletion. Even an ordinary delete is a soft-delete that retains the underlying file, so nothing important disappears on a misclick.
Who can change retention or place a hold?
Only accounts with the governance permission. Changing a retention schedule or placing a legal hold is held behind a separate permission, so these actions cannot happen by accident.
Can we prove who accessed a document?
Yes. Every view, share, and download is recorded. When someone asks who accessed a document, when, and under what authority, the answer is a record you can produce.