Record retention is more than keeping a ZIP file. A future reviewer needs to know which evidence version supported which fact, what checks ran, which limitations remained, who made the final decisions, and how the prepared pack relates to an external submission.
A practical preparation workflow
- 1
Freeze the selected evidence, facts, checks, issues, and decisions.
- 2
Generate a manifest with stable identifiers, versions, and hashes.
- 3
Link later corrections or submission references without rewriting history.
Preserve relationships, not just files
A folder of PDFs does not show which page supported a country value, which geometry belonged to a batch, or which issue was resolved by a later permit. Retain the relationship graph alongside the original evidence.
Use a manifest as the package index
The manifest should list source files, normalized derivatives, confirmed facts, checks, decisions, exports, identifiers, versions, and hashes. This makes the retained package inspectable without depending on a live application view.
Append corrections instead of replacing history
If a supplier corrects a plot or document after preparation, keep the original snapshot and attach the correction as a new version. Record which later export or submission reference used the correction.
What to check
- Immutable source and export versions
- Manifest, hashes, timestamps, and rule versions
- Decision owner and issue resolution history
- Access controls and authorized retrieval record
Filovara can structure a retention package, but the responsible business must determine the legal retention scope and policy that apply to it.
Questions teams ask
Is a PDF export enough for retention?
Usually not for technical reproducibility. Retain the evidence index, structured data, versions, checks, decisions, and manifest with the rendered files.
Should corrected evidence overwrite the original?
No. Preserve the earlier version and append the correction with a clear relationship and timestamp.
Can every team member retrieve retained packs?
Access should follow the workspace’s authorization and audit policy rather than relying on a permanent public link.