Most retention policies are a document describing what should happen to other documents. Nothing reads it, so nothing happens, and the drive keeps everything forever — which is its own kind of exposure.
The short answer
A retention schedule only holds when something applies it on a clock rather than when someone remembers. The On a Schedule trigger runs over an archive folder, the Check File Details step selects what is past its period by file age — 90 days, a year, seven years — and the Move step sends it to a disposal folder. Put Ask a Person to Approve in front of the last step and nothing leaves without a human seeing the list, which is the arrangement most policies actually require. The Move to Trash step is a soft delete: files are recoverable afterwards, so this enforces a schedule, it does not destroy records irreversibly.
Steps this uses
Before and after
As they arrive
After the workflow
A seven-year rule run in 2026: the 2017 and 2018 records are staged for disposal and the rest are left exactly where they were.
Setting it up
This is the sentence. Send it to the builder and the steps below appear on a canvas, wired and named, for you to change before anything runs.
Every month, look through the archive for anything older than seven years, ask me to approve the list, and move what I approve to the trash.
Retention is expressed per category — tax records for years, interview notes for months — so the schedule belongs to the folder rather than to individual files. One rule per retention class, pointed at the folder that holds that class, is the arrangement that stays readable when somebody inherits it.
The Check File Details step routes on file age, with presets up to seven years. It measures the file’s own created or modified date, which is the honest thing to know about it: if your clock starts from a date printed inside the document, that is a different question and the next step answers it.
A tax record’s period runs from the tax year, not from the day someone scanned it. The Ask AI About the File step reads the document and branches on what it finds, so the clock can start from the date the document itself carries rather than from its upload.
Ask a Person to Approve pauses with the list in front of a person. Everything before the pause still runs unattended, so what arrives is a finished proposal rather than a folder that has already emptied itself.
A drive that never disposes of anything is usually described as cautious, and it is the opposite. Every document retained past its period is one more thing to produce in a dispute, one more record in a breach, and one more result burying the file somebody actually needs. Retention schedules exist because deleting on time is the safer position, and the reason they fail is never disagreement about that — it is that applying one by hand is a job nobody is given.
Automatic deletion is the part that stops a retention schedule ever being switched on, and reasonably so. Pausing for a person inverts it: the workflow does the finding, sorting and proposing, which is all of the tedious work, and a human does the deciding, which is all of the risk. That is also closer to what most policies actually say, since they tend to require a review before disposal rather than disposal on a timer.
It applies a schedule you define. It does not tell you what your retention periods should be — those come from law, regulator and sector and differ by document type — and it does not provide the guarantees a records system does: no legal hold, no write-once storage, no certificate of destruction. The Move to Trash step is a soft delete and files remain recoverable, so this is a schedule that gets applied, not a defensible destruction process. An organization under formal obligations should treat it as the first and confirm it meets the second.
FAQ
Run a scheduled workflow over the folder holding each retention class. It selects what is past its period by file age, stages it in a disposal folder, and pauses for approval before anything is cleared. The schedule runs whether or not anyone remembers it, which is the only property that makes a retention policy real.
No. The Move to Trash step is a soft delete and files can be recovered afterwards. That is deliberate: it makes the schedule safe to switch on. If you need irreversible, certified destruction, that is a records management system’s job and this is not one.
Yes, but they are different mechanisms. File-age rules measure the file’s created or modified date. To run the clock from a date printed inside the document — a tax year, a contract end date — the workflow reads the document with the Ask AI About the File step and branches on what it finds.
That is set by law, your regulator and your sector, and it varies by document type — tax records, employment records and contracts commonly carry different periods, several of them measured in years. A workflow applies whatever schedule you give it; deciding the schedule is a question for your own advisers.
It runs every month, stages what is past its period, and waits for you before anything clears.
5 GB free · No credit card required