Compliance & Retention¶
Set how long documents are kept, place legal holds, and handle erasure requests — so the workspace meets statutory retention duties without keeping data forever.
Retention policy¶
Settings → Compliance (/settings/compliance/types) — define document retention classes and
periods (e.g. Labour Agreement: keep 7 years) with the regulatory reference behind each. Periods are
driven by versioned regulatory settings, so they track Finance Act / rule changes.
Screenshot: Compliance settings — TODO
Retention dashboard¶
The Retention Dashboard (/compliance/retention) shows documents due for disposal, those on legal
hold, and recently purged items, with counts by status.
- Legal Hold — block disposal of specific documents (e.g. during a dispute or investigation).
- Right-to-erasure — on a verified request, erase a subject's documents; a tombstone/audit record of the disposal is kept.
Erasure is final
Erasure permanently destroys the documents (crypto-shred). It respects active legal holds — an item on hold won't be purged. Confirm identity and authority before erasing anyone's data.
Compliance Firewall — the annual review queue¶
Administration → Compliance Firewall (/admin/compliance/firewall) is the platform-staff board for
the yearly re-check of every piece of code whose behaviour is dictated by Nepal law or an NFRS/IFRS
standard. Each such class, method or field is tagged in the source with the regulation it implements
and the fiscal year it was last checked against; anything left behind the current fiscal year appears
here as open work.
Use it every Jeth, when the Finance Act lands:
- Open review queue — elements whose last-reviewed fiscal year is older than the current one. Read the cited regulation, confirm the code still matches it, then Mark reviewed (an optional note is recorded with your name). Acknowledged items drop off until next year rolls the bar forward.
- Proposed thresholds — carry-forward threshold values staged for the new fiscal year. Once the Finance Act passes, Enact promotes a proposed value to the live one. New values are added with New threshold; historical rows are never edited, only superseded.
- Inventory sources — which service contributed how many tagged elements. This is provenance, not decoration: a service showing zero when you expect otherwise means its inventory did not reach this build, and the queue above is incomplete. Raise it rather than reading the board as "all clear".
The list covers the whole product, and reflects a build
The inventory is assembled when the platform is built, from every service in the fleet — not just the one serving this page. Because it is a build-time snapshot it describes the code as of the build stamp shown under the heading, not each service's separately deployed version.
Module compliance surfaces¶
Compliance also appears in-context where it's enforced — for example recruitment compliance, HR statutory documents on the employee record, and the Labour Audit report.