Skip to contentSaltar al contenidoAle nan kontni anПерейти к содержимомуדלג לתוכן
EstateDraftFL

For Florida law firms

Retention: the firm's policy, what it makes eligible, and the deletion of an eligible matter with its receipt

firm lane · Deterministic — no model call

Current availability

ShippedConfigured and enabled: firm staff of the active firm (the direct consumer account has no retention policy).

Where it lives
Firm settings → Records (/firms/manage/records) · the matter's Records (/admin/matter/[id]/records) · /api/admin/retention
What unlocks it
the firm's own staff read the policy and its report; an attorney or administrator of the firm sets the policy, deletes an eligible matter and reads the receipts

Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.

Capabilities

  • ShippedThe firm records how many years after a matter closes its records are kept (1 to 25, or none), and can pause deletions at any time — each change with who, when and why, kept as the policy's record.
  • ShippedA closed matter becomes eligible once that many years have passed since the day it closed; the report shows every closed matter the viewer can open — eligible, kept by a legal hold, kept until a date, or kept because its close date is not on the record — a dry run: nothing is deleted from it.
  • ShippedNothing is deleted by itself: an attorney or administrator deletes an eligible matter from its Records, typing its name; the database deletes the matter and everything that carries it in one transaction, and a legal hold — standing, or placed while it runs — refuses it for every role, so nothing is deleted.
  • ShippedIts stored files are listed before (a listing that fails deletes nothing) and removed after, and its folders walked again to prove them empty; a removal left unfinished is finished from the receipt.
  • ShippedThe firm keeps a deletion receipt: which matter, when it closed, the period it was deleted under, how many stored files were found and when they were proven gone, who deleted it and when — its attorneys' and administrators' to read.
  • ShippedThe records that outlive a matter keep it as a plain id: the audit trail, billing and payments, the purchases and the consents behind them, the grant ledger, the AI ledger, the attorney's conflict checks, the vault's custody records, the lifecycle and hold records. Its unused invitations are revoked and its workspace runs go with it.
  • ShippedThe matter's people stay in the firm's conflict index, marked as the deleted matter's, so a later conflict screen still finds a former client or an adverse party; the receipt counts the names and the conflict checks kept.
  • ShippedA screen taken before the deletion still names the deleted matter's people to the firm as that deleted matter's entries, so an attorney can still decide a finding on one of them and the hold waiting on it can clear.
  • ShippedThe nightly file backup lets a deleted file's copy and name go once the backup's window has passed.

Limits

  • The platform sets no retention period: the firm chooses its own under its own obligations; with none, every record is kept.
  • A matter closed before the lifecycle was recorded, with no close on its audit record, has no close date — it is kept, never deleted by the policy.
  • Backup copies of a deleted matter's files stay in the nightly backup for its window (35 days by default) and then leave it — a restore never brings a deleted file back unless asked.
  • The direct consumer account has no retention policy: a person's own matters are theirs to delete.
  • A deleted matter's walls end with it: its people's names in the conflict index are screenable by the firm's staff (what a conflict index is for); an earlier namesake decision about one of them is not carried to the kept name, so a later screen may ask again.

What EstateDraftFL refuses

Reason codeHTTPWhat it means
not-authorized403An attorney or an administrator of the firm, able to open the matter, sets the policy and deletes an eligible matter.
firm-staff-only403Only the firm's own staff act on its retention; a support session reads.
invalid400A period is 1 to 25 years or none, a change needs its reason, and a deletion needs the matter's name typed exactly.
not-a-firm409Retention policies are a firm's — the direct consumer account has none.
no-policy409The firm has set no retention period, so every record is kept — nothing was deleted.
not-yet409The matter is still inside the firm's retention period — nothing was deleted.
held409A legal hold keeps the matter — nothing was deleted.
paused409The firm has paused deletions — nothing was deleted.
unknown-close409The matter's close date is not on the record, so it is kept — nothing was deleted.
open409Only a closed matter is deleted under the retention policy — nothing was deleted.
unavailable503The matter, its files or the change could not be read or recorded just now — nothing was deleted.

Evidence

  • supabase/migrations/20260927110000_phase10c_retention.sql
  • supabase/migrations/20260927120000_phase10c_retention_conflict_history.sql
  • supabase/migrations/20260927130000_phase10c_party_index_sources.sql
  • supabase/migrations/20260927140000_phase10c_screens_deleted_matter.sql
  • supabase/migrations/20260927150000_phase10c_retention_enterprise_firms.sql
  • src/app/api/admin/retention/route.ts
  • src/app/firms/manage/records/page.tsx
  • src/app/admin/matter/[id]/records/page.tsx
  • src/lib/retention/policy.ts
  • src/lib/storage-inventory.ts
  • src/lib/storage-backup.ts
  • src/lib/account-data.ts
  • docs/security/MASTER-PLAN-PHASE10C-PART3-2026-09-27.md

Last reviewed 2026-09-27

← All surfaces