01
Versioned documents
Upload a replacement and the previous version stays addressable, so “which copy did we act on?” has an answer.
Documents & assets · the paper trail
A safety certificate nobody noticed lapsing is a person on the line who is not certified to be there. Documents in Flume carry versions, owners and expiry dates, warn before they lapse rather than after, and survive deletion as an audit record. Company equipment is tracked the same way — issued, returned, or written off, with the history to prove it.
Deleting is not erasing
Drag a document past its retention window and watch what actually happens: the stored object is removed, the restore option disappears — and the record stays behind as a tombstone naming who uploaded it, who deleted it and when. Those are two different operations, and only one of them is safe to do to an HR file.
Days since someone deleted the document — 12
A nightly job at 03:00 Cairo removes stored objects past the retention window. The document row is never hard-deleted — it stays as a tombstone marked purged, so the audit trail still shows the file existed and who removed it.
A nightly job at 03:00 Cairo purges stored objects past the window. The document row is never hard-deleted.
What ships
01
Upload a replacement and the previous version stays addressable, so “which copy did we act on?” has an answer.
02
A document can hang off an employee, a candidate, an onboarding record, a leave request, an expense claim, a disciplinary case, an asset or the company itself.
03
A document with a validity window is tracked against it, so “on file” and “currently valid” stop being the same claim.
04
Warnings at 30, 14, 7 and 1 days out and again on the day, to the document’s subject as well as HR where there is one.
05
Filter the whole store by type, owner, uploader and status rather than hunting through a per-employee folder tree.
06
Deletion is reversible for 30 days — a restore, not a request to IT to find a backup.
07
Past the window the stored object is permanently removed on a nightly schedule, so deleted really does mean deleted eventually.
08
The document row survives the purge marked as purged, keeping the uploader, the deleter and the timestamps.
09
Pull a set of documents in one archive — for an audit request, an inspection, or a leaver’s file.
10
Company equipment with an asset tag, category, serial number and current holder.
11
The four things that actually happen to equipment, each a recorded transition rather than an edited field.
12
Every hand-over kept per asset, so a laptop that has been through four people can still say who had it in March.
How it actually works
After the retention window a nightly job removes the stored file and marks the record purged — it never deletes the record. Hard-deleting the row would erase the evidence that a document was ever uploaded, which is precisely what someone disposing of an inconvenient file would want. Storage is reclaimed; the audit trail is not.
Expiry alerts fire at 30, 14, 7 and 1 days out and again on the day. A daily reminder for a month trains people to filter the sender, at which point the alert that mattered is the one nobody read — the same milestone set contract alerts use, for the same reason.
Where a document has a natural subject — an employee, a leave request, an expense claim — both that person and HR are notified. Where there is no single subject, such as a company policy or an asset file, only HR is. Sending everything to everyone is how notifications stop being read.
Issue, return, retire and mark-lost are distinct transitions that each write history, rather than someone overwriting a “current holder” field. That is what makes the register answer questions after the fact: who had it, for how long, and what state it came back in.
Book a demo
The fastest way to judge Flume is to run it against a period you already argued about. Send a month of punches and the payroll you produced from it, and we will show you the same month reconciled — including what the anomaly detectors flag.