Flume

Documents & assets · the paper trail

Paperwork that
expires on time.

A safety certificate nobody noticed lapsing is a person on the line who is not certified to be there. Documents in Flume carry versions, owners and expiry dates, warn before they lapse rather than after, and survive deletion as an audit record. Company equipment is tracked the same way — issued, returned, or written off, with the history to prove it.

Expiring documents · alert milestonesexample data
Work permitNour Hassan30d
Safety certificateKarim Adel14d
Medical clearanceMahmoud Ezzat7d
Driving licenceMona Fathy1d
Fire-safety cert.Ola Mansourtoday
Assets out on loan
LT-0912 · laptopBD-4471 · badgeTL-0034 · torque wrenchPH-2201 · handset · lost

Deleting is not erasing

The file goes. The fact that it existed does not.

Drag a document past its retention window and watch what actually happens: the stored object is removed, the restore option disappears — and the record stays behind as a tombstone naming who uploaded it, who deleted it and when. Those are two different operations, and only one of them is safe to do to an HR file.

Days since someone deleted the document — 12

rowDocument record · medical-clearance.pdfkept
metaWho uploaded it, who deleted it, whenkept
fileThe stored object itselfrecoverable
actionRestore from the recycle binavailable

A nightly job at 03:00 Cairo removes stored objects past the retention window. The document row is never hard-deleted — it stays as a tombstone marked purged, so the audit trail still shows the file existed and who removed it.

retention window30 days
restore window left18 days
file recoverableyes
audit rowretained
State on day 12Soft-deleted · restorableDeleting a file and erasing the fact it existed are different operations. Flume only ever does the first.

A nightly job at 03:00 Cairo purges stored objects past the window. The document row is never hard-deleted.

What ships

Files and equipment, both tracked as things that change hands.

01

Versioned documents

Upload a replacement and the previous version stays addressable, so “which copy did we act on?” has an answer.

02

Attached to anything

A document can hang off an employee, a candidate, an onboarding record, a leave request, an expense claim, a disciplinary case, an asset or the company itself.

03

Expiry dates

A document with a validity window is tracked against it, so “on file” and “currently valid” stop being the same claim.

04

Lapse alerts

Warnings at 30, 14, 7 and 1 days out and again on the day, to the document’s subject as well as HR where there is one.

05

Browse & search

Filter the whole store by type, owner, uploader and status rather than hunting through a per-employee folder tree.

06

Recycle bin

Deletion is reversible for 30 days — a restore, not a request to IT to find a backup.

07

Retention purge

Past the window the stored object is permanently removed on a nightly schedule, so deleted really does mean deleted eventually.

08

Audit tombstones

The document row survives the purge marked as purged, keeping the uploader, the deleter and the timestamps.

09

Bulk download

Pull a set of documents in one archive — for an audit request, an inspection, or a leaver’s file.

10

Asset register

Company equipment with an asset tag, category, serial number and current holder.

11

Issue, return, retire, lose

The four things that actually happen to equipment, each a recorded transition rather than an edited field.

12

Assignment history

Every hand-over kept per asset, so a laptop that has been through four people can still say who had it in March.

How it actually works

The mechanism, not the marketing.

Tombstone

The object is purged. The row is kept.

After the retention window a nightly job removes the stored file and marks the record purged — it never deletes the record. Hard-deleting the row would erase the evidence that a document was ever uploaded, which is precisely what someone disposing of an inconvenient file would want. Storage is reclaimed; the audit trail is not.

Milestones

Four warnings and a due date, not thirty daily emails.

Expiry alerts fire at 30, 14, 7 and 1 days out and again on the day. A daily reminder for a month trains people to filter the sender, at which point the alert that mattered is the one nobody read — the same milestone set contract alerts use, for the same reason.

Subject-aware

The alert goes to the person who can actually fix it.

Where a document has a natural subject — an employee, a leave request, an expense claim — both that person and HR are notified. Where there is no single subject, such as a company policy or an asset file, only HR is. Sending everything to everyone is how notifications stop being read.

State, not fields

An asset is issued and returned, never just edited.

Issue, return, retire and mark-lost are distinct transitions that each write history, rather than someone overwriting a “current holder” field. That is what makes the register answer questions after the fact: who had it, for how long, and what state it came back in.

Book a demo

Bring us your messiest month.

The fastest way to judge Flume is to run it against a period you already argued about. Send a month of punches and the payroll you produced from it, and we will show you the same month reconciled — including what the anomaly detectors flag.