Records Management
Records Management is the module through which Nashua 360 governs the full lifecycle of the organisation's records, from the moment content becomes a record of business through to its defensible destruction. It owns a single, unglamorous but consequential problem: keeping every record for exactly as long as law, regulation and business need require, and not one day longer, while proving at any moment that the organisation did so deliberately and consistently.
The module sits at the governance layer of the suite, beneath the operational modules that create records and above the storage and audit fabric that preserves them. Every document, transaction, message and dataset produced elsewhere in Nashua 360 can be brought under retention control here, classified against a regulatory scheme, held when litigation demands it, and disposed of under a repeatable, evidenced process. It is the system of record for what the organisation keeps, why, and for how long.
What the module does
Records Management provides the complete apparatus of a corporate records programme as a working system rather than a policy binder. At its core sit retention schedules that express, for every category of record the organisation holds, how long it must be retained, the event that starts the clock, and what happens when time expires. Records are classified against these schedules automatically at the point of capture or on demand, so that a contract, an invoice, a personnel file and a board minute each inherit the retention rules appropriate to their kind and jurisdiction.
On top of classification the module runs the three mechanisms that make a programme defensible. It places and lifts legal holds that suspend disposition across any set of records touched by litigation, investigation or audit, overriding the schedule for as long as the matter is live. It executes disposition, the reviewed, authorised progression of an eligible record towards destruction or permanent archival. And it maintains an immutable archive in which records designated for long-term or permanent preservation are stored in unalterable form, sealed against edit or deletion, with regulatory classification travelling alongside each one. Together these give the organisation continuous control over what exists, what is frozen, and what may finally be destroyed.
The domain and data model
The conceptual centre of the module is the record itself: a unit of content that the organisation has determined it must account for. A record is not merely a file. It is content plus the obligations attached to it, and the module's job is to keep those obligations bound to the content for the whole of its life. Around this idea sit three relationships that do the real work.
The first is between a record and its retention schedule. A schedule expresses a rule in business terms: keep tax records for seven years after the end of the financial year, keep clinical records for the lifetime of the patient plus a fixed span, keep tender submissions for a defined period after award. When a record is classified, it takes on the relevant rule, and from that rule the module derives the moment it becomes eligible for disposition. The second relationship is between a record and any legal hold placed over it. A hold is a claim asserted by a person accountable for a matter, and while it stands it silences the schedule entirely, so no held record can leave the system regardless of how much time has passed. The third relationship is between a record and its own history: every classification, hold, review and disposition decision is captured as an unbroken chain of events, so the record carries the evidence of its own governance. These few concepts, a record, the rule that governs it, the hold that can override that rule, and the history that proves both, are enough to describe the entire domain in plain terms.
Principal workflows
Records enter governance either automatically, as operational modules declare their outputs, or through deliberate capture, when a user or an automated process designates content as a record. Classification follows immediately: the record is matched to a category and inherits its schedule, its regulatory tags and its jurisdiction. From that point the record simply waits, its retention clock running against the triggering event, whether that is a date of creation, a contract expiry, an employee's departure or the close of a fiscal period.
When a matter arises, a records officer or legal owner raises a legal hold and scopes it by criteria: a custodian, a subject, a date range, a category. Every matching record is frozen, and any record created later that meets the scope is swept in as well, so the hold stays complete without manual policing. When the matter resolves, the hold is released and the affected records return to their schedules.
The most consequential workflow is disposition. As records reach eligibility the module assembles them into disposition reviews and routes them to the accountable owners, who confirm that nothing bars destruction, that no hold applies and that no residual business need remains. Only after authorised sign-off does the module carry out the outcome: secure, irreversible destruction with a certificate of destruction retained as evidence, or transfer into the immutable archive for records with enduring or permanent value. Nothing is destroyed silently and nothing lingers unreviewed.
Functional depth that matters
A records programme is only as good as its defensibility, and the module is built around that standard. Retention schedules support event-based, time-based and combined triggers, multiple concurrent citations so a single record can answer to several regulators at once, and jurisdiction-specific variants so that the same category retains differently in different territories. Where obligations conflict, the module applies the longest applicable retention and records the reasoning, so the organisation is never caught keeping too little.
Classification aligns to recognised information-governance practice, mapping records to a controlled file plan and to regulatory categories covering financial, tax, employment, health, privacy and sector-specific regimes. Legal holds are absolute by design: while a hold stands, disposition is impossible, deletion is impossible, and the attempt itself is logged. The immutable archive enforces genuine write-once preservation, with cryptographic sealing and integrity verification so that a stored record can be shown to be unchanged since the day it was archived. Every action across the module, classification, hold placement, review, destruction and archival, is written to a tamper-evident audit trail that constitutes the evidence an auditor, regulator or court would demand. Certificates of destruction, hold registers and disposition histories are producible on request, so the organisation can demonstrate not only that it followed its policy but that its policy was applied uniformly and without exception.
How it fits the Nashua 360 suite
Records Management governs content the rest of the suite produces, so it is wired into the modules that generate records of consequence. It draws documents and their metadata from Document Management, applying retention and classification to the content library at source. It receives financial records, ledgers and statements from Finance and Accounting and applies statutory retention to them automatically. It governs personnel files, contracts and disciplinary records surfaced by Human Resources, honouring both employment-law retention and privacy-driven minimisation. Contracts and their supporting evidence flow in from Contract Lifecycle Management, and case files, tenders and correspondence from the relevant operational modules.
Legal holds coordinate with Legal and Compliance, so that raising a matter there can freeze the associated records here without duplicate effort. Access to records, and to the actions that govern them, is enforced through the suite's shared Identity and Access controls, and every governance event feeds the platform-wide audit and reporting fabric. Because the module operates on the same data plane as the modules it governs, retention is not a bolt-on applied after the fact but a property records carry from the instant they are created anywhere in Nashua 360.
How AI Workers operate inside it
AI Workers are first-class participants in the records programme, not an overlay on it. They answer conversational questions against the module's data, so a records officer can ask which categories are approaching a schedule change, how many records a proposed hold would freeze, or what remains under a hold that should have lifted, and receive a precise, sourced answer. They execute actions within their authority: classifying newly captured content, applying a hold's scope across the estate, assembling disposition reviews and preparing destruction batches for human authorisation.
Their extraction ability makes classification accurate. An AI Worker reads an incoming document, identifies its type, its jurisdiction, its triggering event and the citations that govern it, and proposes the correct schedule, turning unstructured content into a properly governed record. They monitor continuously for anomalies and exceptions: records that escaped classification, holds that overlap or contradict, disposition eligibility that conflicts with an active matter, or destruction volumes that deviate from the expected pattern, and they raise these for attention before they become failures. In decision support they weigh conflicting retention obligations and recommend the defensible outcome. And they stand as named nodes in the module's workflows, participating in disposition and hold reviews as an approval or review step, applying policy consistently, recording their reasoning in the same audit trail as any human reviewer, and escalating anything that requires a human judgement they are not authorised to make.
