Answer Capsule: A contractor record retention policy is not “keep everything seven years.” Apex Prometheus defines it as a controlled chain that connects each record series to its authority, scope, trigger, approved duration, custodian, repositories, hold status, disposition approval, execution evidence, and readback. The period depends on the record and the rules that actually apply. An archive is not a policy. Eligibility is not permission to delete. A completed deletion command is not proof that every intended copy is gone.

That distinction matters on a real job. A project manager closes a Staten Island renovation. The office has contracts in the project platform, change orders in email, progress photos on two phones, payroll support in accounting, safety records in another system, and a closeout export sitting in somebody’s Downloads folder. Slapping “seven years” on the folder does not tell the shop what the clock starts from, which copies are controlled, whether a claim has frozen deletion, or who can authorize destruction.

It only gives everybody a number to hide behind.

The Seven-Year Shortcut Is Not a Control

Contractors do not produce one kind of record. We produce bids, contracts, drawings, revisions, daily logs, submittals, RFIs, change orders, lien documents, invoices, payroll support, tax support, safety files, employee records, customer messages, photos, videos, equipment logs, insurance correspondence, warranties, and closeout packages.

Those records do not all answer to one authority or one trigger.

The IRS says the length of time a business should keep a document depends on the action, expense, or event the document records. Its guidance separately identifies an at-least-four-year period for employment-tax records. OSHA’s rule for covered injury and illness records specifies five years after the end of the calendar year those records cover, with scope and maintenance details in the controlling rule. Those two official examples alone break the lazy idea that one universal number can run the whole shop.

They are examples, not a contractor schedule and not legal advice. Tax, employment, safety, privacy, contract, insurance, claim, and jurisdiction questions belong with qualified reviewers using current sources.

Build the Schedule by Record Series, Not by Folder Name

A usable construction document retention schedule starts with record series. “Project files” is usually too broad. Break the pile into controlled groups such as executed contracts, bid worksheets, approved change orders, daily reports, safety logs, payroll support, final drawings, warranty records, and site photography.

For every series, capture:

  • What is included and excluded
  • The business purpose
  • The source and authority
  • The jurisdiction, project, contract, and entity it applies to
  • The approved duration
  • The event that starts the clock
  • The owner and custodian
  • Every known repository and copy type
  • Any hold or exception rule
  • The authorized disposition method
  • The reviewer, approval state, and review date

The trigger must be an event you can prove. Depending on the approved rule, that might be creation, supersession, project completion, final payment, contract termination, employment separation, asset disposition, or audit closure. “Old file” is not a trigger. Neither is “the PM thinks the job wrapped up around spring.”

If final payment starts the clock, keep the raw payment event, timestamp, source, and any correction. If contract termination starts it, identify the controlling contract and termination evidence. A retention engine running on bad trigger data is just a faster way to make a bad decision.

Your Policy Screen Does Not Know Where Every Copy Lives

A Brooklyn contractor can configure a policy in Microsoft 365 or Google Workspace and still miss the field copies. The same project photo may exist in email, a shared drive, a project platform, a superintendent’s phone, a text thread, an exported ZIP file, a backup, and a subcontractor-controlled system.

That is why repository mapping comes before disposition.

List email, cloud drives, CRM, accounting, HR, safety tools, project platforms, mobile devices, paper storage, shared links, local downloads, exports, archives, backups, personal-device exceptions, and third-party custody. For each location, record whether the policy actually reaches it and how that coverage was verified.

Vendor settings are not legal authority. Google Vault and Microsoft Purview document detailed product-specific retention and hold behavior, but software coverage, licensing, precedence, propagation, deletion, purge, export, and audit behavior must be checked in the authorized environment. A green toggle on one admin screen cannot speak for ten repositories.

A Hold Has to Stop the Blade

Suppose a $2.4 million contractor receives notice of a payment dispute on a $185,000 project. The ordinary schedule says a batch of project communications is eligible for disposition. The dispute says preserve relevant information.

The system must stop.

A legal, investigative, audit, claim, or dispute hold needs a matter identity, issuing authority, scope, custodians, systems, preservation actions, notices, acknowledgments, exceptions, monitoring, authorized release, and post-release reconciliation. If any of those are unknown, deletion stays blocked.

AI can help locate candidate custodians, compare repository inventories, assemble a review packet, and flag records that intersect the matter. It must not issue, narrow, or release the hold. That authority belongs to named, qualified people.

Eligible Does Not Mean Authorized

A record can reach the end of an approved period and still be protected by a hold, contract exception, open claim, incomplete repository map, disputed trigger, or review requirement.

Treat eligibility as the start of a bounded decision, not the end.

Before any real disposition, build a candidate batch with:

  1. The exact record series and approved rule
  2. The trigger event and supporting evidence
  3. The date calculation
  4. The repositories and copy types in scope
  5. Hold and exception checks
  6. Preview counts and exclusions
  7. A named human approver
  8. A fail-closed preflight
  9. The approved method and executor
  10. A plan for receipts, failures, surviving copies, and readback

Consider a synthetic office scenario. A review finds 18,400 candidate files across three systems. At a loaded administrative cost of $42 per hour, manually opening every file for just one minute would represent about 307 hours, or roughly $12,894 of labor. That arithmetic does not prove savings from AI. It shows why classification, deduplication, batching, and exception flags are worth designing—while the approval decision remains human.

The alternative is paying a software reseller to turn on broad deletion, then paying lawyers, IT specialists, and recovery vendors when the scope was wrong. The middleman gets the subscription. The contractor owns the damage.

Secure Disposition Depends on the Material and the Risk

Delete, purge, sanitize, destroy, and dispose are not interchangeable words.

Removing a database row is different from clearing recoverable media. Shredding paper is different from handling an encrypted drive. Deleting a working copy is different from addressing backups or vendor-held exports. The correct method depends on sensitivity, media, custody, platform behavior, business needs, and qualified review.

NIST Special Publication 800-88 Revision 2 provides current risk-based media-sanitization guidance and calls for consultation with privacy, records, and business officials. It should not be twisted into one universal deletion recipe for every contractor record.

The policy should name the approved method by series and environment, not let an operator improvise during a cleanup Friday afternoon.

Proof Means Receipts Plus Readback

A successful API response proves that an API returned success. A vendor certificate proves that a vendor issued a certificate. Neither automatically proves every intended copy is gone.

For each authorized disposition event, capture the decision, approver, scope, method, executor, time, tool or vendor receipt, result, omissions, failures, surviving copies, exceptions, and corrections. Then read the destination state back from the systems that were supposed to change.

Do not preserve the sensitive content merely to prove it was destroyed. Preserve the minimum evidence needed to show what rule ran, what population was approved, what happened, what failed, and what was verified.

Apex Prometheus uses the same field-first standard behind the Churchill proof model: test controls against a real contractor operating context before presenting them as production-ready. For retention and disposition, that means synthetic records and bounded review first. It does not mean touching live customer, employee, tax, safety, claim, or legal files without authority.

What AI Can Do Without Taking the Foreman’s Keys

AI can inventory repositories, propose record classifications, retrieve current sources, extract possible triggers, compare rules, flag conflicts, assemble candidate batches, and detect missing evidence. That is useful work.

AI must abstain when authority, applicability, jurisdiction, hold status, repository coverage, permission, or readback is unknown. It must not choose a legal period, approve policy, release a hold, execute live deletion, or declare complete disposition.

The Policy-to-Proof Checklist

Before configuring deletion, make sure the shop can answer:

  • Which current source controls this record series?
  • Does it apply to this entity, jurisdiction, contract, and event?
  • What exact event starts the period?
  • Who owns the record and where do all known copies live?
  • Is any hold, claim, audit, or exception active?
  • Who may approve the candidate batch?
  • Which disposition method is authorized?
  • What receipt will execution produce?
  • How will failures and surviving copies be handled?
  • How will the actual destination state be read back and corrected?

If one answer is missing, the control is not ready. Do not let a vendor dashboard, an old spreadsheet, or an AI-generated number make the decision for the people who carry the risk.

Frequently Asked Questions

Is seven years a universal contractor retention rule?

No. The correct duration can depend on record type, authority, jurisdiction, contract, tax treatment, employment rule, safety rule, claim, insurer requirement, business need, and trigger event. Build a source-linked schedule and route applicability to a qualified reviewer.

When does a contractor record retention period start?

It starts from the trigger defined in the approved rule. Possible triggers include creation, supersession, project completion, final payment, contract termination, employment separation, asset disposition, or audit closure. Record the event and its evidence explicitly.

Does a legal hold override scheduled deletion?

A valid legal or investigative hold can require relevant information to be preserved despite an ordinary schedule. Authorized, qualified people must direct its scope, system coverage, monitoring, and release. If hold status is unknown, disposition stays blocked.

Is an archive or backup the same as a retention program?

No. An archive or backup preserves copies. A retention program defines record series, sources, applicability, triggers, approved periods, repositories, holds, authorization, disposition methods, evidence, exceptions, and corrections.

Who can approve destruction of contractor records?

Only a named person with authority under the approved policy and qualified-review process. Authority can vary by record, organization, contract, matter, jurisdiction, and system. AI should never supply or assume it.

Come see what time it is — apexprometheus.ai