unforged/folio · docs

How folio will work

You’ll file a record and get a receipt for it, and folio will keep it for as long as its class says.

The parts

Record
One filed document and its details. Filing will give you a receipt with its SHA-256 and SHA-512 fingerprints.
Folder
Where you file a record, usually one per person, case or property. You’ll be able to protect a folder so that every view in it needs a reason.
Retention class
How long a record is kept. A Retained record will be kept until retention ends, and deleted early only by two people with a reason. A Locked record will be write-once: nobody, including you and us, will be able to change or delete it before its retention ends.
Reason
Every view, change and deletion will be recorded with a reason. Your organisation will choose whether views need one; changes and deletions always will.
Hold
Keeps records from being disposed of while a matter is open. Releasing one will take two people.
Ledger
The history of everything that happens to your records. It will be chained, time-stamped and exportable for your auditors.

That’s an auditing feature you set for your organisation, not something the law asks of you.

The ledger and receipts

Every event will be chained to the one before it and time-stamped by an outside authority. You’ll be able to export the ledger for your auditors, and a changed or missing entry will show up when it’s checked.

The API

The same routes will serve the web app and your own code. Each will need an API key with the right permission, and changes and deletions will need a reason, as will views if your organisation asks for one.

Filing

  • POST /folio/records
  • POST /folio/filings
  • GET /folio/filings/{id}
  • POST /folio/records/from-check

Records

  • GET /folio/records
  • GET /folio/records/{id}
  • GET /folio/records/{id}/content
  • POST /folio/records/{id}/move
  • POST /folio/records/{id}/retention

Folders

  • GET /folio/folders
  • POST /folio/folders
  • GET /folio/folders/detail
  • POST /folio/folders/protect

Reasons

  • POST /folio/reasons
  • DELETE /folio/reasons/{id}

Holds and approvals

  • POST /folio/holds
  • GET /folio/holds
  • POST /folio/holds/{id}/release
  • GET /folio/approvals
  • POST /folio/approvals/{id}/approve

Exports and reports

  • POST /folio/exports
  • GET /folio/exports/{id}
  • GET /folio/exports/{id}/download
  • GET /folio/records/{id}/custody
  • GET /folio/records/{id}/integrity
  • GET /folio/residency

Links

  • POST /folio/records/{id}/link
  • GET /folio/links/{token}

Classes and settings

  • GET /folio/classes
  • POST /folio/classes
  • GET /folio/config
  • PATCH /folio/config

Search

  • GET /folio/search

Ledger, usage and webhooks

  • GET /folio/ledger
  • GET /folio/usage
  • GET /folio/webhooks
  • POST /folio/webhooks

We’ll publish the full reference, folio.yaml, when folio is generally available.

Filing, exports, links and webhooks

Filing
File one document, or queue a batch and follow each one. Files will be checked for malware first, and one that fails won’t become a record.
Exports and reports
You’ll be able to take records out with their receipts and ledger, or get a custody or integrity report on one record for your auditor.
Links
Share one record with someone who has no account, through a link that expires. Each open will be recorded in your ledger.
Webhooks
We’ll tell your systems when a record is filed, and sign each message so you can check it came from us.

folio is designed to support your record-keeping obligations under UK GDPR and GDPR, and the long-term keeping of electronically signed documents.