Records, Retention & Data Management
Audits do not usually find wrongdoing. They find that nobody kept the paper. This page states what records are kept here, for how long, how they are protected, and how quickly they can be produced.
Record Classes and Ownership
Retention is impossible without classification. Records are grouped into classes, each with a named owner who is accountable for completeness rather than for storage volume.
- Contract records: awards, modifications, correspondence, deliverable submissions, and closeout documentation
- Cost and financial records: timekeeping, labor distribution, indirect rate support, invoices, and payment records
- Purchasing records: solicitations, quotations, justifications, price determinations, and executed orders
- Technical records: requirements, analyses, drawings, test data, review packages, and configuration baselines
- Quality and safety records: inspection results, nonconformances, corrective actions, hazard analyses, and training completion
- Personnel and security records held under their own access restrictions and retention rules
Retention Schedule
Retention periods are set from the governing requirement, not from habit, and they are written down so nobody has to guess whether something can be deleted.
- Retention periods derived from FAR Part 4.7, contract clauses, export regulations, tax and employment law, and customer direction
- The longest applicable requirement governs where multiple requirements overlap
- Retention clock defined explicitly, typically from final payment or contract closeout, and recorded with the record set
- Scheduled destruction executed only after verification that no hold applies, and recorded as a controlled event
- Litigation, audit, and investigation holds suspend destruction until released in writing
Protection and Access Control
A record has to survive and stay confidential at once. Protection is applied by sensitivity class rather than uniformly, so controlled information is not diluted by being treated the same as public material.
- Access granted on least privilege and reviewed when roles change or people depart
- Controlled unclassified information handled under the safeguarding practices described in the institution's cybersecurity posture
- Export-controlled technical data segregated with access limited to authorized persons
- Proprietary information belonging to customers, teammates, and suppliers marked, segregated, and used only for its authorizing purpose
- Backup and recovery of record repositories tested rather than assumed
- Audit logging of access to sensitive record classes
Retrieval, Audit and Customer Access
The government's right to examine records is meaningful only if retrieval is fast. The system is designed so an audit request is answered by production rather than by reconstruction.
- Indexing sufficient to locate a record by contract, date, program, and record class
- Defined response path for contracting officer, auditor, and inspector general requests
- Access and examination rights under FAR 52.215-2 supported without requiring a special project
- Single point of coordination so responses are complete, consistent, and reviewed before release
- Record of what was produced, to whom, and when
Closeout and Institutional Memory
Programs end; the obligation to answer questions about them does not. Closeout is treated as the moment institutional memory is converted from people into records.
- Closeout checklist covering deliverables, property, purchasing files, cost records, and technical data
- Final inventory verifying that each required record class is complete before the team disperses
- Transfer or return of customer records exactly as the contract directs
- Lessons learned captured into the knowledge management process rather than lost with the team
- Retained records placed under the schedule with a defined owner after the program organization dissolves
Where This Connects
Records discipline supports accounting system and internal controls, document control, knowledge management and lessons learned, the cybersecurity posture, and data protection.
Alignment Disclosure
Monarch Space Systems describes its business integrity, property accountability, records, and data rights practices as aligned with the cited federal regulations, agency supplements, and consensus standards. Alignment is not a determination. The institution does not claim an approved property management system, an audited records program, a government determination on any conflict of interest matter, or any specific contract, customer relationship, or property holding. Case-specific facts, disclosures, and filings are handled with the responsible contracting officer rather than published.
Policy documentation, procedures, and control descriptions are available to customers and prospective teammates through the confidential engagement pathway or by request through institutional contact.