Regulated manufacturers cannot delete engineering history when they retire a system. Design records, change approvals, controlled documents and the trail linking them preserved under retention lock, with access logged and chain of custody evidenced from the Agile source forward.
Audit questions about product history are rarely about the current revision. They are about what was approved, by whom, on what date, against which drawing, and what changed afterwards.
In Agile that evidence is spread across objects. The approval and status information sits on the change order. What changed sits in the redlines and the affected-items list. The controlled document sits in the vault, attached to a specific revision. The manufacturer that was approved for a part at the time sits in the AML on that revision. Answering one question means traversing all of them.
A compliance archive has to preserve that traversal, not just the documents. Flattening the record to a folder of PDFs produces something you can read but cannot interrogate: no where-used, no revision comparison, no way to show that the drawing you are holding is the one that was approved by the change you are citing.
Retention then has to be enforced rather than declared. Different slices of PLM data commonly carry different periods, so the archive is zoned by regime, each zone carries its own retention lock, and every read is recorded with identity and timestamp so the access trail is itself evidence.
The difference between preserving data and preserving evidence.
Each data slice carries the retention period its regime requires, enforced by immutable storage rather than by process.
Every query and download recorded with identity and timestamp, which is what an inspector asks for after they have seen the record.
Checksums recorded at extraction and re-verified in place, so silent corruption is detected rather than assumed absent.
Export-controlled technical data restricted by role and region, because an archive that is readable by everyone creates a new problem.
Specific products, changes or date ranges can be held beyond their normal retention when litigation or an investigation requires it.
Reconciliation by object family against the Agile source, produced once and retained, so the archive's completeness is documented.
Regime mapping first. Everything downstream depends on getting the zones right.
Work out which regimes apply to which slices: quality records, design history, export-controlled technical data and general engineering history rarely share a retention period.
One retention zone per regime, each with its period, its access rules and its residency constraint agreed in writing.
Objects and files pulled with counts and checksums, and the extract hash-signed so chain of custody starts at the source.
Role-scoped search and retrieval with read logging enabled from the first query, not switched on later.
Retention applied per zone, reconciliation pack produced against the source baseline, and the whole thing signed off with compliance.
Regulatory enquiries about product history follow a recognisable shape. They start narrow, widen to the surrounding record, and end with questions about the archive itself rather than about the product.
An archive that can answer the last two comfortably is doing something the original Agile deployment usually could not.
Three arrangements that look compliant until somebody tests them.
Kept alive purely for audit, running unsupported software, with access controls nobody has reviewed since the last person who understood it left.
Documents without the record around them. You can produce a drawing but not show what approved it or what superseded it.
Restorable in principle. In practice the restore is untested, the retention is not enforced, and nothing records who read what.
It varies by sector and most manufacturers carry several at once. Quality-management record requirements under ISO 9001 and IATF 16949, design history and device history records under FDA 21 CFR Part 820, electronic records and signatures under 21 CFR Part 11, aerospace quality records under AS9100, and export-controlled technical data under ITAR or EAR are the ones that come up most in PLM. Each brings its own retention period, access restriction and evidence expectation, which is why the archive is zoned rather than treated as one undifferentiated store.
By the storage platform, using object-level retention locks that hold data unalterable for the regulated window. Inside that window the record cannot be modified or deleted by a user or by a storage administrator, which is the property that distinguishes a compliance archive from a well-organised copy. Retention is applied per zone, so a ten-year quality record and a shorter-lived engineering record are not forced onto the same period.
Yes, and it is not optional. Every search, view and download is recorded with the identity of the reader and a timestamp. That matters twice over: it evidences that controlled technical data was only seen by people entitled to see it, and when an inspector asks who accessed a record during an investigation the answer comes from the log rather than from memory.
That is what the sign-off pack is for. Counts are reconciled by object family between the Agile source and the archive, every vault file carries a checksum recorded at extraction and verified in the archive, and the extract itself is hash-signed. The chain runs from the Agile source, through the extract, to the archived record, and each link is evidenced rather than asserted.
Through residency and access control together. The archive is placed in a region that satisfies the control regime, and read access is scoped by role and by user nationality or location where the regime requires it. Because access is logged, there is a positive record of who viewed controlled drawings and specifications, which is usually easier to produce from the archive than it was from the original Agile deployment.
Specific products, change orders, document sets or date ranges can be held beyond their normal retention period, independently of the zone they sit in, and released when the hold lifts. Holding is applied at the record level rather than by freezing the whole archive, so an investigation into one product line does not suspend routine retention expiry across everything else.
Book a call with our compliance team. Bring your retention obligations and we will map them to Agile objects, propose the retention zones and show you what the sign-off pack contains.