S.V.E.N Inc.™

“No man was ever wise by chance.” — Attributed to Seneca

Business & Systems · Guide

Records, Files & Document Control

Put every contract, invoice, customer record, and file where your future self can find it — with naming rules, version discipline, and backups that survive staff turnover and disputed transactions.

What this guide covers

  • Customer, vendor, and engagement folder structure
  • File naming, dates, and version control
  • Document types: customer records, agreements, orders, invoices, inventory, IP, and consent records
  • Access credentials, licenses, tax records, and personnel files
  • Access control, backups, retention, and secure disposal
  • Minimum folder structure for a small operator
  • Why searching text messages is not document control

Document control versus “I’ll find it later”

Document control means you can retrieve the right version of the right record for the right customer or engagement within minutes — by someone who did not create the file. Searching your text message thread for “that file from March” is not control; it is archaeology. Control matters when a customer disputes an order, when a tax auditor asks for documentation, when an insurer requests proof of coverage, or when you need to defend a chargeback.

Small businesses fail records management in predictable ways: everything in downloads, files scattered across one person’s laptop or phone, contracts in email attachments with no folder copy, and “final_final_v3_REAL.pdf” naming. The fix is boring structure applied consistently, not expensive software on day one.

Customer, vendor, and engagement folders

Separate company records from customer/engagement records. Company-level holds licenses, insurance policies, tax filings, bank agreements, vendor agreements, and templates. Customer/engagement level holds everything tied to a specific relationship or transaction.

Two common patterns work for small operators. Customer-first: Clients/Smith-John/2026-041-Website-Redesign/ nests engagements under repeat customers. Engagement-first: Engagements/2026-041-Smith-Website-Redesign/ flat list sorted by reference ID. Pick one; mixing both creates duplicates.

Each engagement folder opens at first contact — not at invoice. Create it when the inquiry becomes a qualified proposal so any records from that stage have a home immediately. Minimum subfolders inside an engagement:

  • 01-Admin — proposal, contract, revisions, correspondence summary
  • 02-Records — photos, files, or other supporting material specific to the engagement
  • 03-Finance — invoices, payment confirmations, receipts
  • 04-Closeout — acceptance record, guarantee note, lessons learned

Align folder names with reference IDs on your status system from Work Lifecycle & Closeout System. When IDs match, nobody asks which “Smith engagement” you mean.

Naming, dates, and versions

File names should sort chronologically and identify content without opening the file. Pattern: YYYY-MM-DD_type_description_v##.ext. Example: 2026-03-12_proposal_brand-refresh_v01.pdf. When a proposal revises, increment version — do not overwrite v01 if it was sent to the customer. Keep sent versions; they are evidence.

Dates in names use ISO order (year-month-day) so folders sort correctly. Avoid “3-12-26” ambiguous formats. Document numbers from your billing system — EST-2026-018, REV-2026-018-b, INV-2026-0041 — should appear in the filename or prominently in the document header, matching Invoice, Payment & Collections sequences.

Version control rule: one authoritative “working” file if needed, but every version sent externally is immutable once sent. Email the PDF and save that exact PDF to the folder the same day. Editing the folder copy after send creates two truths.

For businesses that rely on photos — construction, real estate, repair, events, product staging — include date and stage: 2026-04-02_before_north-wall.jpg, 2026-04-08_progress_install.jpg. Phone auto-names are useless at scale — rename on upload or use an app that stamps a reference ID and date.

What belongs in the system

Customer records — contact information, preferences, order or engagement history, and consent or approval records such as signed agreements and marketing opt-ins. Vendor records — agreements, W-9s or equivalents, performance notes, and certificates of insurance where required. Proposals and contracts — every revision sent, with scope assumptions and expiration dates.

Inventory and product records — SKUs, stock counts, product specifications, and lot or batch numbers where traceability matters. Transaction history — invoices, receipts, refunds, and chargebacks. Photos, files, or other project records — site conditions, progress, completion, defects, or client walkthroughs, for businesses whose work produces them.

Intellectual property and digital assets — logos, source files, content libraries, and registered trademarks or copyrights. Access credentials — software logins, domain registrar access, and admin accounts, stored in a password manager rather than a spreadsheet. Privacy-sensitive data — anything containing personal or payment information, handled per the privacy laws that apply to your customers.

Licenses and permits — business license, trade or professional licenses, and any inspection sign-offs. Store company-wide copies at company level and engagement-specific permits in the engagement folder. Tax records — returns, quarterly filings, exemption certificates from customers, 1099s issued and received. Personnel files — onboarding paperwork, agreements, and training records, not mixed into customer folders and kept under restricted access discussed below.

Access, backups, and where files live

Access means who can view, edit, and delete. Owner and office admin: full access. Team leads: upload records and notes to assigned engagements; no delete on finance folders. Contractors and vendors with occasional access: share links to specific subfolders or deliverables — not your entire drive.

Use role-based sharing on cloud storage (Google Drive, Microsoft OneDrive, Dropbox Business, etc.) rather than one shared password. When someone leaves, revoke access the same day — especially if they used personal accounts to store company files.

Backups are not optional. Rule: three copies, two media types, one offsite. Cloud sync plus periodic export to an external drive or separate cloud account covers most small operators. Test restore quarterly — copy one old engagement folder back from backup and open the files. Untested backup is hope.

Phones and laptops are capture devices, not archives. Same-day upload from the field or from a device to the engagement folder. A lost device should not mean lost evidence for several active engagements.

Retention and secure disposal

Retention periods vary by document type, industry, and jurisdiction. Tax-related records often require seven years or more in many U.S. contexts; employment records have their own timelines; contracts may need keeping until the statute of limitations on claims passes; privacy-regulated customer data may carry its own retention and deletion rules. This guide does not prescribe periods — your CPA and attorney set them — but your system must support keeping records that long without chaos.

Practical approach: mark engagement folders closed at closeout; move closed engagements to an archive area yearly (Archive/2026/); never delete tax, payroll, or entity formation docs without professional advice. Active engagements stay in the working area; stale inquiries that never converted go to Leads-Not-Converted/ with a note, not mixed with paid work.

Secure disposal matters for personnel files, customer financial or payment data, and any document with Social Security numbers or account numbers. Deleting a file from trash is not destruction on synced drives — use platform secure delete or shred paper. When disposing of old hardware, wipe storage or destroy the drive. Customer data breaches from careless disposal create liability beyond the saved desk space.

Minimum folder structure

At company root:

  • _Templates — proposal, contract, revision, invoice templates
  • _Company — entity docs, insurance, licenses, bank, annual tax
  • _People — personnel and contractor files (restricted)
  • Engagements — one folder per reference ID with the four subfolders above
  • Archive — closed engagements by year

That structure supports billing disputes, guarantee follow-ups, and tax questions without a document management server. Add indexing spreadsheets later if search volume grows — but folders and consistent names come first.

Searching texts ≠ document control

Text threads, DMs, and platform chat logs are communication — not a filing system. They are searchable until they are not: phone upgrades, deleted threads, staff turnover, or a customer who switches numbers. Critical approvals, scope changes, and payment promises must be copied to the engagement folder the day they happen.

Workflow: customer texts “approved, proceed” — screenshot or export if needed, save to 01-Admin, reply with written confirmation referencing the proposal number, log the status change on the status board. Same for email: filing means saving the attachment and PDF, not leaving it in an inbox with 4,000 unread messages.

Accounting software, CRM, and order or job apps help but only if they receive the documents. The folder (or cloud equivalent) remains the source of truth for legal and guarantee questions years later when subscriptions have changed twice.

Checklist

  • Company root folders created: Templates, Company, People, Engagements, Archive
  • Engagement folder opens at proposal with ID matching status board
  • Naming convention documented: date, type, description, version
  • Sent proposals, revisions, and invoices saved as immutable PDFs
  • Records uploaded same day with date and stage in filename
  • Licenses, permits, and vendor COIs stored at the correct level (company vs engagement)
  • Personnel files separated with restricted sharing
  • Cloud backup plus tested restore process
  • Retention policy defined with CPA or attorney input
  • Critical customer approvals copied from text/email to the engagement Admin folder

Common mistakes

  • One device holds all records until it is lost or full
  • Overwriting sent proposals instead of versioning
  • Mixing personal and business files in one unsearchable downloads pile
  • Sharing an entire drive with vendors instead of engagement-specific links
  • No archive process — the active folder list grows for a decade
  • Assuming email search replaces filing
  • Deleting closed engagement folders to save space without a retention review
  • Personnel records in the same folder customers could see on a shared link

Minimum viable system

Cloud drive with the company root structure above. Engagement folder template duplicated for each new reference ID. Written one-page naming guide pinned in chat or on the office wall. Weekly habit: any loose desktop files filed or deleted. Monthly backup to an external drive or separate cloud account. Text approvals screenshotted to Admin the same day.

Upgrade later

Document management with OCR search; automated photo or file upload from a field or mobile app; CRM integration linking emails to engagements; e-signature platform with automatic archive; retention tags and legal hold flags; role-based audit log; encrypted storage for personnel; offsite immutable backup for tax years.

When professional guidance may be needed

Consult a CPA on tax record retention and how digital copies satisfy audit requirements in your state. Consult an attorney on contract retention and data privacy obligations if you handle sensitive customer information. Use IT or security specialists when setting up access controls for teams larger than a handful, or when regulations covering health data, payment data, or other protected categories apply. Shredding services and certified destruction may be required for certain industries.

Educational material only. Not legal, tax, privacy-compliance, or records-management certification advice. Retention rules and data-protection obligations vary by jurisdiction and industry.

Last reviewed: July 2026