Pan Innovation House Pan Innovation House
CUSTOM SOFTWARE · DOCUMENT AND CONTENT MANAGEMENT

Document Management: A Single Correct Copy of Every Record

We take the company's paperwork out of folders and personal computers and move it into a single archive. Every document's version, who may see it, which approval it passed through and how long it will be kept are defined in the system; the document you are looking for is found in seconds rather than minutes, and its history can be evidenced in an audit. A DMS manages the document itself; ECM covers the process and the content that flow with it.

Ask where a document is in a company and the answer is usually the same: on someone's computer, in a folder, maybe in an email. Who holds the latest version of the quality procedure, the date the supplier's certificate arrived, which cabinet holds the original signed delivery note — all of it is carried in people's memories. While things are going well, this arrangement holds. When an audit arrives, when a customer asks for a document going back years, or when the person who knew that document leaves, the search begins. As irritating as the length of the search is the inability to be sure that the document found is the latest version. Three copies of the same file named final, final_revised and final_real is a common sight in the field. Which of those three went to production is usually a question nobody asks.

A shared network folder or cloud drive brings relief at first, but past a certain volume it creates a problem of its own. As the folder tree grows nobody knows where to save; the same document lands in two different places under two different names. Because permissions are granted at folder level, either everyone sees everything or someone has to grant access each time. Who changed a document, when and why is not recorded. Most importantly, because nowhere states how long a document will be kept and when it should be destroyed, the archive grows without end; a quotation file from ten years ago sits in the same place, with the same weight, as this month's signed contract.

A document management system (DMS) turns a document from a file into a record. Every document has an owner, a type, a version history and a permission that determines who it is open to; changes do not overwrite, they accumulate as new versions and the old version stays readable. Enterprise content management (ECM) goes a step wider: alongside the document it also takes in the process around it, its metadata, its retention and destruction rules, its evidential value and content arriving through different channels. Put roughly, a DMS answers the question where is this document and in which version, while ECM answers how did this content come about, whose hands did it pass through, how long will it live and how will it be evidenced. For a small archive need a DMS is enough; in a structure carrying quality, legal and audit load the work widens towards ECM of its own accord.

The most common mistake in setting this up is copying the existing folder structure into the new system as it stands; the result is a more expensive version of the same mess. So document types, owners and retention periods are discussed first, and migration comes afterwards. Let us state the boundary up front as well: the part that reads a document's content and extracts data from it we treat as a separate module; the system on this page stores, versions, permissions and finds documents. In regulated areas such as electronic signature and registered electronic mail we do not take the place of licensed service providers, we connect to their infrastructure. Nor do we usually recommend scanning an entire twenty-year paper archive; in most companies the right decision is to start properly from today and bring across from the past only the files still in use.

Who is it for?

Who is Document and Content Management (DMS / ECM) a good fit for?

Manufacturing companies that face audits

Factories that meet ISO 9001, customer audits or document requests arising from exports. The current version of procedures, work instructions, forms and records has to be demonstrable. Being able to pull up the document the auditor asks for from a single screen, rather than searching for it, removes the most time-consuming part of an audit. Because the audit trail is held in the same system, the question of who approved the document and when does not go unanswered.

Firms whose paperwork is scattered across individuals

Companies where contracts, quotations, minutes and technical files sit on employees' computers or in personal mailboxes. In that structure the knowledge belongs to the individual rather than to the organisation; one departure or one hardware failure can make years of paperwork inaccessible. The first concrete benefit of a central archive is breaking that dependency. Backup also becomes something that can be done from a single point.

Organisations carrying legal, tender and official correspondence load

Organisations that bid for tenders, correspond with public bodies or run large numbers of contracts. Here it is not enough for a document simply to be found; which version is valid, who approved it and how long it must be kept must also be demonstrable. A registration number, an incoming and outgoing correspondence register and a retention schedule are basic requirements for these structures.

Multi-site teams and teams working in the field

Businesses with branches, warehouses, construction sites or a dealer network. An instruction updated at head office has to reach everyone in the field at the same time, and the minutes and photographs produced in the field have to reach head office in an orderly way. Mobile access and working over a weak connection are the decisive parts of this kind of installation; otherwise the field goes back to its own messaging group.

What we build

What we deliver within Document and Content Management (DMS / ECM)

Central archive and document header data

Every document is stored together with its type, owner, relevant unit, date, validity period and related record. Instead of a file buried in a folder tree, you get a record with its fields filled in. The same document sits in one place; other processes link to it rather than taking a copy of it. The header fields are defined according to the company's own terminology, not fitted to a ready-made template.

Version, revision and effectivity control

When a document changes the old one is not deleted; a new version is created and the old version stays readable in the history. Which version is in force is clear in one place, and the user normally sees only the version in force. The reason for the revision and the person who made the change are recorded. The revision number and issue date that quality documents require are handled by the system rather than by hand.

Approval workflow and publishing

A new procedure, quotation or draft contract cannot come into force without passing through a defined approval chain. Who holds approval authority for which document type can vary by unit or by value. A document awaiting approval is flagged to the person responsible, and a record that has been waiting a long time can be escalated to the next level. An approved document is published and the relevant people are notified.

Permissions, confidentiality and external sharing

Access is granted not at folder level but at document type, unit and role level. A personnel file and a production work instruction can sit in the same system yet appear to different people. For sharing outside the company, time-limited and traceable links are generated, and who opened them and when is visible. That strikes the balance between the two extremes of everyone seeing everything and nobody being able to reach anything.

Full-text search and scanned paperwork

The search runs not only on the file name but inside the document. Scanned paper documents and photographed minutes are converted to text with OCR, so the old archive becomes searchable too. Filtering is combined with the header fields: date range, unit, type, counterparty. We say up front that OCR results remain limited on handwriting and on poor scans.

Retention periods, destruction and audit trail

A retention period is defined for each document type; records whose period has expired drop into a destruction list and are destroyed with the approval of the person responsible and with a record of destruction produced. Every view, download, change and deletion in the system is logged. These two capabilities are the most useful part of the system from the point of view of both audits and personal data legislation.

E-signature, KEP and links to existing systems

A document can be signed by connecting to the electronic signature infrastructure of licensed service providers, and can be sent by registered electronic mail (KEP). Documents are linked to records in ERP, accounting and production systems: a customer account's contract, or a work order's technical drawing, opens from the same screen. Connections are made over APIs, and your existing systems are not changed.

Technologies

The technologies we work with

  • PostgreSQL
  • S3-compatible object storage
  • Elasticsearch / OpenSearch full-text search
  • OCR (Tesseract)
  • PDF/A long-term archiving
  • CMIS content management standard
  • LDAP / Active Directory
  • SSO (OIDC / SAML)
  • e-Signature and KEP integration
  • Storage encryption and backup
  • Audit log
Process

How we move from discovery to go-live

  1. 01

    1. Document inventory and on-site discovery

    We work out together which document types exist, who produces them, where they sit and how many copies are in circulation. This step usually takes one to two weeks and in most companies gives a collective picture for the first time. Migration carried out without an inventory produces nothing but a copy of the same tangle in a new system.

  2. 02

    2. Classification, header and permission design

    Document types, header fields, approval chains, retention periods and who sees what are designed in writing. Quality, legal, human resources and IT approve that design together. Most of the decisions are made here; the steps that follow are simply the implementation of that design. Contentious points are not left for later; correcting them after the system has gone live is always more expensive.

  3. 03

    3. Installation, workflows and integrations

    The archive, search, versioning and approval workflows are set up; connections are made to authentication and to existing systems such as the ERP. We show a working version at short intervals. The first usable version usually appears within six to ten weeks depending on the breadth of scope, and it aims first at getting new documents entered correctly.

  4. 04

    4. Pilot department and migrating the archive

    We start with a single unit, for example quality or purchasing. New documents go straight into the system; from the historical archive only the files still in use are moved. Objections raised during the pilot are fed back into the header and workflow design; if that feedback is skipped, a flawed design is rolled out across the whole company. Scope is widened unit by unit as the team gets used to it.

  5. 05

    5. Go-live, retention schedule and support

    All units are brought on, the retention and destruction schedule starts running and reports are opened up. User training is delivered and a written manual is handed over. Afterwards, new document types, new workflows and regulatory changes are built into the system under maintenance. The source code, the database and the whole archive stay with you.

Frequently asked questions

Common questions about Document and Content Management (DMS / ECM)

Our ERP has a document attachment field — do we really need a separate system?

If you are getting by with a small number of attachments you may not, and we say so plainly. The attachment field in an ERP fastens a document to a record; it does not manage its version, its approval, its retention period or the text inside it. When it comes to documents with a life of their own — quality documents, contracts, personnel files, technical drawings — an attachment field is not enough. The deciding criterion is not the number of files but whether the document has a process of its own.

Should we scan our entire twenty-year paper archive?

Usually no. Bulk scanning is expensive, takes a long time, and most of what is scanned is never opened. The route we recommend is that every new document enters the system correctly from today, and that from the past only the files still in use, still within a legal retention period or requested in audits are migrated. The rest is scanned as the need arises. This approach lowers the cost and stops the project waiting until the scanning is finished.

How does this differ from the document intelligence module?

The two do not replace each other, they work together. Document intelligence reads an invoice, a delivery note or a contract and extracts the fields inside it; the system on this page stores, versions, permissions, routes for approval and finds the document. The arrangement we often build is this: incoming paperwork is first read and its fields extracted, then its header is filled in with that information and it is filed in the archive. You can also install the two modules separately.

Is an electronically signed document legally valid?

That is a legal question more than a software one and should be confirmed with your lawyer; we do not give legal opinions. On the technical side, what we do is connect the signing operation to the infrastructure of licensed electronic certificate service providers, store the signed file in a form that will not degrade, and keep the verification record. We do not build our own signature infrastructure; this is a regulated area and it runs on the provider's licence. Which provider you work with is also your choice.

What if the team carries on saving to the desktop anyway?

This is the most common way document projects die, and the only remedy is to make using the system the easiest way to do the job. Search has to be fast, uploading has to take a few steps, and the approval workflow has to run more comfortably than email traffic. In addition, in critical processes the output point is tied to the system: the approved version can only be obtained from the system. Habits change through convenience, not through rules; that is also the purpose of the pilot department.

What do we end up with?

A central archive with document types and header fields defined; version and effectivity control; approval workflows; permissions by role and by unit; full-text search including scanned paperwork; a retention and destruction schedule; an audit trail recording every operation; e-signature and connections built to your existing systems. Alongside these you receive an administration screen where you can update document types and permissions yourself, and a written user manual. The source code, the data and the whole archive belong to you.

Contact

Let us talk about your Document and Content Management (DMS / ECM) project

In a 30-minute discovery call we listen to what you need and tell you honestly whether custom development or an off-the-shelf product is the better answer.

Related

Related pages and guides

Contract Management (CLM)

We build a system that produces a contract from a template, puts it through approval and signature, and — once it is signed — tracks effectivity, renewal, the notice period for termination and the parties' commitments. Contract lifecycle management (CLM) is exactly that: not storing a file, but managing the contract's lifetime. A contract whose term has run out does not quietly extend itself because nobody noticed.

Details

IT and Enterprise Service Management (ITSM / ESM)

We build an arrangement in which faults and requests arrive through a single record rather than through a messaging app, a corridor conversation or a phone call. Every request is prioritised, has a clear owner and a measured resolution time. We run the same structure not only in IT but also for human resources, administrative affairs and maintenance requests. That is what enterprise service management (ESM) means.

Details

IT Asset and Licence Management (ITAM)

Who is using which computer, phone, server and network device, which licence expires when, which subscription quietly renews itself: we gather all of it into a single record system. Assignment, warranty, the renewal calendar and decommissioning run in the same system; the inventory moves out of personal memory and into the organisation's records.

Details

Governance, Risk and Compliance (GRC)

We tie risks to their owners and place a control, and the evidence for that control, against each risk. Policies run under version control, audit findings are tracked to a deadline, and a regulatory change lands with the right person. Work on personal data, occupational safety and the environment is read from a single dashboard under the same roof.

Details

Project and Portfolio Management (PPM / PMS)

We break projects down into a work breakdown structure, make resources and capacity visible, and put budget and actuals side by side. Milestones, risks and decisions sit in the same record; management reads the whole portfolio from a single dashboard and discusses which work comes first by looking at data.

Details

Web Applications & SaaS

We design and build internal systems and subscription-based SaaS products that run in the browser, sit behind secure sign-in and show content according to role and permission. We shape them around how your business actually works, and we share the source code with you.

Details
Call Free strategy call