1. Agree the evaluation scope
- Identify document classes, required metadata, roles and permitted operations.
- Confirm enabled modules, storage and processing readiness, optional integrations and delivery channels.
- Use wholly synthetic documents and accounts. Agree capture permissions and redactions before recording.
- Record each requirement as demonstrated, configuration-dependent, unsupported or not yet verified.
2. Capture and find a document
- Upload a synthetic equipment-justification PDF with a reference, title and department, without financial figures.
- Inspect available processing output and failure handling. Embedded digital-text extraction does not guarantee full-text transcription of scans.
- Review and correct metadata. Where AI is enabled, confirm review or auto-confirmation rules and test an uncertain result.
- Retrieve the file using structured metadata or available document text, subject to access.
3. Execute a configured review
- Configure submitter and reviewer access and a review workflow. Proposed “Under review”, “Approved” and “Rejected” labels are demo choices, not installation defaults.
- Manually start review; check the assigned reviewer can inspect and approve or reject.
- Test rejection as a terminal result. Correct metadata or upload a version only with permission and without a blocking lock; start a new workflow instance.
- Inspect the recorded decision and permitted retrieval/history. Approval alone is not signing, record activation, archival, ordering or payment.
4. Verify access, versions and evidence
- Test both permitted access and denial with a separate restricted role, including the healthcare administrative scenario before calling it demonstrated.
- Check permitted versions and editing/checkout restrictions, including active-workflow locks.
- Inspect recorded activity and available audit exports. Tamper evidence does not mean every action is captured forever or that logs cannot change.
- Test permitted document downloads, metadata and audit exports; establish batch limits and scope. Do not assume complete one-click migration.
- If signatures are required, separately confirm configured identity assurance, delivery and supporting evidence. Do not assume qualified status or universal legal effect.
5. Evaluate records controls separately
- Inspect a non-destructive illustrative retention policy and records lifecycle, separately from approval.
- Confirm holds and other protections constrain supported changes and disposal eligibility.
- Do not run disposal or configure production policies during this evaluation. Configured deletion is possible; permanent, held, vital and active records require their applicable protections.
- Agree legal authority and retention periods independently. Archival status does not prove transfer to an external repository; erasure across backups requires separate evidence.
6. Keep industry boundaries explicit
- Education: transcript-request supporting documents, not transcript generation.
- Legal: contract versions/review, not legal advice or court filing.
- Finance: approval-supporting documents, not accounting or transactions.
- Healthcare: restricted administrative documents, not clinical or EHR functionality.
- Government: correspondence registration/review, not statutory certification.
- Manufacturing: procedure revisions/review, not manufacturing execution or training acknowledgement.
Evaluation record
| Requirement | Evidence / date / role | Status and unresolved question |
|---|---|---|
| Capture and metadata | ||
| Review and rejection | ||
| Access and versions | ||
| History and export | ||
| Separate records controls |
Further reading
Dockria platform overview · Requirements guide · Retention and disposal guide
Confirm published pages reflect this material before sharing. Compliance and legal conclusions require the organisation's own policy and professional assessment.