[{"data":1,"prerenderedAt":1018},["ShallowReactive",2],{"help:\u002Fhelp\u002Fsettings\u002Faudit-log":3,"help-all-categories":243,"help-cat-articles:\u002Fhelp\u002Fsettings\u002Faudit-log":363,"help-related:\u002Fhelp\u002Fsettings\u002Faudit-log":364},{"id":4,"title":5,"audience":6,"body":7,"category":221,"description":222,"draft":223,"extension":224,"icon":225,"keywords":226,"meta":233,"navigation":234,"order":235,"path":236,"related":237,"seo":239,"stem":240,"updatedAt":241,"__hash__":242},"help\u002Fhelp\u002Fsettings\u002Faudit-log.md","Read the audit log","clinic",{"type":8,"value":9,"toc":204},"minimark",[10,19,24,36,40,43,127,157,163,167,179,183,187,190,194,197,201],[11,12,13,14,18],"p",{},"The audit log is the permanent record of who did what in your business — role changes, refunds, deletions, permission edits, and every other sensitive action, each stamped with the person and the time. Open it from ",[15,16,17],"strong",{},"Settings → Compliance & data → Audit log",".",[20,21,23],"h2",{"id":22},"who-can-see-the-audit-log","Who can see the audit log?",[11,25,26,27,30,31,35],{},"Access is its own capability — ",[15,28,29],{},"audit — view"," — not a role tier. That means a compliance reviewer can be granted read access to the log without being made an admin. The full-page log at ",[32,33,34],"code",{},"\u002Fsettings\u002Faudit"," is additionally admin-gated.",[20,37,39],{"id":38},"how-do-i-find-a-specific-change","How do I find a specific change?",[11,41,42],{},"The log is filterable from every angle:",[44,45,46,59],"table",{},[47,48,49],"thead",{},[50,51,52,56],"tr",{},[53,54,55],"th",{},"Filter",[53,57,58],{},"Use it to answer",[60,61,62,73,83,93,103,117],"tbody",{},[50,63,64,70],{},[65,66,67],"td",{},[15,68,69],{},"Entity type",[65,71,72],{},"\"Show me everything that happened to gift cards\"",[50,74,75,80],{},[65,76,77],{},[15,78,79],{},"Action",[65,81,82],{},"\"Show me every deletion\"",[50,84,85,90],{},[65,86,87],{},[15,88,89],{},"Team member",[65,91,92],{},"\"What did this person change?\"",[50,94,95,100],{},[65,96,97],{},[15,98,99],{},"Client",[65,101,102],{},"\"Everything that touched this client's record\"",[50,104,105,110],{},[65,106,107],{},[15,108,109],{},"Severity",[65,111,112,113,116],{},"Info, notice, or ",[15,114,115],{},"critical"," — the shortlist worth reviewing",[50,118,119,124],{},[65,120,121],{},[15,122,123],{},"Date range",[65,125,126],{},"Bound the search to the period in question",[128,129,130,135,139,143,146,150],"steps",{},[131,132,134],"h3",{"id":133},"open-the-log","Open the log",[11,136,137,18],{},[15,138,17],{},[131,140,142],{"id":141},"narrow-it-down","Narrow it down",[11,144,145],{},"Combine filters — a team member plus a date range plus an action gets you from \"50 pages\" to \"the six entries that matter\".",[131,147,149],{"id":148},"open-an-entry","Open an entry",[11,151,152,153,156],{},"Each entry shows who, what, and when. Where a record was changed, the ",[15,154,155],{},"diff viewer"," shows the before and after values side by side, so \"someone edited the price\" becomes \"changed from $120 to $90\".",[158,159,160],"tip",{},[11,161,162],{},"Other pages deep-link here pre-filtered — a client profile or a form submission can jump you straight to its own audit trail, already scoped to that record.",[20,164,166],{"id":165},"can-audit-entries-be-edited-or-deleted","Can audit entries be edited or deleted?",[11,168,169,170,173,174,18],{},"No. The log is append-only by design and is ",[15,171,172],{},"not"," touched by your data-retention purge — entries can't be edited or removed, by anyone, including the owner. That immutability is what makes it evidence rather than notes. See ",[175,176,178],"a",{"href":177},"\u002Fhelp\u002Fsettings\u002Fdata-privacy-and-retention","Data privacy and retention",[20,180,182],{"id":181},"common-questions","Common questions",[131,184,186],{"id":185},"does-the-log-capture-reads-or-only-changes","Does the log capture reads or only changes?",[11,188,189],{},"It records actions and changes — the things that alter state or move money. It isn't a keystroke recorder.",[131,191,193],{"id":192},"how-far-back-does-it-go","How far back does it go?",[11,195,196],{},"To the beginning of your workspace. Retention purges skip the audit log entirely.",[131,198,200],{"id":199},"can-i-export-it","Can I export it?",[11,202,203],{},"Use the date and entity filters to scope what you need on screen. ",{"title":205,"searchDepth":206,"depth":206,"links":207},"",2,[208,209,215,216],{"id":22,"depth":206,"text":23},{"id":38,"depth":206,"text":39,"children":210},[211,213,214],{"id":133,"depth":212,"text":134},3,{"id":141,"depth":212,"text":142},{"id":148,"depth":212,"text":149},{"id":165,"depth":206,"text":166},{"id":181,"depth":206,"text":182,"children":217},[218,219,220],{"id":185,"depth":212,"text":186},{"id":192,"depth":212,"text":193},{"id":199,"depth":212,"text":200},"settings","See who did what and when in Owneli — filter the audit log by person, client, action, or date, and read the before\u002Fafter of any change.",false,"md","i-lucide-shield-alert",[227,228,229,230,231,232],"audit log","who changed this","activity history","track staff changes","who deleted a client","audit trail",{},true,180,"\u002Fhelp\u002Fsettings\u002Faudit-log",[238,177],"\u002Fhelp\u002Fsettings\u002Froles-and-permissions",{"title":5,"description":222},"help\u002Fsettings\u002Faudit-log","2026-08-14","etNUA2Dtb8G1PWHXC01q76Smz9Njmy9DJgC9aKIFCQk",[244,255,264,273,283,293,303,313,323,332,342,353],{"id":245,"title":246,"audience":6,"description":247,"extension":248,"icon":249,"meta":250,"order":251,"slug":252,"stem":253,"__hash__":254},"helpCategories\u002Fhelp\u002Fcategories\u002Fgetting-started.yml","Getting started","Set up your workspace, learn the layout, and run your first day.","yml","i-lucide-compass",{},1,"getting-started","help\u002Fcategories\u002Fgetting-started","lTnfg_2tKvxQ9QanJ9XY3shoBHrJNWNfnxhcYaaKKPI",{"id":256,"title":257,"audience":6,"description":258,"extension":248,"icon":259,"meta":260,"order":206,"slug":261,"stem":262,"__hash__":263},"helpCategories\u002Fhelp\u002Fcategories\u002Fcalendar.yml","Calendar & booking","Book, move, and cancel appointments. Block time, work the waitlist, and read the grid at a glance.","i-lucide-calendar",{},"calendar","help\u002Fcategories\u002Fcalendar","s5UMHzRIeTUFi7mdsOyuSluzJBp79U9WTsTpOtbaW-E",{"id":265,"title":266,"audience":6,"description":267,"extension":248,"icon":268,"meta":269,"order":212,"slug":270,"stem":271,"__hash__":272},"helpCategories\u002Fhelp\u002Fcategories\u002Fcheckout.yml","Checkout & payments","Ring up a sale, take tips, handle deposits and fees, issue refunds, and close the drawer.","i-lucide-credit-card",{},"checkout","help\u002Fcategories\u002Fcheckout","4PQPgJd7Z25g0SvtoqqdMlnzk3DlcJpaZhNAiNiYVW0",{"id":274,"title":275,"audience":6,"description":276,"extension":248,"icon":277,"meta":278,"order":279,"slug":280,"stem":281,"__hash__":282},"helpCategories\u002Fhelp\u002Fcategories\u002Fclients.yml","Clients & forms","Add and find clients, read a client profile, and send forms and consents.","i-lucide-users",{},4,"clients","help\u002Fcategories\u002Fclients","u-tqzEJo2gR_wJ7x7y-EMIF3L4TP9EuBWlamwgwCC0I",{"id":284,"title":285,"audience":6,"description":286,"extension":248,"icon":287,"meta":288,"order":289,"slug":290,"stem":291,"__hash__":292},"helpCategories\u002Fhelp\u002Fcategories\u002Fretail.yml","Memberships, packages & gift cards","The things clients buy once and spend down over time, and how each one behaves at checkout.","i-lucide-gift",{},5,"retail","help\u002Fcategories\u002Fretail","wVVr_rc_P9p2RZWwy0XKsNB9fQ7XtQxxIz4qnixkGkg",{"id":294,"title":295,"audience":6,"description":296,"extension":248,"icon":297,"meta":298,"order":299,"slug":300,"stem":301,"__hash__":302},"helpCategories\u002Fhelp\u002Fcategories\u002Foperations.yml","Operations","The internal side of the business, covering your written playbook, task boards, venue incidents, and the policies everyone signs.","i-lucide-briefcase",{},6,"operations","help\u002Fcategories\u002Foperations","kSPRTYYbOW5LBNuaYXGv0C4IE7BqS2n-OkCSI97f-cM",{"id":304,"title":305,"audience":6,"description":306,"extension":248,"icon":307,"meta":308,"order":309,"slug":310,"stem":311,"__hash__":312},"helpCategories\u002Fhelp\u002Fcategories\u002Fteam.yml","Team & scheduling","Working hours, the weekly roster, clock-in, timesheets, and time off.","i-lucide-id-card",{},7,"team","help\u002Fcategories\u002Fteam","1cMbCRwUmewb4t_DwUJ7jJUjntx-odU8jRDgBredsPs",{"id":314,"title":315,"audience":6,"description":316,"extension":248,"icon":317,"meta":318,"order":319,"slug":320,"stem":321,"__hash__":322},"helpCategories\u002Fhelp\u002Fcategories\u002Fgrowth.yml","Reports & growth","Read the numbers, export them, and find the report you actually need.","i-lucide-trending-up",{},8,"growth","help\u002Fcategories\u002Fgrowth","3XyCU-DkoYi7xSPz0tDRohlYkNBUS0YsLo-insknI8o",{"id":324,"title":325,"audience":6,"description":326,"extension":248,"icon":327,"meta":328,"order":329,"slug":221,"stem":330,"__hash__":331},"helpCategories\u002Fhelp\u002Fcategories\u002Fsettings.yml","Settings & admin","Services and pricing, who can see what, and moving your data in from another system.","i-lucide-settings",{},9,"help\u002Fcategories\u002Fsettings","rdLQHp7tfAu5iySbsypfXu1kOuujDAuLVk6yGidNvtQ",{"id":333,"title":334,"audience":6,"description":335,"extension":248,"icon":336,"meta":337,"order":338,"slug":339,"stem":340,"__hash__":341},"helpCategories\u002Fhelp\u002Fcategories\u002Faccount.yml","Your login and profile","Your own login, password, two-factor security, profile, and language.","i-lucide-user-circle",{},10,"account","help\u002Fcategories\u002Faccount","8JZPH_8Q-lnEEFgysE9gCwyd1pzUe2hfAebATuQ5Pog",{"id":343,"title":344,"audience":345,"description":346,"extension":248,"icon":347,"meta":348,"order":349,"slug":350,"stem":351,"__hash__":352},"helpCategories\u002Fhelp\u002Fcategories\u002Fbook-online.yml","Book online","client","Booking, paying, and managing your visit from your venue's booking page and the private links they send you.","i-lucide-globe",{},20,"book-online","help\u002Fcategories\u002Fbook-online","dUBIoELt-ci1vqbw_VX1VA6PGJV8V-9x4ZmpAk1aXXE",{"id":354,"title":355,"audience":345,"description":356,"extension":248,"icon":357,"meta":358,"order":359,"slug":360,"stem":361,"__hash__":362},"helpCategories\u002Fhelp\u002Fcategories\u002Fportal.yml","Your account and visits","Booking from your account, managing your visits, and using your wallet, memberships and rewards.","i-lucide-user-round",{},21,"portal","help\u002Fcategories\u002Fportal","D8_zQhv9hO2b9PYDADw-ebh1yZUuC0UcBt3DDZbMAH4",[],[365,827],{"id":366,"title":367,"audience":6,"body":368,"category":221,"description":816,"draft":223,"extension":224,"icon":817,"keywords":818,"meta":819,"navigation":234,"order":349,"path":238,"related":820,"seo":823,"stem":824,"updatedAt":825,"__hash__":826},"help\u002Fhelp\u002Fsettings\u002Froles-and-permissions.md","Roles and permissions",{"type":8,"value":369,"toc":797},[370,373,378,382,385,439,445,449,452,456,475,511,514,567,571,578,642,645,651,655,658,689,696,700,743,747,754,759,763,766,770,784,787,791],[11,371,372],{},"Access in Owneli is capability-based, not tier-based. There is no hidden ladder where \"manager\" magically unlocks things — every screen and every API call checks a specific capability, and roles are just named bundles of capabilities.",[11,374,375],{},[15,376,377],{},"Settings → Team & access → Permission roles",[20,379,381],{"id":380},"the-four-starting-roles","The four starting roles",[11,383,384],{},"Every business is created with four system roles you can adapt.",[44,386,387,397],{},[47,388,389],{},[50,390,391,394],{},[53,392,393],{},"Role",[53,395,396],{},"What it is",[60,398,399,409,419,429],{},[50,400,401,406],{},[65,402,403],{},[15,404,405],{},"Owner",[65,407,408],{},"Full access to everything, plus owner-reserved actions: enforcing multi-factor authentication and transferring ownership.",[50,410,411,416],{},[65,412,413],{},[15,414,415],{},"Admin",[65,417,418],{},"Full access to the business. Can invite people, manage the team, and change settings.",[50,420,421,426],{},[65,422,423],{},[15,424,425],{},"Manager",[65,427,428],{},"Operational lead. Manages clients, forms and sends, approves time off. Cannot change settings or invite users.",[50,430,431,436],{},[65,432,433],{},[15,434,435],{},"Staff",[65,437,438],{},"Standard team member. The capability set is adjustable per business.",[440,441,442],"note",{},[11,443,444],{},"The owner is deliberately a superuser and is granted every capability, including ones added in future releases. That's so a new feature can never accidentally lock the owner out of their own business.",[20,446,448],{"id":447},"two-axes","Two axes",[11,450,451],{},"Access is controlled along two axes, and both matter.",[131,453,455],{"id":454},"_1-what-you-can-do","1. What you can do",[11,457,458,459,462,463,466,467,470,471,474],{},"Each of roughly three dozen capability areas carries its own actions — typically ",[15,460,461],{},"view",", ",[15,464,465],{},"manage",", and ",[15,468,469],{},"delete",", plus ",[15,472,473],{},"create"," where creating differs meaningfully from editing.",[11,476,477,478,462,481,462,484,462,487,462,490,462,493,462,496,462,499,462,502,462,505,466,508,18],{},"The permission editor groups them the way you think about the app: ",[15,479,480],{},"Calendar",[15,482,483],{},"Scheduling & timesheets",[15,485,486],{},"Sales",[15,488,489],{},"Clients",[15,491,492],{},"Catalog",[15,494,495],{},"Marketing",[15,497,498],{},"Inventory & Retail",[15,500,501],{},"Team",[15,503,504],{},"Reports",[15,506,507],{},"Workspace",[15,509,510],{},"AI concierge",[11,512,513],{},"Things are split more finely than you might expect, on purpose:",[515,516,517,527,536,546,552],"ul",{},[518,519,520,523,524,526],"li",{},[15,521,522],{},"Cash drawer"," is separate from ",[15,525,486],{}," — a cashier can ring up without holding the power to open, count and reconcile the till.",[518,528,529,523,532,535],{},[15,530,531],{},"Scheduling",[15,533,534],{},"Appointments"," — you can grant \"runs the rota and signs off payroll\" without handing over the client calendar.",[518,537,538,541,542,545],{},[15,539,540],{},"Client photos"," and ",[15,543,544],{},"clinical charts"," are separate from the client record — health imagery grants and revokes on its own.",[518,547,548,551],{},[15,549,550],{},"Compensation"," is its own area — someone can see their own earnings without seeing a colleague's.",[518,553,554,462,557,462,560,541,563,566],{},[15,555,556],{},"Purchasing",[15,558,559],{},"stock",[15,561,562],{},"transfers",[15,564,565],{},"products"," each grant independently, so a buyer can raise purchase orders without touching stock counts.",[131,568,570],{"id":569},"_2-which-rows-you-can-do-it-to","2. Which rows you can do it to",[11,572,573,574,577],{},"The ",[15,575,576],{},"data scope"," decides which records an action reaches:",[44,579,580,590],{},[47,581,582],{},[50,583,584,587],{},[53,585,586],{},"Scope",[53,588,589],{},"Meaning",[60,591,592,602,612,622,632],{},[50,593,594,599],{},[65,595,596],{},[15,597,598],{},"All",[65,600,601],{},"Everything in the business",[50,603,604,609],{},[65,605,606],{},[15,607,608],{},"Own",[65,610,611],{},"Only records belonging to this person",[50,613,614,619],{},[65,615,616],{},[15,617,618],{},"Assigned",[65,620,621],{},"Only records they're assigned to",[50,623,624,629],{},[65,625,626],{},[15,627,628],{},"Location",[65,630,631],{},"Only records at their location",[50,633,634,639],{},[65,635,636],{},[15,637,638],{},"None",[65,640,641],{},"Nothing",[11,643,644],{},"Staff-tier defaults reflect how a provider actually works: their own calendar, their assigned clients, their own timesheets, their own sales, their own reports and earnings.",[646,647,648],"warning",{},[11,649,650],{},"Granting an action without widening its scope is the most common configuration mistake. Someone with \"view all appointments\" but a scope of \"own\" will still only see their own calendar, and it will look like a bug.",[20,652,654],{"id":653},"fine-grained-client-access","Fine-grained client access",[11,656,657],{},"The client record is the most sensitive surface in the app, so it's split further:",[515,659,660,666,672,678,684],{},[518,661,662,665],{},[15,663,664],{},"Can view client profile"," — the base",[518,667,668,671],{},[15,669,670],{},"Can view contact details"," — email and phone",[518,673,674,677],{},[15,675,676],{},"Can view personal info"," — date of birth and home address",[518,679,680,683],{},[15,681,682],{},"Can view spending and wallet"," — lifetime value, balances, loyalty",[518,685,686],{},[15,687,688],{},"Can add and remove tags",[11,690,691,692,695],{},"Denied fields are masked in the interface ",[15,693,694],{},"and"," stripped from API responses — this is enforced at the server, not hidden with CSS.",[20,697,699],{"id":698},"building-a-custom-role","Building a custom role",[128,701,702,706,709,713,716,720,723,727,734,738],{},[131,703,705],{"id":704},"start-from-the-closest-system-role","Start from the closest system role",[11,707,708],{},"Duplicate it rather than building from an empty matrix. Empty matrices produce roles that can't do their job.",[131,710,712],{"id":711},"turn-on-the-areas-the-role-needs","Turn on the areas the role needs",[11,714,715],{},"Each area has a master toggle. The editor enforces parent-first ordering — a child permission can't take effect while its parent is off.",[131,717,719],{"id":718},"set-the-scope-for-each-area","Set the scope for each area",[11,721,722],{},"Only surfaces with end-to-end enforcement offer a scope picker, so every option you're shown actually does something.",[131,724,726],{"id":725},"preview-it","Preview it",[11,728,729,730,733],{},"Use ",[15,731,732],{},"View as"," to see the app exactly as that role sees it. This is the step people skip and then regret.",[131,735,737],{"id":736},"assign-it","Assign it",[11,739,740,741,18],{},"Set the role on each team member under ",[15,742,501],{},[20,744,746],{"id":745},"what-the-sidebar-tells-you","What the sidebar tells you",[11,748,749,750,753],{},"Every nav item is capability-gated, so people only see what they can open. An ",[15,751,752],{},"eye icon"," beside a link means view-only access — you can read the page but not change anything. It saves a click into a page where every button is disabled.",[646,755,756],{},[11,757,758],{},"Hiding a link is presentation. The real gate is on the server: every endpoint re-checks the capability and the scope. Restoring a hidden link in the browser gets you an error, not access.",[20,760,762],{"id":761},"multi-factor-authentication","Multi-factor authentication",[11,764,765],{},"Owners can require multi-factor authentication for the business. Once enforced, everyone is prompted to enrol at sign-in.",[20,767,769],{"id":768},"suspending-and-offboarding","Suspending and offboarding",[515,771,772,778],{},[518,773,774,777],{},[15,775,776],{},"Suspend"," locks someone out immediately while keeping their record and history intact",[518,779,780,783],{},[15,781,782],{},"Archive"," runs a reassignment wizard so their upcoming appointments and open work move to someone else before the record is closed",[11,785,786],{},"Neither deletes their history. Past sales, appointments and timesheets stay attached to them for reporting and payroll.",[20,788,790],{"id":789},"auditing","Auditing",[11,792,793,796],{},[15,794,795],{},"Settings → Compliance → Audit log"," records who did what and when — role changes, permission changes, refunds, voids, merges, deletions. Audit access is its own capability, so a compliance reviewer can read it without being an admin.",{"title":205,"searchDepth":206,"depth":206,"links":798},[799,800,804,805,812,813,814,815],{"id":380,"depth":206,"text":381},{"id":447,"depth":206,"text":448,"children":801},[802,803],{"id":454,"depth":212,"text":455},{"id":569,"depth":212,"text":570},{"id":653,"depth":206,"text":654},{"id":698,"depth":206,"text":699,"children":806},[807,808,809,810,811],{"id":704,"depth":212,"text":705},{"id":711,"depth":212,"text":712},{"id":718,"depth":212,"text":719},{"id":725,"depth":212,"text":726},{"id":736,"depth":212,"text":737},{"id":745,"depth":206,"text":746},{"id":761,"depth":206,"text":762},{"id":768,"depth":206,"text":769},{"id":789,"depth":206,"text":790},"The four starting roles, the two axes that control access, and how to build a custom role without locking yourself out.","i-lucide-shield-check",[],{},[821,822],"\u002Fhelp\u002Fteam\u002Fshifts-timesheets-and-time-off","\u002Fhelp\u002Fgrowth\u002Ffind-and-read-a-report",{"title":367,"description":816},"help\u002Fsettings\u002Froles-and-permissions","2026-09-01","TENSZfd1Unekw8skVK5ZgEABdPfFFfQpo8przNdYK7o",{"id":828,"title":178,"audience":6,"body":829,"category":221,"description":1003,"draft":223,"extension":224,"icon":1004,"keywords":1005,"meta":1012,"navigation":234,"order":1013,"path":177,"related":1014,"seo":1015,"stem":1016,"updatedAt":241,"__hash__":1017},"help\u002Fhelp\u002Fsettings\u002Fdata-privacy-and-retention.md",{"type":8,"value":830,"toc":987},[831,838,842,880,886,890,926,930,937,941,948,955,964,966,970,973,977,980,984],[11,832,833,834,837],{},"Owneli can automatically purge data older than a retention period you choose, with a dry-run preview before anything is deleted and legal holds to exempt records you must keep. It's configured at ",[15,835,836],{},"Settings → Compliance & data → Data & privacy"," (admins only).",[20,839,841],{"id":840},"how-do-i-set-a-data-retention-period","How do I set a data retention period?",[128,843,844,848,855,859,862,866,873,877],{},[131,845,847],{"id":846},"turn-on-automatic-retention","Turn on automatic retention",[11,849,850,851,854],{},"Flip ",[15,852,853],{},"Enable automatic data purge"," on.",[131,856,858],{"id":857},"choose-the-period","Choose the period",[11,860,861],{},"Set the retention window in days — anywhere from 30 to 3650 (ten years). Data older than this becomes eligible for deletion.",[131,863,865],{"id":864},"preview-before-you-commit","Preview before you commit",[11,867,868,869,872],{},"Click the preview button. Owneli runs a ",[15,870,871],{},"dry run"," and shows exactly how many records would be eligible under the period you typed — before anything is actually purged.",[131,874,876],{"id":875},"save","Save",[11,878,879],{},"The retention policy saves with the rest of your workspace defaults.",[881,882,883],"caution",{},[11,884,885],{},"A purge is permanent. Always run the preview and read the numbers before saving a shorter period — \"365\" where you meant \"3650\" is a very different policy.",[20,887,889],{"id":888},"what-never-gets-purged","What never gets purged",[44,891,892,902],{},[47,893,894],{},[50,895,896,899],{},[53,897,898],{},"Data",[53,900,901],{},"Why",[60,903,904,916],{},[50,905,906,911],{},[65,907,908],{},[15,909,910],{},"The audit log",[65,912,913,914,18],{},"Append-only and immutable — it's your evidence trail. See ",[175,915,5],{"href":236},[50,917,918,923],{},[65,919,920],{},[15,921,922],{},"Records under a legal hold",[65,924,925],{},"Explicitly exempted until the hold is released.",[20,927,929],{"id":928},"legal-holds","Legal holds",[11,931,932,933,936],{},"A legal hold pins specific records so the retention purge skips them — for a dispute, an investigation, or a regulatory request. Active holds are listed on this tab, and an admin can ",[15,934,935],{},"release"," a hold when the obligation ends, returning those records to the normal retention rules.",[20,938,940],{"id":939},"clinical-charting-health-information","Clinical charting (health information)",[11,942,943,944,947],{},"The same tab carries the ",[15,945,946],{},"clinical charting"," switch. It's off by default because it changes what kind of data your workspace stores: turning it on enables treatment charts on appointments, which is protected health information.",[11,949,950,951,954],{},"Clinical charts get their ",[15,952,953],{},"own retention period"," — separate from, and typically much longer than, general data retention, because health-record laws commonly require charts be kept for many years.",[646,956,957],{},[11,958,959,960,963],{},"Deleting a client on request (a GDPR-style erasure) is a separate flow from retention. Clinical treatment records are ",[15,961,962],{},"archived and access-restricted"," rather than destroyed, because retention law overrides the erasure request for health records.",[20,965,182],{"id":181},[131,967,969],{"id":968},"does-retention-delete-my-audit-history","Does retention delete my audit history?",[11,971,972],{},"No — the audit log is excluded entirely.",[131,974,976],{"id":975},"can-i-see-what-a-different-period-would-delete-without-changing-anything","Can I see what a different period would delete without changing anything?",[11,978,979],{},"Yes. Type the candidate number of days and run the preview; it's a dry run and deletes nothing.",[131,981,983],{"id":982},"who-can-change-these-settings","Who can change these settings?",[11,985,986],{},"Admins. Access to read the audit log is a separate capability, so review and configuration can be held by different people.",{"title":205,"searchDepth":206,"depth":206,"links":988},[989,995,996,997,998],{"id":840,"depth":206,"text":841,"children":990},[991,992,993,994],{"id":846,"depth":212,"text":847},{"id":857,"depth":212,"text":858},{"id":864,"depth":212,"text":865},{"id":875,"depth":212,"text":876},{"id":888,"depth":206,"text":889},{"id":928,"depth":206,"text":929},{"id":939,"depth":206,"text":940},{"id":181,"depth":206,"text":182,"children":999},[1000,1001,1002],{"id":968,"depth":212,"text":969},{"id":975,"depth":212,"text":976},{"id":982,"depth":212,"text":983},"Set automatic data retention in Owneli, preview what a purge would delete, use legal holds, and control clinical charting for health records.","i-lucide-database",[1006,1007,1008,1009,1010,1011],"data retention policy","auto delete old data","gdpr retention","legal hold","clinical charting phi","purge client data",{},190,[236,238],{"title":178,"description":1003},"help\u002Fsettings\u002Fdata-privacy-and-retention","YoQ7U7z-ziAfnoHEkvwqG8nU4bP9k3TvlxPpbfmJWLw",1790218960825]