A document management workflow for filing, versions, retrieval and retention
This template keeps documents tidy across Drive, Box or Dropbox: it proposes where each new file belongs, spots new versions, finds files on request, and prepares retention reviews. Deleting and sharing outside the company wait for a named person.
Last reviewed 7 October 2026
Starting point
The status rests on the Google Drive workflow, which lists files and folders, and the Box file workflow, which reads the root folder, lists items and searches. Both only read. The Filesystem MCP entry covers local files. Filing, versioning and deletion are yours to add.
The library has a template, chatflow, MCP server or governed template that covers part of the job. You assemble the rest in Studio.
What this template does
Documents pile up where people leave them. A contract sits in a downloads folder, a policy exists in four versions, and nobody can say which one is current or when it may be deleted. The owner is the operations lead or the records owner, who answers to auditors and colleagues who cannot find things.
The flow works on the storage you already use. It proposes a home and a name for each new document, notes when a file looks like a newer version of another, and answers where something is. Deletion and external sharing are the two actions that cannot be undone or taken back, so both wait for a person.
The workflow, step by step
Steps marked as approval gates pause the run until a named person approves. Nothing after a gate runs before that decision, and the decision is recorded.
- 01
Take an inventory
On a schedule the flow lists files and folders in the storage you name, reading only. It records name, folder, owner, size and modified date, and compares with the last run to find what is new. The new items go forward. - 02
Classify the new files
An agent reads each new file's name and text, and proposes a document type, owner, project and sensitivity label. It also proposes a clear file name and target folder following your naming rule. Uncertain files go to a person. - 03
File inside the intake area
Files in the intake folder are moved and renamed as proposed, and the original name is kept in a note. The flow does not touch files outside the intake folder. Each move is logged so it can be reversed. - 04
Detect new versions
The flow compares a new file with existing ones of the same type and project. If it looks like a newer version, the older one is marked superseded in a note, not deleted. Doubtful matches are listed for the owner. - 05
Answer retrieval requests
Staff ask in plain language, for example for the current supplier agreement. The agent searches the storage, returns links rather than copies and shows the folder and modified date. It respects existing sharing; it cannot open what the asker could not. - 06
Records owner approves deletion and sharing
A scheduled retention review lists files past the period you set, and requests to share outside the company arrive from staff. Each goes to the named records owner. Deleting or sharing happens only after approval, with a different person assigned for legal hold questions.Approval gate: a named person approves before the next step runs. - 07
Record
The run keeps the inventory, each classification and move with the original name, the version notes and the retrieval requests. For every deletion or share it also keeps the approver, the decision and the time, which is the evidence an auditor will ask for.
What it can do, cannot do, needs approval for, and records
Can
- List and search files in connected storage
- Propose names, folders and labels
- File documents inside the intake area
- Mark a file as superseded in a note
Cannot
- Delete a file on its own
- Share a file outside the company on its own
- Open files the asker has no access to
- Decide how long a document must be kept
Requires approval
- Every deletion, including past-retention files
- Every external share
- Any move out of the intake area
Records
- Inventory and changes since the last run
- Classifications and moves, with the original name
- Version notes
- Approver, decision and time for deletes and shares
What the library holds for this job
| Asset | Type | Covers | Role in this flow |
|---|---|---|---|
| Google Drive Workflow | Workflow template | Part of the job | Lists files and folders in Google Drive; the inventory step builds on it. It does not create or move anything. |
| Box File Workflow | Workflow template | Part of the job | Reads the root folder, lists items and searches files in Box; the retrieval step builds on it. |
| Filesystem MCP server | MCP server entry | Part of the job | A library entry for a filesystem operations MCP server, for documents held on a local or shared disk. |
| Dropbox | Integration | Used inside the flow | A third storage option for the same flow. |
Integrations this flow uses
- Google Drive: Storage that is listed, searched and filed.
- Box: Storage with folder and search operations.
- Dropbox: A third storage option for the same flow.
- Amazon S3: Object storage for archives and exports.
The full list of tools Studio connects to is on the integrations page.
What you supply, and what this page does not cover
- You supply the naming rule, the document types and the folder structure.
- Retention periods come from your law, contracts and policy. They are <retention periods - set by the records owner>, and this page gives none.
- The library fixtures only read and search. Creating, moving and renaming files are steps you add and test.
- Legal hold and records law are not covered. Ask your legal adviser.
Common questions
- Does it replace a document management system?
- No. It works on top of the storage you have, adding classification, naming and review. If you need check-in and check-out, formal records classes or e-discovery, a dedicated system may still be right.
- Can it delete old files to save space?
- It prepares the list and a person approves. Deletion is the one action here that cannot be undone, so the design keeps it behind the records owner every time, even for files that look obviously stale.
- How does it handle documents it cannot read?
- Scans and images need text extraction first, which this flow does not include. Unreadable files are filed by name and type only, and marked for a person. The document extraction template covers reading incoming files.
- Will search show people files they should not see?
- The flow searches with the permissions of the connection you give it. Use a connection that can see only what the asker may see, and test with a restricted user. Do not use an administrator account for this.