Use Documents for controlled organisational files
Put policies, procedures, forms, guidance, templates and other shared files in Documents when the organisation needs to control ownership, access, review dates or versions. The document is the governed record, not merely an attachment to somebody else's activity.
A clear organisation library helps people find the current file without searching personal drives or deciding which email attachment is authoritative. Folders and categories should aid browsing; they should not replace meaningful ownership, dates and access rules.
- An accountable owner and a named audience
- A current version and retained version history
- A review date or lifecycle state where required
- Access for the relevant site, team, role or named people
Use staff documents for personal compliance records
A driving licence, right-to-work check, business-use insurance record or qualification belongs against the relevant staff member. A reusable template defines what is required; each assignment then holds that person's dates, reference, supplied file, review decision and history.
This is different from uploading a general organisational document. The important question is not only where the file sits, but who must keep it current, who reviews it and what happens when it is missing or expires.
- Staff member and document requirement
- Issue, check, expiry or next-review date
- Employee responsibility and authorised reviewer
- Requested, supplied, accepted, rejected and overdue states
Use Evidence for proof linked to another record
Evidence supports a training result, assessment, competence decision or other governed record. Examples include a certificate, observed assessment, signed declaration or uploaded work sample. The evidence should remain linked to the record it proves and to the review decision made about it.
Avoid copying the same file into Documents, Evidence and a staff profile simply to make it visible. Link the source record and show its status instead. Duplication creates conflicting versions, unclear retention and avoidable access risk.
- Name what the evidence is intended to prove
- Keep supplied and accepted evidence distinct
- Record the reviewer, decision, date and reason
- Retain the relevant history without creating parallel copies
Choose the record first, then the file
Start with the business record: an organisational document, a personal document requirement, a training result or an assessment. Once that purpose is clear, store or link the file in the workspace that owns the lifecycle.
A useful rule is simple: Documents governs shared files; staff documents governs person-specific documents and renewals; Evidence supports another record. Policies keeps the additional publication and acknowledgement workflow needed for controlled policies.
Questions this guide answers
Is a staff certificate a document or evidence?
It depends on the record it supports. A certificate supplied as proof of training should normally remain linked to that training record. A person-specific document that has its own expiry and renewal workflow can be managed as a staff document.
Should the same file be uploaded to several modules?
Usually no. Keep one governed source where possible and link related records to it. Duplicate uploads make version, access and retention decisions harder to trust.
Are policies just documents?
A policy is a controlled document, but it may need publication, audience assignment, acknowledgement, declarations and overdue follow-up. That additional workflow is why Policies is distinct from the general organisation library.

