What this means for the deal
- Keep source files immutable and create separately identified working copies.
- Use one document register to expose version, status, source date, lane, owner and missing evidence.
- Grant the minimum project access required and remove access when a role ends.
- Do not treat an upload, filename, browser hash or selected status as proof of legal effect.
- Set retention and destruction rules with privacy, legal, tax, insurance and operational advisers.
Build a chain of evidence, not a folder of attachments
A commercial leasing file mixes market material, correspondence, proposals, financial models, drawings, diligence records, legal drafts, approvals and final instruments. Those files do not carry the same authority. The control system should show whether an item is a source received from another party, an internal working record, a draft under review, an approval record, an executed instrument or a superseded copy.
Start with a project identifier and a document register. The register is the index; the file is the evidence. Each register row should point to the controlled file and preserve its lane, title, document date, version, source, responsible owner, review status, confidentiality class and any missing counterpart, signature, schedule or verification. Never infer those fields from a filename alone.
| Control field | What it answers | Example without invented authority |
|---|---|---|
| Project and lane | Where does the record belong? | Project 24-017 · diligence |
| Document identity | What is it? | Landlord proposal · option B |
| Source and received date | Who supplied it and when? | Landlord representative · 2026-08-25 |
| Version and status | Which state is this copy in? | v03 · working draft |
| Authority | Who reviewed or approved it? | Approval not yet recorded |
| Exceptions | What remains incomplete? | Schedule C absent from source file |
Separate source, working, approval and executed states
Preserve an unaltered source copy when a document is received. Create a working copy for markup and never silently replace the source. Use a naming convention that stays useful outside the software: project, lane, document type, counterparty or property identifier, source date, version and state. Keep sensitive personal information out of filenames because filenames may appear in notifications, exports or logs.
Version numbers identify sequence, not authority. A file called final, approved or executed may still be incomplete, unsigned, incorrectly assembled or later superseded. Record approval in a separate decision or activity entry and compare the executed set against the approved draft, exhibits, guaranties and counterpart pages before changing its status.
- Use dates in YYYY-MM-DD format and avoid ambiguous labels such as latest, new or final-final.
- Increment the version when substantive content changes; do not overwrite a circulated draft.
- Record the source file name separately when renaming a controlled copy.
- For redlines, identify both the base and compared versions.
- For executed sets, retain the assembled PDF and the separate source counterparts when advisers require them.
Give each participant the least access needed for the current task
Lease files can contain personal information, banking details, financial statements, security information, insurance records, floor plans and commercially sensitive terms. Access should follow the role and the stage of the project. Owners control membership and deletion; editors can maintain the working file; viewers can read current records without changing them. A link should expire and should not become a substitute for managing membership.
Canadian privacy obligations depend on the organization, province, activity and information involved. Alberta describes PIPA as its private-sector privacy law and requires reasonable measures against unauthorized access, collection, use, disclosure, copying, modification, disposal or destruction. PIPEDA's safeguards principle similarly ties protection to sensitivity. Apply the stricter internal control where the file contains high-value or sensitive information, and obtain legal or privacy advice for the actual organization and transaction.
| Role | Typical capability | Control question |
|---|---|---|
| Owner | Membership, uploads, metadata, deletion | Is this person accountable for the project file? |
| Editor | Uploads, metadata and working-file maintenance | Does the current assignment require change authority? |
| Viewer | Read and time-limited download | Does the participant need the file but not change authority? |
| External adviser | Narrow, time-bound access where supported | Which exact lane and period are required? |
File by the decision the document supports
A controlled lane makes the document useful to the next decision. Requirements hold the approved operating brief. Tourbook holds source-controlled property evidence and tour records. LOI holds issue lists, proposals, redlines and authority. Diligence holds property-specific evidence and adviser outputs. The lease lane holds draft reconciliation and the execution set. Buildout and commencement hold drawings, changes, inspections, turnover and actual-event evidence. Administration receives the abstract, obligations and notice controls.
Do not duplicate a file into every lane. Keep one controlled record and link the relevant workflow to it. When a later record depends on an earlier one, record that relationship: a budget depends on a scope version; a lease schedule depends on a drawing; a commencement entry depends on an actual event and the governing clause. The relationship matters more than the folder depth.
| Lane | Core records | Handoff test |
|---|---|---|
| Requirements | Brief, authority, budget | Is the requirement approved and dated? |
| Tourbook | Source sheets, photos, notes, exclusions | Can each claim be traced to a dated source? |
| LOI | Proposals, redlines, issue and authority records | Is the current negotiating position identifiable? |
| Diligence | Reports, permits, title, environmental and adviser review | Are gaps and release authority recorded? |
| Lease | Drafts, comparisons, approval and execution set | Does the executed package match the authorized form? |
| Administration | Abstract, dates, notices and obligations | Did operative terms transfer without assumption? |
Reserve, upload, verify and finalize as separate controls
A secure upload is a sequence. Confirm the user's project role, validate the file type and size, reserve a unique storage path, upload to private storage, verify that the stored object matches the reservation, then finalize the metadata record. If finalization fails, remove the orphaned object where possible and record the failure for follow-up. The file should not appear as a completed register item merely because bytes reached storage.
Content review remains a human and adviser task. A storage service does not necessarily scan for malware, read the document, extract clauses, confirm redactions or determine whether signatures are valid. Keep those limitations explicit. Before relying on a file, open it safely, confirm the expected pages and schedules, reconcile material terms and record the reviewer and review date.
- Reject unsupported extensions, MIME types and files above the published limit before upload.
- Use private storage and short-lived signed download links instead of public object URLs.
- Log material actions such as upload, metadata change, download-link creation and removal.
- Do not use status selectors to manufacture approvals or legal conclusions.
- Escalate encrypted, corrupt, macro-enabled or unexpected files under the organization's security process.
Retain by purpose and obligation—not by storage convenience
The Office of the Privacy Commissioner of Canada says organizations should know what personal information they hold, limit employee access, establish retention periods and securely dispose of information that no longer serves its purpose. Alberta guidance likewise connects protection with reasonable business and legal retention. Those principles do not produce one universal lease-file period. The right schedule depends on the document, governing law, limitation periods, tax and accounting rules, insurance, disputes, corporate policy and the continuing lease obligation.
Create a schedule by record class and define a trigger, not just a number of years. Examples of triggers include project abandonment, lease expiry, final payment, claim closure or termination of a guarantee. Add legal-hold rules that suspend ordinary destruction. At the end of the period, delete working copies, exports and backup copies under the organization's approved process; removing one register row is not proof that every copy has been destroyed.
| Field | Control purpose | Example question |
|---|---|---|
| Record class | Groups records with similar obligations | Executed lease, diligence, invoice or working draft? |
| Trigger | Starts the retention clock | Expiry, termination, payment or matter closure? |
| Period and authority | Explains the rule | Which law, policy or adviser instruction supports it? |
| Legal hold | Suspends destruction | Is litigation, audit, claim or investigation anticipated? |
| Disposition evidence | Records controlled destruction | Who approved what was destroyed and when? |
Design the file for staff change, system failure and dispute
At execution, transfer the controlled package to lease administration with a signed-off index: executed lease, schedules, amendments, guarantees, insurance requirements, notices, payment instructions, commencement evidence, drawings and unresolved follow-ups. Confirm that the receiving owner can access the files and understands which dates are actual, contractual, calculated or pending evidence.
The Canadian Centre for Cyber Security recommends identifying high-value information, applying least privilege, maintaining activity logs, backing up essential information, encrypting backups and testing restoration. A project vault is one working control, not the organization's complete backup, records-management or incident-response program. Define who responds to suspected unauthorized access, lost credentials, malicious files or unavailable data, and preserve relevant logs before ordinary cleanup occurs.
Frequently asked questions
Does uploading a lease make it an executed or verified document?+
No. Upload confirms only that a file was submitted to storage. Execution, completeness, authenticity, authority and legal effect require review of the actual document and transaction evidence by the appropriate people and advisers.
Should every project participant be an editor?+
No. Use the minimum access needed. People who only need to inspect or download the current file should normally be viewers; editing and membership authority should remain narrower and be removed when the assignment ends.
Can a SHA-256 hash prove a lease is authentic?+
No. A hash can help determine whether file bytes changed, but it does not identify the signer, validate a signature, prove the file is complete or establish legal effect.
How long should a commercial lease file be kept in Canada?+
There is no single period suitable for every record or organization. Set a record-class schedule with legal, privacy, tax, accounting, insurance and operational advice, define the trigger and legal-hold rules, and document controlled disposition.
Is a private cloud bucket a complete security program?+
No. Private storage and time-limited downloads are useful controls, but the organization still needs identity management, least privilege, endpoint security, malware handling, backups, restoration testing, retention, incident response and staff procedures.
What belongs in the final handover package?+
The governing executed instruments and schedules, later amendments, guarantees where applicable, commencement evidence, payment and notice controls, insurance and compliance requirements, current drawings, the lease abstract, obligation owners and a register of open exceptions.
Where the factual guidance comes from
These links support narrow factual points in this guide. They do not replace review of the proposal, executed lease or advice for the actual transaction.
Office of the Privacy Commissioner of Canada — PIPEDA fair information principles ↗Official principles for accountability, limiting collection, retention, safeguards and access. Applicability depends on the organization and activity.Office of the Privacy Commissioner of Canada — Limiting use, disclosure and retention ↗Official operational guidance on access limits, retention schedules, reviews and secure disposal of personal information.Government of Alberta — Personal Information Protection Act ↗Official current Alberta hub identifying PIPA as the province's private-sector privacy law and distinguishing federally regulated organizations.Government of Alberta — Organization responsibilities for protecting personal information ↗Official Alberta guidance on reasonable security measures, accountability and service-provider considerations.Canadian Centre for Cyber Security — Baseline cyber security controls ↗Official Canadian guidance on incident response, authentication, backup, encryption, cloud services, access control and authorization.Canadian Centre for Cyber Security — Protecting high-value information ↗Official identify, protect, detect, respond, recover and review framework for high-value business information.This guide is general educational information and financial-workflow support. It is not legal, tax, accounting, engineering, environmental, appraisal or brokerage advice. Verify source documents and obtain appropriate professional advice before acting.
