Evidence Packages: When the Auditor Wants the Bundle, Not the Trail
The six scopes, what is actually inside the ZIP, how long the download link lives, and the two ways a package reaches the customer.
An auditor does not want to navigate your platform. They want a file on their desktop containing everything needed to verify one specific claim — and they want the next one to look the same, so the second review takes an hour instead of a morning. Evidence packages are that export: pick a scope, generate, download, hand it over.
Six scopes
A package can be built around a single asset, an inbound order, an outbound order, a contract, a company across a date window, or a batch of assets selected in a list. The scope is not decoration: it decides which assets get resolved into the bundle. A contract pulls what ran under it, a company plus a window pulls what moved in that period, a batch pulls exactly the rows your operator ticked. Pick the smallest scope that answers the question you were actually asked.
What is in the ZIP
At the root sits summary.pdf — the readable account of the package, its scope, its assets and how it was generated. Beside it a photos folder holds one folder per asset tag with that device’s gallery; generated erasure certificates are filed the same way, one folder per asset tag, when they belong to the scope. External recycling certificates arrive as the original recycler PDFs, filed by certificate number, because a downstream recycler’s document is worth more unretyped. If a gallery ran past the size cap, a note inside the ZIP says so rather than quietly shipping a short set.
The summary PDF is the manifest, and it is the part the auditor opens first anyway. There is also a PDF-only format for reviews where photos are not the point: the summary, and nothing to unzip.
Ready, expired, purged
A package moves through pending, generating and ready, and can end up failed, expired or revoked. A ready package carries a signed download link valid for seven days by default — a platform setting rather than a hardcoded number. An hourly sweeper expires links that have run out; a daily sweeper permanently removes packages that have been expired for ninety days, storage object included. As long as the file itself is still there, the detail page can refresh a stale link instead of regenerating the whole thing.
Ninety days is a deliberate compromise. A regulator asking about a decommission a month after delivery should not hit a dead link, and a bucket full of forgotten ZIPs is nobody’s compliance strategy.
Sending and resuming
A ready, current intermediate package can be sent by your administrators, managers or operators. Final service dossiers contain financial documents and require an administrator, manager or finance user. A package linked to the awarded pickup request becomes available to the authorized customer portal users. Other customer packages go to the order or company contacts, with extra email addresses your team can add. Recipients receive a time-limited download link.
The detail page records the outcome for each recipient: accepted by the mail service, rejected, pending or uncertain. Acceptance does not prove receipt or download. Resume unfinished sends reuses the original message and skips accepted recipients. If the outcome is uncertain or the safe retry period has ended, an administrator or manager must check the mail service and record the confirmed outcome with a reason before another attempt.
If the erasure evidence changes, generate a new package version before sharing again. The previously released version and its delivery history remain available. Shared packages are excluded from routine expiry cleanup.
Intermediate report or final service dossier
Use the existing Generate evidence action on an inbound order, or select that inbound order in the evidence overview. Choose Intermediate report for a PDF summary or ZIP of available evidence. Every selected current erasure source must be readable; failed or partial erasure remains visible with its actual outcome. This report does not confirm that the service is complete.
Final service dossier keeps one inbound order, client, contract and device selection together. The dialog shows required and successful erasures, readable sources, delivered returns with complete signature and photo evidence, and the issued service invoice. Missing requirements are listed before generation. An administrator, manager or finance user can create the final ZIP after these checks pass. It includes the summary, service invoice, return proof, original evidence files and source manifest.
Product footprint remains additional information, with explicit current, imported, provisional and missing coverage. Incomplete Carbontrace coverage does not prevent service delivery. The sources are checked again before the final version is stored or released. If the service evidence changes, that saved dossier is marked outdated; create a new version before sharing again. Earlier versions and their delivery history remain traceable.