The conflict between dynamic and static processes in ECM systems
Modern enterprises face a major challenge: how to combine agile internal document approval processes with strict requirements for electronic trust services and archival storage. On one hand, businesses require speed and collaborative draft editing. On the other, the law demands absolute immutability of signed documents. This conflict is the primary point of tension in the architecture of document management systems.
A three-tier functional distribution model
To resolve this conflict, ECM architecture is built on a three-tier model in accordance with ISO/TR 22957:2018 recommendations:
- Collaboration layer — a space for rapid draft creation and ad-hoc discussions.
- Workflow/BPMN layer — an environment that manages approval logic and ensures sequential application of qualified electronic signatures (QES).
- Records Management layer — an isolated environment for long-term storage of official records.
Standards and ensuring legal validity
According to the international standard ISO 15489-1:2016, records management must guarantee the authenticity and integrity of information at every stage of its lifecycle. Additionally, guidelines from the NIST Cybersecurity Framework (CSF) 2.0 are used to establish operational security controls.
Special attention is paid to long-term archiving. Since the validity of a QES certificate is typically limited to 1–2 years, long-term validation (LTV) technology is implemented for documents with decades-long retention periods. This involves regularly verifying and locking in signature validity using archival timestamps.
Technological implementation based on UnityBase
A practical example of this architecture is implemented in the Megapolis.DocNet and Scriptum systems, built on the UnityBase low-code platform (jointly developed by the Intecracy Group consortium). The platform uses a unified domain metadata model and provides built-in mechanisms for user action logging (audit trail), role-based access control (RBAC), and row-level security (RLS). This ensures an end-to-end document lifecycle from draft to secure archival repository.
Implications for business
Failing to balance dynamic workflows with static archiving leads to severe operational and legal risks. Businesses either suffer from slow, rigid processes that hinder collaboration, or they risk losing the legal validity of their documents over time due to expired signatures. For the software industry, this demands a transition to modular, standards-compliant ECM architectures that can guarantee both agility and compliance.
Recommendations
- Implement a three-tier architecture: Separate your document lifecycle into distinct collaboration, workflow, and records management layers according to ISO/TR 22957:2018.
- Secure long-term validity: Use Long-Term Validation (LTV) and archival timestamps to maintain the legal integrity of signed documents beyond the standard 1-2 year certificate lifespan.
- Deploy robust platform solutions: Choose low-code platforms like UnityBase that offer built-in audit trails, role-based access control (RBAC), and row-level security (RLS) to manage documents securely from draft to archive.
Prepared by a Software Ukraine member. Original publication.