Executive assistants create and receive calendars, correspondence, approvals, board logistics, travel files, contact lists, meeting notes, and drafts. Some material may be an organizational record; some may be a convenience copy, transient notification, or personal item. Keeping everything forever is not a neutral choice, and deleting by instinct is not a defensible program. The assistant needs an approved classification, retention, and hold process with qualified owners.
The U.S. National Archives and Records Administration provides federal records-management and scheduling guidance. The FTC advises businesses to understand the personal information they keep, retain it only as long as there is a legitimate need, and dispose of it securely. Private organizations are not automatically governed by federal agency schedules; these sources offer principles, while counsel and records owners must determine applicable duties.
Identify authoritative systems
For each recurring workflow, state where the official record lives: contract repository, board portal, human-resources system, customer platform, finance system, decision register, or approved document library. Email and calendar may notify or coordinate without being the final repository. Link to the record rather than maintaining uncontrolled copies where possible.
Name the record owner and the person who approves corrections, access, retention, and disposition. The assistant can execute a process but should not be made the sole interpreter of whether a document has legal, tax, employment, regulatory, or historical value.
Classify by function, not filename
“Notes,” “final,” and “miscellaneous” do not tell a retention story. Classify content by the business activity it documents: a decision, transaction, governance action, employment matter, customer commitment, expense, or temporary coordination. Apply the approved schedule for that class.
Distinguish authoritative records from convenience copies and drafts, but do not assume every draft is disposable. A draft may document approval, negotiation, or a material decision under the organization’s rules. When unsure, pause and ask the records or legal owner rather than inventing a category.
Control the working environment
Use approved repositories with named access. Avoid personal email, personal drives, unapproved messaging exports, and local folders that no one else can govern. Use consistent naming, versioning, ownership, and status so another authorized person can understand what is current.
Minimize sensitive data in working files. Contact lists do not need every personal detail; travel coordination does not require passport copies in every itinerary folder. Restrict board, employee, legal, and transaction material to the people whose role requires it.
Apply retention schedules as rules
A retention schedule should identify the record class, triggering event, period, responsible system, and approved disposition. “Seven years” without saying seven years after what event is incomplete. Configure system rules where possible and document exceptions.
Do not use inbox age as a proxy for business value. Moving email to an archive forever can increase exposure, while bulk deletion can remove required material. File the necessary record in its authoritative system and manage duplicates according to approved policy.
Recognize and follow a legal hold
A hold directs preservation of specified information that might otherwise be changed or deleted. The notice should come from an authorized legal or records function and define scope, custodians, sources, dates, actions, and contact. The assistant should acknowledge it, ask focused questions about ambiguity, and follow instructions promptly.
Suspend routine deletion only for material within scope as directed; do not independently broaden a hold to every executive-office file. Preserve content and relevant context without reorganizing, annotating, or “cleaning up” it. Do not contact other potential custodians unless the hold process authorizes that communication.
Cover all relevant locations
Work may exist in email, calendar, chat, shared drives, board portals, travel platforms, phones, paper notebooks, recordings, downloads, and collaboration tools. Provide the legal or records owner an honest inventory. Do not promise complete preservation until system owners confirm it.
Forwarding selected messages to a folder may omit attachments, metadata, edits, or linked content. Use the approved technical collection method. Preserve access controls and confidentiality; a hold does not make restricted information broadly shareable.
Handle departures and role changes
Before offboarding, identify open commitments and authoritative records, transfer ownership, preserve held material, and remove access on schedule. Do not ask a departing person to keep corporate records privately or leave an account active because its contents are poorly organized.
Coordinate account disposition with legal, records, technology, security, and the business owner. Automatic deletion, license removal, device wiping, and mailbox conversion can interact with retention and holds. Use a checklist with named approvals and verification.
Dispose securely when authorized
When the schedule and hold status permit disposition, use approved methods appropriate to media and sensitivity. Record completion where policy requires. Deleting a shortcut is not deletion of the underlying file; removing a cloud item may not address exports, backups, or synchronized devices.
Avoid ceremonial “cleanup days” that ask individuals to make unreviewed legal judgments at speed. A safer cleanup applies established classes and escalation paths, with extra care for sensitive and held material.
Audit for recoverability and excess
Sample workflows to confirm that an authorized reviewer can locate the authoritative record, reconstruct its ownership and approval, apply the correct retention trigger, identify hold status, and restrict access. Also identify unnecessary duplicates and obsolete access. Good governance supports both preservation and defensible disposal.
Measure unclassified repositories, overdue ownership transfers, failed disposition jobs, excessive access, hold acknowledgments, unresolved scope questions, and time to locate records. Numbers require interpretation: a large preserved volume may reflect a broad matter or poor prior classification.
The executive office should make a clear operating choice: assistants coordinate records under documented rules; they do not become informal archivists or legal decision-makers. That boundary protects the organization, the executive, and the assistant while keeping important evidence usable.
Method, evidence, and limitations
This guide uses the primary government and standards sources listed below, checked on 2026-09-23. We reviewed them for principles relevant to executive-support operations and translated those principles into a practical workflow. Facts attributed to a source are distinct from our operational analysis. Public guidance and voluntary frameworks are not presented as universal mandates.
We evaluated each workflow through six questions: what outcome is required; what information and authority are necessary; what can fail; who owns exceptions; what evidence should remain; and how access or responsibility ends. We excluded vendor marketing claims, unsupported productivity percentages, invented customer results, and claims that one process guarantees security, compliance, accessibility, or continuity.
The analysis has limits. Duties vary by jurisdiction, sector, contract, organization size, technology, and facts. This material is not legal, employment, privacy, cybersecurity, accessibility, accounting, records, emergency, or insurance advice. Apply the organization’s policies and consult qualified owners for consequential decisions. Recheck sources and local requirements because guidance and operating conditions change.
Executive decision checklist
Before adopting the workflow, answer these questions in writing:
- What result is required, and who is accountable for it?
- Which actions may the assistant execute, prepare for approval, or never take?
- What information is necessary, and what exposure can be eliminated?
- Which identity, device, repository, and communication channel are authorized?
- What event requires work to stop and escalate?
- Who decides an exception, and where is that decision recorded?
- What evidence is needed to reconstruct the work without retaining unnecessary data?
- Who provides backup coverage, and has the handoff been tested?
- When will access, performance, exceptions, and source currency be reviewed?
- How will accounts, copies, integrations, permissions, and temporary authority be removed?
Test the answers with an ordinary request, an incomplete request under deadline pressure, and a plausible request that conflicts with a control. A dependable process stays understandable in all three. If success depends on one person’s memory, personal account, or willingness to challenge an executive without organizational support, redesign it before scaling.
Sources checked
- “Records Management,” U.S. National Archives and Records Administration, https://www.archives.gov/records-mgmt (checked 2026-09-23)
- “Frequently Asked Questions about Records Scheduling and Disposition,” U.S. National Archives and Records Administration, https://www.archives.gov/records-mgmt/faqs/scheduling.html (checked 2026-09-23)
- “Protecting Personal Information: A Guide for Business,” Federal Trade Commission, https://www.ftc.gov/business-guidance/resources/protecting-personal-information-guide-business (checked 2026-09-23)