Disposition follows rules in authorised, current disposition authorities, and systems support executing disposition actions. Records and metadata are kept for the specified periods and actions are carried out: destruction, transfer of control to an organisation taking over the business, or transfer to an archive. Actions are reviewed beforehand in case requirements changed, and some metadata may need to be kept longer than the record. Destruction is always authorised, never done while litigation, legal action or investigation is under way or anticipated, complete and consistent with security or access restrictions, and documented.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.