Documents on records
A record is a claim; a document is the paper behind it. Six kinds of record carry documents:
| Record | Where | Who may attach and remove |
|---|---|---|
| Authorization (COA, waiver, operational authorization) | Documents on the card, Authorizations | Safety records permission |
| Insurance policy | Documents on the policy, Authorizations | Safety records permission |
| Occurrence | Documents on the occurrence page | Safety records permission |
| Pilot credential | Documents on the credential, Pilot Logbook, My details | The person themselves, or the Members permission |
| Training sign-off | evidence on the record, Training Programs | Training permission |
| Maintenance record | documents on the record, Maintenance, Tech log | Maintenance permission |
Reading a record's documents takes the same area's view permission; organization admins can do both everywhere.
What a document is#
A PDF, a JPEG or PNG image, or plain text, up to 25 MB, up to 40 per record. The type is read from the file's own bytes, never from its name, so a file called certificate.pdf that is not a PDF is refused. A PDF or text file is kept exactly as it arrived, and a JPEG or PNG is kept without its hidden details (below) and is never re-encoded the way a job photograph is. The SHA-256 of the file as kept is on the record; on the way out the bytes are checked against that hash, and a file that has been altered is refused rather than served.
The sheet#
Documents opens a sheet listing what the record carries: the file name, an optional label, the size and the date. A name opens the file in a new tab (a PDF or an image displays; anything else downloads). Add takes a file and an optional label. A JPEG or PNG loses its hidden location, camera and time details on the way in, and keeps its orientation, so it still shows the right way up. Remove asks why: the document leaves the record and nobody can open it, and its file is kept, hidden, until your organization's window for withdrawn photos and documents on the Retention page passes, then deleted with a line in the disposal register. Adding and removing are written to the activity log with the record, the file name, its size and the start of its hash. A document on a record a legal hold reaches cannot be removed until the hold is lifted; the sheet says why. That is a document on an occurrence whose flight is on legal hold, and a document on any of these records that a legal hold by matter reaches through its aircraft, its pilot or its date.
What they are for#
An inspector asks for the COA behind an operation, an insurer for the certificate on the policy that covered a flight, a training auditor for the sign-off sheet, a maintenance auditor for the outside shop's release. Each is one click from the record it supports, and the audit binder's verification code covers the record that names it. The audit binder and every audit package list each document attached to the records they include, by name, size and SHA-256 fingerprint, without the files themselves: hand a document over on its own, and the reader checks it against the fingerprint in the binder or package. A document removed from its record is not on the list.
A client usually asks for the facts as well as the paper: who flew, on what, under which authorization, with what insurance. A job's flight record and a client's flight statement can print those from your records in an Operator credentials block, and they lead with your business name and carry a QR code that opens the document's verification. See Clients and Jobs. Every document issued with a verification code keeps, with its code, the record data it printed: it is in your organization export's issued_documents.json and is deleted with your organization's data, and the verification page never shows it (see Verifying documents).