The chain
Every compliance-relevant act writes an audit event: issuing a KID, approving a timesheet, recording a right-to-work check, filing umbrella evidence, generating an invoice, changing an umbrella's risk status. Each event carries a hash of the one before it.
Because the events are chained, a removed or altered row breaks the chain from that point on. The value of that is not cryptographic theatre: it is that the trail is either intact or visibly not, rather than quietly plausible.
The pack
An evidence pack assembles everything held about one placement: the placement itself, the worker and client, the umbrella and its evidence position, the right-to-work record, the Key Information Document, the assignment confirmation, the weeks and who approved them, and both invoice series. One call, one document.
This is the thing an agency currently builds by hand the night before an audit, out of a spreadsheet, a shared drive, an inbox and the accounting package. Assembling it in advance is not the same as holding it: what makes it defensible is that each piece was recorded when it happened, with its date, by a person the record names.
Retention is a deliberate act
Documents carry a retention category and a date. Deletion happens as a scheduled, logged act rather than as a delete buried in a service method, so both keeping something and destroying it are decisions the record can account for.
What an inspector actually asks
Not "do you have a policy". The question is closer to: this worker, on this assignment, in this week, show me the right to work, the key information document, the umbrella you paid through, the hours the client agreed and the invoice you raised. Every one of those is a different system in most agencies, and the join between them is the work.
One placement, the whole chain
Open the demo and build an evidence pack for any placement. It is the same call an API key makes.