R60 behavior and validation guide
Deleting a client
After an MSP administrator confirms client deletion, the server removes all managed evidence directories associated with the client ID. This includes directories created before a client rename and prior deleted-client recovery archives for that ID. The database record is removed only after storage removal completes and verification finds no matching managed path.
Legal holds and running assessments continue to block deletion. The deletion audit record retains the client identity, administrator reason, and record counts, but it does not retain evidence files.
Governance and ISMS
Select any clause under Governance & ISMS > Clauses 4-10 to see:
- what the requirement expects in plain language;
- examples of evidence and documentation an auditor can review;
- what the selected status means and what should be recorded next.
The Scope tab explains what belongs in each field and shows examples. Enter factual information for the current organization. Prompt text is display-only and is not saved.
Executive and IT remediation reports
Open Reports for the active client and active program.
- Executive - What Needs Attention summarizes open findings, critical/high items, unassigned work, severity distribution, leadership priorities, and readiness gaps.
- IT - What Needs Fixing lists each open technical item with its requirement, affected asset or account, observation, source, recommended action, and closure-evidence checklist. It also lists implementation and evidence gaps.
The client ID and program ID are applied to every server query used for these reports. The application verifies that the program belongs to the active client and refuses to finish the report if the user changes client or program while it is being generated.
Evidence inside the Control Workspace
Select a requirement in Controls Workspace. Use Upload & link evidence to select one or more files; the application stores each version for the active client and links it to the selected requirement without leaving the page. Use Preview selected evidence to view a selected linked or available version in the right panel. The preview supports common images and text-based evidence, plus extracted DOCX text. The application verifies the downloaded file against its retained SHA-256 before displaying it. Unsupported formats remain identified by filename, size, version, timestamp, and verified hash in the same panel.
Windows validation
- Upgrade a Windows R59 client and server to R60.
- Open Governance & ISMS, select several clauses, and confirm the requirement, evidence, and status guidance changes with the selection.
- Open Scope and confirm each field has instructions and an example.
- Open Evidence and confirm the selector displays the requirement ID and title without clipping.
- In Controls Workspace, upload and link image and text evidence. Preview both without leaving the workspace and confirm the displayed hash is verified.
- Open Reports and generate both current-client remediation reports. Verify the client, program, assets/accounts, findings, and gaps belong only to the active client.
- Create a test client with evidence, rename it, add more evidence, and delete it. Confirm no matching
__<clientId>directory and no matching deleted-client archive remains. - Confirm a client with a legal hold or running assessment cannot be deleted.
- Confirm the Documentation Open Document button has normal width.
Guide basis
R68 package: Docs/R60-Complete-Client-Evidence-Deletion.md
Published as a website guide on 1 October 2026. Where a bundled reference is older, the version-specific guide and installed interface take precedence.