Assets Reference Public

Disposal & Sanitization

Retiring equipment in Safekeep: the request, assessment, approval, data-wipe and completion path, what blocks a disposal and why, when sanitization is required, how an exception is granted on the record, and the gain or loss the certificate reports.

Guide version: r1 Module version: 1.11.0 Updated: 2026-08-25 Estimated time: 11 min 5 views 0% helpful
Finance & Governance

Disposal & Sanitization

Retiring a laptop is not a status change. It is a chain of decisions somebody has to be able to defend a year later: who asked, who looked at the hardware, who authorised it, what happened to the data on it, where it went, and what the books lost or gained. Safekeep records all six, and will not let the equipment leave until the ones that matter are answered.

ℹ️
Where it lives. Sidebar Safekeep → Finance, the Disposals tab (ams/accounting/disposals). Reading the list needs the Assets: Finance permit; each step below needs its own. A shared link to ams/disposals lands you on the same tab — there is one page, not two.

The path an asset takes

Five steps, in this order. The page shows them as a stepper on every disposal, so at a glance you can see where one has stopped and what it is waiting for.

  1. Request

    Somebody says an asset should go, and why — obsolete, worn out, beyond repair, lost, stolen, or destined for sale, donation, trade-in or scrap. You may name the intended method now or leave it for the assessment. This is also where the asset is checked against the blockers below.

  2. Assess

    Somebody technical records what state the equipment is actually in. Not optional: an approver should not sign off on destroying something nobody has looked at. An assessment may change the intended method — a machine found beyond repair stops being a sale.

  3. Approve

    Authorisation, by somebody other than the requester. Where the asset is valuable enough, a second, finance signature is also required. Approval decides what happens next: an asset that held data goes to sanitization pending and cannot skip the wipe; anything else goes straight to ready to complete.

  4. Sanitize

    The data is destroyed and the evidence recorded — or, where that is genuinely impossible, an exception is granted on the record. See below.

  5. Complete

    The asset physically leaves. You record where it went, on what date, for how much, and what it cost to get rid of. The book closes, the gain or loss is struck, and the asset drops out of the active register.

Two exits sit alongside the path: Reject (the request is refused) and Cancel (it is abandoned). Both are final for that request and both free the asset, so a fresh request can be raised later — a new one, with its own date, rather than an old decision revived months afterwards.

ℹ️
One open disposal per asset. While a request is live the asset cannot be entered into a second one, so two people cannot dispose of the same machine in parallel. Submitting the same request twice — a double-clicked button, a page that reloaded — simply returns you to the request that already exists.

What stops a request

Three checks run when a disposal is raised. Each one exists because letting it through would leave the register asserting something untrue.

BlockerWhyWhat to do
Still in somebody's custody Disposing under an open custody would leave the register saying a disposed asset is issued to a named employee — and that employee still formally accountable for it. Check the asset in, or close the custody, first. See Custody, Transfers & Returns.
An open serious fault A high or critical fault nobody has closed usually means the asset's story is not finished — a warranty claim, a repair, an insurance matter. Close the fault, or raise the disposal with the reason that matches it (next row).
Already disposed The asset has already left. There is nothing to dispose of. Nothing — check you have the right asset.
ℹ️
When the fault IS the reason, it does not block. A disposal filed as lost, stolen or beyond repair is not stopped by the open high-severity issue describing exactly that. Blocking there would make a broken asset undisposable and leave it counted as in-service forever — which is how registers end up full of equipment that no longer exists.

Sanitization: the point of the whole workflow

Equipment that held company data must not leave the building still holding it. So an asset that carries data cannot reach completed without either recorded wipe evidence or a named, reasoned waiver. There is no third path, and no way to press past it.

When it is required

Two signals decide, and your administrator chooses which are consulted:

RuleSanitization is required when…
Storage mediaThe asset is marked as containing storage media.
ClassificationThe asset's data classification is a sensitive one — confidential, restricted, secret or top secret.
Both (the default)Either signal is present.
ManualNothing is derived — the requester ticks the box.
⚠️
"Both" means EITHER signal, not both conditions. It reads like "and" and is not: the setting names which signals are consulted, and under "both" an asset tripping either one requires sanitization. Reading it as "and" would let a classified device with no drive, or an unclassified laptop full of data, walk out unwiped — which is precisely the pair of cases the default is there to catch.
ℹ️
The decision is taken once, at request time, and stored. It is a record of what was agreed, not a live reading of the rule. A policy relaxed next year must not retroactively rewrite what was decided about the drive already sitting in a box; a policy tightened next year must not silently reopen disposals completed honestly under the old one. An approver can override the decision either way — with a reason.

Recording the wipe

The Sanitize form asks for more than a tick, because "it was wiped" is not defensible a year later and "purged with this tool on this date, performed by A, verified by B, certificate number N" is:

FieldNotes
Method (required)Clear, purge or destroy; cryptographic erase; factory reset; physical destruction; or a vendor-certified service.
ToolWhat was used. The detail that makes a method claim checkable.
Performed by / Verified byDeliberately two people. Whoever wiped it should not be the only person attesting that it was wiped.
CertificateA vendor's destruction certificate number, where one exists.
Date and filesWhen it happened, plus photos or certificates as evidence.

You may record a wipe even where none was required. Somebody who wiped a machine nobody asked them to wipe has done a good thing, and refusing to record it would teach people not to bother.

When the wipe is impossible: the exception

Some assets genuinely cannot be sanitized. A drive already physically destroyed cannot be "cleared"; a stolen laptop is not available to wipe. Refusing to model that would push people into fabricating evidence, which is strictly worse than an honest exception.

⚠️
An exception is a governed act, not a shortcut. It takes an approver, a timestamp, and a mandatory reason — the request is refused without one, because the reason is the control. Without it the exception is just a switch that turns the gate off. Expect every exception to be read: this is the first thing a reviewer filters for, and a list of them with thin reasons is a finding in itself.
ℹ️
Nobody is chased forever, but nobody is forgotten either. A daily reminder follows up disposals whose wipe has not been recorded, on a cadence your administrator sets (three days by default) rather than every morning. Equipment waiting in a cupboard with its data still on it is exactly the thing that gets quietly forgotten.

The second, finance signature

Above a configured value, disposing of an asset needs a finance approval on top of the operational one. The requirement is decided when the request is raised, from the asset's cost or book value, and it is shown on the disposal.

It is a second signature, not a second status: the disposal still moves forward on the operational approval, and if the approver happens to hold the finance permit their signature counts for both at once. Where they do not, the disposal simply cannot be completed until somebody who does signs. Blocking the whole approval instead would strand every disposal whose operations approver is not also a finance manager — which is most of them.

Completing the disposal

Completion is where everything irreversible happens, so it happens once and all at once. The form asks for:

FieldRequired when
Disposal dateAlways.
MethodAlways, and it must be one your administrator permits.
ProceedsOnly for a sale or a trade-in. Scrapping something for nothing is the normal case, and demanding an amount there would only teach people to type 1.
RecipientWhenever the asset goes to a named party — sale, trade-in, donation, transfer out, return to lessor.
Disposal cost, filesOptional, but the cost belongs in the gain/loss figure and the files are the evidence somebody will ask for.

On completion, in a single step:

What happensDetail
The book closesIts carrying amount at the last posted period is captured as the value at disposal, and the book stops being touched by future depreciation runs.
Gain or loss is struckproceeds − disposal cost − book value at disposal. Positive is a gain, negative a loss.
The asset is archivedIt is stamped as disposed and moved onto your archived status label, so it leaves the active register while staying fully readable.
The record is writtenAn entry on the asset's activity feed, an audit-log entry, and a notification to the people involved.
ℹ️
An asset with no financial book shows a blank gain/loss, not a fabricated one. If no carrying amount was ever recorded, reporting the proceeds as the gain would overstate it by the entire unrecorded value of the asset. A blank is the honest answer, and it points at the real problem: the asset should have had a book. See Finance & Depreciation.
⚠️
Pressing Complete twice is safe, and does not do it twice. A retry finds the disposal already completed and shows you the same result. It does not close the book a second time, restate the gain, or send a second notification — none of which could be recalled.

The certificate

A completed disposal can print a certificate of disposal: the asset and its tag and serial, the reason and method, the date and recipient, the full sanitization record — method, tool, who performed and who verified it, the certificate number — or the exception and its reason, the financial outcome, and a statement that the asset has been removed from the active register. It carries a quotable reference number of its own.

This is the document you hand to a recycler, attach to an insurance claim, or produce when somebody asks what happened to a machine that is no longer on the floor.

Following a disposal

Each disposal has its own page with the stepper, every field recorded so far, the evidence files, and a chronology of the decisions in the order they were taken — oldest first, so it reads the same direction as the stepper above it. Where a disposal is stuck, the step that is waiting says what it is waiting for.

The list itself filters by status, by reason, and by sanitization status, which is the view worth keeping: every disposal whose wipe has not been settled, in one place.

ℹ️
Disposal notifications open the asset, not the disposal. Notifications about approvals, sanitization and completion deep-link to the asset's page — from there, its activity feed carries the disposal. Worth knowing before you go looking for a link that behaves differently.

Who can do what

PermitLets somebody…
Assets: FinanceSee the disposal list and any disposal's page. Required by everybody below.
Disposal: Request & assessRaise a request, record the technical assessment, cancel a request.
Disposal: Approve / reject / exceptionAuthorise or refuse a disposal, and grant a sanitization exception.
Disposal: Sanitize & completeRecord the wipe and complete the disposal.
Finance: Manage books & estimatesGive the second, finance signature above the value threshold.

Requesting and approving are separate permits for the same reason preparing and posting are in depreciation: an approval the requester gave themselves evidences nothing. The full reference is in Permissions & Roles.

ℹ️
Settings behind the scenes. Which sanitization rule applies, which disposal methods are permitted, the value threshold that demands a finance signature, whether evidence is expected, how often pending wipes are chased, and which status label an archived asset lands on are all administrator-controlled. If the workflow behaves differently from this page, that is where the difference will be.

Related

Was this guide helpful?

Report a content problem