> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.co.in/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/docs/_mcp/server.

# Object Locking

> Mark objects as immutable for compliance, ransomware protection, or regulatory holds. Object Lock is a permanent bucket setting in IBEE Object Storage.

**Object Lock** prevents objects from being deleted or overwritten while a retention period is in effect. Use it for compliance (financial records, audit logs), ransomware protection, or any case where data integrity must be guaranteed.

> **Warning**
>
> **Object Lock is a permanent bucket setting.** It must be enabled at **bucket creation time** in the **Versioning and object lock** section of the create-bucket page. It cannot be enabled, disabled, or changed after the bucket is created.

## Enable Object Lock at bucket creation

When creating a bucket, turn on **Object lock (WORM)** in the **Versioning and object lock** section before clicking **Create Bucket**. Turning it on also turns on **Versioning**. See [Buckets → Create a bucket](/docs/infrastructure/object-storage/buckets#create-a-bucket).

You can set the bucket's default retention right there: pick **None**, **Governance**, or **Compliance** and, for Governance or Compliance, a **Retention period** in days (default 30).

After creation, the **Lock Settings** tab is active for the bucket and you can change the default retention at any time.

## Lock Settings tab

After bucket creation, find the lock state in two places:

* The **General** tab shows **Object Lock** as a read-only field (Enabled or Disabled).
* The **Lock Settings** tab shows the active retention configuration.

### If Object Lock was enabled at creation

The **Lock Settings** tab lets you manage retention policies for objects in the bucket. Object Lock applies to objects uploaded **after** retention is configured.

### If Object Lock was not enabled at creation

The **Lock Settings** tab shows the message:

> *"Object Lock Not Enabled — Object locking must be enabled when creating the bucket to use retention policies. This setting cannot be changed after bucket creation."*

The message is marked **Permanent Bucket Setting**. To use Object Lock for that workload, create a new bucket with the option turned on and migrate objects.

## How retention works

A locked object cannot be overwritten or deleted until its **retention period** expires. You configure retention on the **Lock Settings** tab under **Default Retention Policy**, which applies to every object uploaded **after** the policy is saved. A policy has two parts: a **retention mode** and a **retention period**.

### Retention modes

The retention mode controls *who* can shorten or remove the lock before it expires. Choose one:

| Mode           | Who can override                                                                          | Use it for                                                                                   |
| -------------- | ----------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- |
| **GOVERNANCE** | Users with special permissions can override retention and delete or modify objects early. | Internal data-integrity policies where a privileged operator may still need an escape hatch. |
| **COMPLIANCE** | No one can delete or modify objects until retention expires — not even an Admin token.    | Regulatory holds, financial records, and audit logs where immutability must be guaranteed.   |

> **Warning**
>
> **COMPLIANCE is the strictest protection.** Once an object is written under a COMPLIANCE retention period, neither you nor any token can delete or overwrite it until the period expires. Confirm the retention period is correct before you save.

### Retention period

The retention period is *how long* objects stay locked. Set it under **Retention Period** using a number plus a unit (**Days** or **Years**); the page shows the resolved **Total Retention Period** below the field. The lock stays in effect for that duration from the time each object is uploaded.

### Set a default retention policy

1. Open the bucket and go to the **Lock Settings** tab.
2. Under **Default Retention Policy**, click **Edit**.
3. Select a **Retention Mode** — **GOVERNANCE** or **COMPLIANCE**.
4. Set the **Retention Period** value and unit (**Days** or **Years**), and check the **Total Retention Period** summary.
5. Click **Save Changes**. The policy status shows as **Configured** and applies to objects uploaded afterward.

Use Object Lock together with API token scoping ([Bucket policies](/docs/infrastructure/object-storage/buckets/bucket-policies)) so that no path can bypass the lock.

## Lock individual objects

In a bucket with Object Lock enabled, each object's actions menu on the **Objects** tab has two extra entries.

### Set retention on one object

1. Open the object's actions menu and click **Set Retention**.
2. Choose a **Retention Mode** — **Governance (Admin can override)** or **Compliance (Cannot delete by anyone)**.
3. Enter **Retain for (days)**. The dialog shows the resulting **Locked until** date.
4. Save. Once an object has retention, the menu shows its locked-until date instead of **Set Retention**.

### Legal hold

A legal hold locks an object with no expiry date, independently of retention. While legal hold is on, the object cannot be deleted or modified, and the hold stays until someone removes it.

* To place a hold, open the object's actions menu and click **Set Legal Hold**, then turn the hold on and save.
* To lift it, click **Remove Legal Hold**.

Objects under legal hold can't be deleted from the portal — the delete button shows *"Cannot delete: object has legal hold"*.

## Best practices

* **Decide at creation time.** Because Object Lock cannot be added later, plan before creating buckets that may need immutability.
* **Pair with lifecycle rules carefully.** Lifecycle expiry cannot delete locked objects; verify rules don't silently fail on protected data.
* **Document your retention policy** internally so future engineers understand why objects can't be deleted.
* **Don't lock everything.** Reserve Object Lock for buckets where immutability is genuinely required.

## Related

* [Buckets](/docs/infrastructure/object-storage/buckets)
* [Bucket policies](/docs/infrastructure/object-storage/buckets/bucket-policies)
* [Lifecycle](/docs/infrastructure/object-storage/buckets/lifecycle-management)
* [Concepts](/docs/infrastructure/object-storage/core-concepts)