Retention and deletion
Apply explicit policies to streams, project state, evidence, provider data, and security records.
Outcome
Every data class has a named region, retention, backup, export, and deletion policy, and a deletion request cannot silently destroy still-referenced evidence.
Prerequisites
Classify transient stream chunks, ordinary state, immutable evidence, sensitive sources, provider prompts/responses, and audit/security events. Identify legal or contractual holds before action.
Steps
- Export the project when the user requests a portable copy.
- Stop schedules and revoke active attempt capabilities.
- Mark project deletion intent in canonical state.
- Remove provider sandboxes and transient staging data through reconciled, idempotent operations.
- Apply database and artifact policies in dependency order.
- Record completion and any retained class with its reason and expiry.
Do not describe provider “zero retention” unless the selected account, endpoint, and contract have been verified.
Verify
The project cannot be read through application or direct role tests; unrelated tenant objects remain; retained records match the declared exception; and provider inventories show no orphaned resources.
Recover
Deletion is consequential and may be irreversible. Before the final irreversible step, verify exact workspace/project identity and export status. If identity or provider state is ambiguous, stop and resolve it rather than broadening the target.