Skip to content

Milestone 5 slice 3: retention, holds, and lawful disposition #64

Description

@TusanHomichi

Outcome

Implement Milestone 5 slice 3 from the owner-approved #44 decisions: versioned retention policies, typed holds, explicit disposition authority, exact-scope preview and confirmation, authorized content destruction, independently retained tombstones, and honest export verification of policy boundaries.

Delivery stages

  1. Policy and hold administration: immutable policy versions, attributed hold creation/replacement/release, explicit grants with no default bundle, and operator interface. This stage cannot delete records.
  2. Disposition execution: a reviewed scope model covering complete record lineage, snapshots, acknowledgments/amendments, summary dependencies, in-scope derived material, backups/restore implications, and partial failure/retry. Policy and holds are rechecked in the execution transaction after exact preview confirmation. Ordinary immutability stays enforced.
  3. Portable disposition evidence and independent log retention: format/producer/verifier agreement, tombstones that do not retain destroyed content, policy-required metadata closure, and operator documentation.

Acceptance criteria

  • Versioned policy and explicit authority have typed service contracts and usable administration.
  • All six named hold kinds plus configured other authority block applicable disposition; changes and releases are attributed.
  • Operators preview exact scope and authority; changed policy, scope, holds, or permission invalidates confirmation.
  • Authorized destruction removes all in-scope content and copies, with transactional or explicitly recoverable failure/retry behavior. Backup and restore semantics cannot silently resurrect disposed records or overstate destruction.
  • Normal writes retain immutable-record protections.
  • Disposition events have independently configured retention, do not smuggle destroyed personal content, and support policy-required metadata removal.
  • Exports and file-only verification report disposed/unavailable content and policy boundaries honestly.
  • Full repository and browser gates pass; operator documentation states implemented limits.

No agency retention schedule or legal authority is supplied by Consolebook. Installation operators configure their own approved values. This issue remains open until all stages are implemented and proved.

Refs #44; docs/records-integrity.md; PRINCIPLES.md 3, 7, 8, 10.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions