Outcome
Implement Milestone 5 slice 3 from the owner-approved #44 decisions: versioned retention policies, typed holds, explicit disposition authority, exact-scope preview and confirmation, authorized content destruction, independently retained tombstones, and honest export verification of policy boundaries.
Delivery stages
- Policy and hold administration: immutable policy versions, attributed hold creation/replacement/release, explicit grants with no default bundle, and operator interface. This stage cannot delete records.
- Disposition execution: a reviewed scope model covering complete record lineage, snapshots, acknowledgments/amendments, summary dependencies, in-scope derived material, backups/restore implications, and partial failure/retry. Policy and holds are rechecked in the execution transaction after exact preview confirmation. Ordinary immutability stays enforced.
- Portable disposition evidence and independent log retention: format/producer/verifier agreement, tombstones that do not retain destroyed content, policy-required metadata closure, and operator documentation.
Acceptance criteria
No agency retention schedule or legal authority is supplied by Consolebook. Installation operators configure their own approved values. This issue remains open until all stages are implemented and proved.
Refs #44; docs/records-integrity.md; PRINCIPLES.md 3, 7, 8, 10.
Outcome
Implement Milestone 5 slice 3 from the owner-approved #44 decisions: versioned retention policies, typed holds, explicit disposition authority, exact-scope preview and confirmation, authorized content destruction, independently retained tombstones, and honest export verification of policy boundaries.
Delivery stages
Acceptance criteria
No agency retention schedule or legal authority is supplied by Consolebook. Installation operators configure their own approved values. This issue remains open until all stages are implemented and proved.
Refs #44; docs/records-integrity.md; PRINCIPLES.md 3, 7, 8, 10.