noCV
RDELETE-101 · Accept a scoped removal request

Separate profile removal from leaving one organization

Practice briefTaskFoundational

A member belongs to two organizations. The current button says delete account but removes only the active membership.

Focused work estimate
1h 15m + prerequisites
Priority in the scenario
Medium
Engineering practice
Domain boundaries · Identity scope

Estimated field mix

  • Privacy engineering50%
  • System design30%
  • Security20%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional collaboration product lets a member request removal of their personal profile. Search, notifications and cached displays retain copies after the primary row disappears. The exercise uses a documented product deletion policy and synthetic identities.

Setup prerequisites

  • Create local profile, search-index and notification fixtures with controlled provider failures.
  • Define synthetic members, organizations and a current-session authorization fixture.

Preceding work

No earlier ticket is required. Complete the project setup above.

Acceptance criteria

  • Define distinct commands for leaving one organization and removing the global personal profile.
  • List owned stores affected by each command and any retained records under the fictional policy.
  • Show the command scope and expected access change before submission.

Implementation constraints

  • Do not infer global identity from an organization-local display name or email field.

Verification to include

  • Trace a two-organization member through both commands and compare affected records.
  • Verify a membership-only request leaves the other organization and global profile unchanged.

Deliverables

  • Deletion scope contract and multi-organization fixtures

Rollout and recovery

Introduce distinct command names before enabling cleanup adapters.

Value of the work

For the engineer: Practice distributed cleanup, identity scope, idempotency and accurate user-facing lifecycle states.

For the team: Produce a reviewable deletion workflow and copy inventory for adaptation to an approved company policy.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.