noCV
RDELETE-107 · Reconcile exceptions and completion

Keep the removal status page useful after the profile is gone

Practice briefStoryIntermediate

Deleting the profile also removes the data needed to render progress, leaving the requester with a broken page before cleanup is finished.

Focused work estimate
2h 30m + prerequisites
Priority in the scenario
Medium
Engineering practice
Minimal disclosure · Access control

Estimated field mix

  • Privacy engineering40%
  • Security40%
  • Frontend20%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional collaboration product lets a member request removal of their personal profile. Search, notifications and cached displays retain copies after the primary row disappears. The exercise uses a documented product deletion policy and synthetic identities.

Setup prerequisites

  • Create local profile, search-index and notification fixtures with controlled provider failures.
  • Define synthetic members, organizations and a current-session authorization fixture.

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Provide a narrowly scoped status mechanism independent of the removed profile display fields.
  • Expose progress categories and unresolved exceptions without returning deleted content or internal storage identifiers.
  • Define status access expiry and deny access to unrelated operations.

Implementation constraints

  • Use the exercise authentication contract or an explicitly scoped expiring receipt; do not place a reusable access secret in generic analytics.

Verification to include

  • Read progress before and after primary-profile removal.
  • Attempt another subject’s operation and an expired receipt/session; verify denial without detail leakage.

Deliverables

  • Minimal status response and post-removal access tests

Rollout and recovery

Publish the status contract before enabling destructive cleanup; retain safe operation metadata for its declared lifetime.

Value of the work

For the engineer: Practice distributed cleanup, identity scope, idempotency and accurate user-facing lifecycle states.

For the team: Produce a reviewable deletion workflow and copy inventory for adaptation to an approved company policy.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.