noCV
RRETENTION-104 · Apply removal safely

Preview the attachment purge set with stable decision reasons

Practice briefStoryIntermediate

Operators cannot tell why two similarly aged attachments are treated differently by the retention job.

Focused work estimate
2h 30m + prerequisites
Priority in the scenario
Medium
Engineering practice
Operational tooling · Data minimization

Estimated field mix

  • Privacy engineering40%
  • Developer tooling30%
  • Security30%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

A fictional support service keeps uploaded diagnostic files indefinitely. The exercise policy expires attachments 30 days after case closure, while a separately authorized investigation hold pauses removal. These are invented product rules, not legal advice or compliance certification.

Setup prerequisites

  • Create synthetic cases, attachment metadata and a fake object store with controllable failures.
  • Use an injected UTC clock and an authorized operator fixture; no real support uploads are needed.

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Return bounded pages of eligible, held and ineligible records with policy and decision timestamp.
  • Keep preview tenant-scoped and omit file contents and unrestricted object URLs.
  • State that preview is advisory and execution rechecks current eligibility.

Implementation constraints

  • Use stable cursor ordering; a preview must never claim to lock the future purge set.

Verification to include

  • Compare expiry and hold fixtures with the decision function.
  • Place a hold after preview and verify the preview itself causes no deletion.

Deliverables

  • Purge-preview endpoint and scoped pagination tests

Rollout and recovery

Expose preview to authorized local operators first; disable the view independently of lifecycle records.

Value of the work

For the engineer: Practice temporal policy, deletion races, exception authority and truthful recovery reporting.

For the team: Develop inspectable retention behavior that a company can review against its own approved data policy.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.