Skip to content

Reviewed privacy system handling ​

Migration038 adds an erasure-only completion workflow for eight declared domains. Completion means an independent operator reviewed the documented handling of that register. It does not certify universal inventory coverage, legal adequacy of retention, or physical erasure of providers/backups. No external API operations, account deletion, or backup deletion run in this workflow.

The first domain binds an exact019 completed owned execution and its database/storage receipts to the case subject, assigned operator and current case revision. The remaining seven domains are financial history; immutable audit/approval/privacy evidence; shared support/dispute/message/moderation records; profile/auth/provider identities; notification workers/external delivery; backups/external systems; and unclassified storage. Each requires an explicit system scope, protected policy reference, protected evidence reference and SHA-256 digest. The operator records documented_retention, documented_erasure or unknown. Retention requires a finite future review deadline. These are staff declarations with independent review, not automatic legal determinations or provider verification.

Routes mount at /admin/privacy-system-handling: GET and POST /cases/:caseId, POST /:id/review. Proposal bodies contain a stable UUID, exact execution ID, displayed case revision, reason and all seven tasks once. Review binds the exact manifest checksum, complete_handling or reject, and reason. Actor identity and MFA assurance come only from the verified authentication callback. Request JSON cannot choose either.

SQL checks service-role RPC authority, aal2, active current global capabilities and locks current staff/role rows. Proposal requires assignment, identity evidence and verification, in-progress erasure status and no hold.019 must have completed its exact approved scope with no uncertain/unavailable storage items. The owned collections must still be empty; recreated records force fresh reviewed execution. Source locks fence owned/storage mutations while validating the snapshot. Completion recomputes the same identity, inventory and019 receipt snapshot; unknown outcomes, expired retention/review deadlines, changed ownership/identity/assignment/case revision, holds, or revoked proposer/reviewer authority refuse completion. The reviewer must differ from the proposer. A stale or held proposal can still be independently rejected without changing case status.

Accepted handling, case completion, case event and audit entry share one transaction. Audit failure rolls back the whole decision. Intent/evidence/checksum and final review are immutable. Exact uncertain retries return the same bound receipt after live caller checks; changed replay intent is rejected. Table permissions, write triggers and the004 case trigger prevent direct or accidentally regranted service-role writes from forging completion. All other completion paths keep004's prohibition. Existing terminal cases are not retroactively certified.

The admin panel displays exact task scope, policy/evidence references and hashes, deadline and manifest before confirmation. Focus/periodic refresh and subject/permission/eligibility changes clear prior confirmations; stale asynchronous responses cannot complete a different case. Historical accepted receipts retain their documented meaning. Reviewers must inspect the protected evidence and applicable policy outside this form; a reference alone is not proof of external deletion.

Local acceptance includes eight actual004/015/019/038 database checks; authenticated callback/receipt adversarial backend tests; and admin independent review, unknown outcome, held rejection, permission revocation, subject switch and receipt mismatch tests. scripts/db-native-privacy-system-handling-checks.mjs replays the full historical baseline and its real command fixture without disabling case triggers in PGlite. scripts/db-native-privacy-handling-concurrency-tests.mjs requires disposable native PostgreSQL and real independent psql sessions; it asserts observed database lock waits for completion/hold, hold/completion, rejection/completion, exact retry and competing reviewer races. That runner is syntax-checked but was not executed locally because the PostgreSQL client is absent and Docker's engine is stopped. Neither representative nor full-schema PGlite checks establish independent concurrency, hosted migration reconciliation, real MFA sessions or physical provider/backup erasure. No hosted writes or customer actions were performed.

Released under Proprietary Enterprise License.