ACTION TYPE · DELETE RECORDS

Deletions that cannot be undone, run by a job nobody watches.

Retention clean-ups, account closures, data-subject requests, log rotation. The job is usually right, and the one time it is not, the evidence it needed is the thing it deleted.

Who runs it today: Nightly clean-up scripts, privacy-request workflows, account-closure agents.

The rules that usually govern it

  • Only records past their retention period
  • Never a record under a legal or regulatory hold
  • Large batches need a second approval
  • Some record types are never deleted by automation

Typical rule shapes, not a claim about any one organisation. A pilot starts from yours.

Where rules like these break

  1. The hold lives somewhere else.

    The system that deletes is rarely the system that knows about the hold. A rule that cannot see the hold cannot honour it.

  2. Small batches, large total.

    A batch-size limit applies per run. Many runs under the limit remove as much as one run the rule would have stopped.

What the gate does

  1. 01

    Checks each request against the proven policy before it executes. What fails never reaches the system.

  2. 02

    Refuses when a window or population the rule depends on is missing or does not reconcile, instead of guessing.

  3. 03

    Seals every decision, allow or block, so it can be re-checked without us.

What you can check today

NOT YET

Nothing public yet for this action type. The decisions on the home page are illustrative, under a sample policy. A pilot is where the first sealed pack for record deletion would come from.