{
  "schema_version": "1.0",
  "id": "retention",
  "title": "Report Retention and Deletion",
  "summary": "Final reports default to 90 days; financial records follow a separate four-year schedule.",
  "sections": {
    "default_report": "90_days",
    "modes": [
      "delete_after_delivery",
      "24_hours",
      "7_days",
      "30_days",
      "90_days",
      "365_days",
      "until_deleted"
    ],
    "inspect": "GET /v1/reports/{report_id}",
    "delete_early": "DELETE /v1/reports/{report_id}",
    "admin_exception": "POST /v1/reports/{report_id} requires security:manage, an expiry or clear action, a reason, and an audit record.",
    "financial": "Receipts, usage ledger entries, quotes, payments, refunds, disputes, and supporting financial records: 4 years baseline.",
    "security_audit": "2 years baseline; identifiers and redacted metadata only.",
    "cleanup": "Bounded, idempotent scheduled cleanup tombstones report content and removes expired tokens without deleting financial records."
  },
  "version": "2026-08-v6",
  "effective_at": "2026-08-10T00:00:00Z",
  "content_hash": "sha256:464b2f5e0a8dc6f59e1b3fd42a83ba432e3d35a5818d4f1050b0986c33207dad"
}