Audit retention is deferred out of D5 and the table grows without bound. The brief's operating assumptions exclude retention duration, archival, export formats and external shipping from this effort, so no pruning job is registered even though Prune exists. The first party to notice will be an operator, not a reviewer. Someone has to decide what retention means before an operated deployment runs for long.
Done when
Agent instructions
Authority is this issue. The bullet was removed from design/90-decisions.md § Open when this issue was opened, so nothing in design/ restates it.
Prune already exists in the audit contract; what is missing is the decision about who calls it and how long a row lives. The brief deliberately excludes retention from D5, so this is scoped as a decision to be taken and logged, not as work to be scheduled inside the effort.
Stop if settling it turns out to need a contract or schema change — an added column, a changed signature, a migration. That is a /contract amendment and the repository owner's call, not something to fold into the answer here.
Audit retention is deferred out of D5 and the table grows without bound. The brief's operating assumptions exclude retention duration, archival, export formats and external shipping from this effort, so no pruning job is registered even though
Pruneexists. The first party to notice will be an operator, not a reviewer. Someone has to decide what retention means before an operated deployment runs for long.Done when
design/90-decisions.mdwith its rejected alternativesPrune, and on what schedule, is decided and recorded alongside itAgent instructions
Authority is this issue. The bullet was removed from
design/90-decisions.md§ Open when this issue was opened, so nothing indesign/restates it.Prunealready exists in the audit contract; what is missing is the decision about who calls it and how long a row lives. The brief deliberately excludes retention from D5, so this is scoped as a decision to be taken and logged, not as work to be scheduled inside the effort.Stop if settling it turns out to need a contract or schema change — an added column, a changed signature, a migration. That is a
/contractamendment and the repository owner's call, not something to fold into the answer here.