Manual pruning in v1

No automatic expiry ships; the human is the garbage collector, and retention is a per-layer concept.

Context

Session brains and feed events grow without bound. A retention policy could ship from day one, but an automatic policy that deletes agent state is a sharp tool, and its right settings are unknown before real use.

Decision

Ship no automatic expiry in v1. The human prunes sessions and projects explicitly through the PWA, which is the only deletion path. Retention is treated as a per-layer concept, with separate later policies for feed events, session brains, and artifacts.

Consequences

  • The schema carries created_at, last_activity, a retention column, and room for an archived_at column, so the later layers slot in without a painful migration.
  • The storage and prune screen is a first-class part of the PWA, not an afterthought.
  • Session brains survive until the human acts, which is safe but requires the prune surface to be usable early.

Amendment (2026-09-16)

The design foundation adds one property: prune is reversible. A prune is confirmed in a dialog, then a 30 second undo window, then committed. The session row carries deleted_at during the window and the file is removed only on commit. Storage acts on sessions only; whole-project deletion is a separate destructive action in project settings, and it is the only path that removes artifacts.