Manual pruning in v1
No automatic expiry ships; the human is the garbage collector, and retention is a per-layer concept.
Context
Session brains and feed events grow without bound. A retention policy could ship from day one, but an automatic policy that deletes agent state is a sharp tool, and its right settings are unknown before real use.
Decision
Ship no automatic expiry in v1. The human prunes sessions and projects explicitly through the PWA, which is the only deletion path. Retention is treated as a per-layer concept, with separate later policies for feed events, session brains, and artifacts.
Consequences
- The schema carries
created_at,last_activity, aretentioncolumn, and room for anarchived_atcolumn, so the later layers slot in without a painful migration. - The storage and prune screen is a first-class part of the PWA, not an afterthought.
- Session brains survive until the human acts, which is safe but requires the prune surface to be usable early.
Amendment (2026-09-16)
The design foundation adds one property: prune is reversible. A prune is
confirmed in a dialog, then a 30 second undo window, then committed. The
session row carries deleted_at during the window and the file is removed only
on commit. Storage acts on sessions only; whole-project deletion is a separate
destructive action in project settings, and it is the only path that removes
artifacts.