Skip to Content
Security & privacyDeletion, reversal and undo

Developer reference

Deletion, correction and undo

Offer the action that matches intent and preserve linked financial history when removal is unsafe.

Removing an unused setup record, correcting money, reversing a movement, undoing an import and deleting an entire user account are different operations.

Choose by intent

IntentAppropriate boundary
Change a label or unused setupOwned setup editing or eligible deletion.
Fix recorded moneyDated correction with an explanation.
Reverse a movementExplicit reversal with its domain constraints.
Remove imported workEligible unchanged units within the specific import job.
Remove all personal dataFollow the installation’s supported request process; one-click self-service deletion is planned.

Respect a refusal

The server can refuse deletion when linked records or financial state make removal unsafe. Import undo does not erase unrelated or subsequently changed history.

Read the explanation, inspect the linked records and choose a correction or other supported action. Do not bypass the refusal with a direct database deletion.

Recover uncertain actions

Retain the original operation identity and inspect the existing result before submitting again. A timeout is not evidence that no destructive effect occurred.

Public capability boundary

Complete-history export and self-service account deletion remain planned. Do not invent an available button or imply token revocation removes stored financial records.

Use movement guidance, import recovery and idempotency for specific next steps.