Developer reference
Deletion, correction and undo
Offer the action that matches intent and preserve linked financial history when removal is unsafe.
Removing an unused setup record, correcting money, reversing a movement, undoing an import and deleting an entire user account are different operations.
Choose by intent
| Intent | Appropriate boundary |
|---|---|
| Change a label or unused setup | Owned setup editing or eligible deletion. |
| Fix recorded money | Dated correction with an explanation. |
| Reverse a movement | Explicit reversal with its domain constraints. |
| Remove imported work | Eligible unchanged units within the specific import job. |
| Remove all personal data | Follow the installation’s supported request process; one-click self-service deletion is planned. |
Respect a refusal
The server can refuse deletion when linked records or financial state make removal unsafe. Import undo does not erase unrelated or subsequently changed history.
Read the explanation, inspect the linked records and choose a correction or other supported action. Do not bypass the refusal with a direct database deletion.
Recover uncertain actions
Retain the original operation identity and inspect the existing result before submitting again. A timeout is not evidence that no destructive effect occurred.
Public capability boundary
Complete-history export and self-service account deletion remain planned. Do not invent an available button or imply token revocation removes stored financial records.
Use movement guidance, import recovery and idempotency for specific next steps.