Legal holds
client.holds, the Holds namespace, lets the Owner role stop deletes. It is the one delete-related action an Owner takes directly. A hold stops a delete or a shred over what it covers:
- a whole
dataset - one key domain
- a single record
A hold does not change who may open what it covers. Lifting a hold takes two Owners. The hold stays in place until the second Owner signs.
The calls
The samples use the allowed helper from Access decisions.
const holds = await client.holds.list();// [{ holdId, target, reason, reference, placedAt, placedBy, liftSignatures }, ...]
await allowed(await client.holds.place({ dataset: 'imaging' }, 'Audit', 'AUD-2026-03'));await allowed(await client.holds.place({ domain: root }, 'Litigation', 'LIT-2026-04'));await allowed(await client.holds.place({ record: locator }, 'Subject access dispute', 'SAR-2026-11'));
const lift = await allowed(await client.holds.lift(holds[0].holdId));if (lift?.lifted) tell('The second Owner has signed; the hold is lifted');let holds = try await client.holds.list()
_ = try await allowed(client.holds.place(.dataset("imaging"), reason: "Audit", reference: "AUD-2026-03"))_ = try await allowed(client.holds.place(.domain(root), reason: "Litigation", reference: "LIT-2026-04"))_ = try await allowed(client.holds.place(.record(locator), reason: "Subject access dispute", reference: "SAR-2026-11"))
let lifted = try await allowed(client.holds.lift(holds[0].holdId))if lifted == true { tell("The second Owner has signed; the hold is lifted") }val holds = client.holds.list()
allowed(client.holds.place(HoldTarget.Dataset("imaging"), "Audit", "AUD-2026-03"))allowed(client.holds.place(HoldTarget.Domain(root), "Litigation", "LIT-2026-04"))allowed(client.holds.place(HoldTarget.Record(locator), "Subject access dispute", "SAR-2026-11"))
val lifted = allowed(client.holds.lift(holds[0].holdId))if (lifted == true) tell("The second Owner has signed; the hold is lifted")Each Hold carries:
targetreasonandreference: the free-text reason and case reference the Owner gave itplacedAtandplacedByliftSignatures: how many of the two required Owner signatures exist so far
What the SDK does for you
- Signs
liftafter a fresh multi-factor sign-in and counts it towardliftSignatures. Frees the hold only after a second, different Owner also signs. - Turns any delete or shred that a hold covers into a
deny, rather than letting it fail partway. - Raises a
hold-liftitem in the worklist once the first Owner signs. A second Owner sees it waiting.
Decisions and errors you may see
Outcome or ErrorCode | When | What to do |
|---|---|---|
deny on place or lift | The caller does not hold the Owner role. | Ask an Owner to place or lift the hold. |
held (a DenyReason) | Someone tried to delete or shred something under an active hold. | Lift the hold first, or wait for the case it covers to close. |
deny on lift | The same Owner who placed or already signed tries to sign again. | Ask a different Owner to provide the second signature. |