Delete and restore
Deleting anything takes two decisions. The first retires it into the recycle bin, where it stays fully recoverable. The second, shred, destroys it for good. Break-glass recovery cannot reverse a shred. Only a domain owner can retire or shred. The SDK refuses both while a legal hold or the dataset’s retention floor applies.
Retire a version, an object or a key domain
objects.delete retires either one version or, when no version is named, every version of an object. domains.delete retires a whole key domain.
The samples use the allowed helper from Access decisions.
await allowed(await client.objects.delete({ locator, version: 4 })); // one versionawait allowed(await client.objects.delete({ locator })); // every versionawait allowed(await client.domains.delete(root));try await allowed(client.objects.delete(ObjectRef(locator: locator, version: 4)))try await allowed(client.objects.delete(ObjectRef(locator: locator)))try await allowed(client.domains.delete(root))allowed(client.objects.delete(ObjectRef(locator, version = 4)))allowed(client.objects.delete(ObjectRef(locator)))allowed(client.domains.delete(root))List, restore or shred the recycle bin
recycleBin lists the retired versions, objects and key domains that a key domain’s domain owners can see. Each RecycleBinItem carries:
kind:version,objectordomainlocatorversion, for a retired versionretiredAtandretiredByheld: true while a legal hold keeps the item in the bin, whatever a domain owner decides
const bin = await client.domains.recycleBin(root);await allowed(await client.domains.restore(bin[0]));await allowed(await client.domains.shred(bin.filter((item) => !item.held)));let bin = try await client.domains.recycleBin(root)try await allowed(client.domains.restore(bin[0]))try await allowed(client.domains.shred(bin.filter { !$0.held }))val bin = client.domains.recycleBin(root)allowed(client.domains.restore(bin[0]))allowed(client.domains.shred(bin.filter { !it.held }))restore reverses a retire. The entry is live again in the folder index. shred is final. The Seald Healthcare Cloud destroys the object’s key material, then the object itself. Nothing brings it back, including break-glass recovery. Only the tombstone remains. It keeps the locator, the version and their access events for the audit trail.
What the SDK does for you
- Rewrites the folder index to mark an entry retired or restored. A retire leaves the object itself untouched.
- Refuses
objects.delete,domains.deleteandshredoutright while a legal hold applies. - Destroys the object’s key material before the object itself. A shred never leaves an object half-destroyed and still readable.
- Records one Delete access event for a retire or a shred.
- Records one Restore access event for a restore.
Decisions and errors you may see
Outcome or ErrorCode | When | What to do |
|---|---|---|
held | A legal hold covers the target. | Wait for the hold to lift, or see legal holds. |
retention | The dataset’s retention floor still applies. | Wait until the floor passes, or ask an Owner to confirm the floor. |
deleted | The target was already shredded. | Nothing to do. The tombstone is all that remains. |
deny (other) | The caller is not a domain owner. | Only a domain owner may retire, restore or shred. |
Next
- Legal holds for placing and lifting a hold.
- Owners and sub-domains for who counts as a domain owner.
- Datasets on S3 for what shredding does to the underlying storage.
- Evidence and audit for what a tombstone still proves.