Skip to content

Delete and restore

Deleting anything takes two decisions. The first retires it into the recycle bin, where it stays fully recoverable. The second, shred, destroys it for good. Break-glass recovery cannot reverse a shred. Only a domain owner can retire or shred. The SDK refuses both while a legal hold or the dataset’s retention floor applies.

Retire a version, an object or a key domain

objects.delete retires either one version or, when no version is named, every version of an object. domains.delete retires a whole key domain.

The samples use the allowed helper from Access decisions.

await allowed(await client.objects.delete({ locator, version: 4 })); // one version
await allowed(await client.objects.delete({ locator })); // every version
await allowed(await client.domains.delete(root));

List, restore or shred the recycle bin

recycleBin lists the retired versions, objects and key domains that a key domain’s domain owners can see. Each RecycleBinItem carries:

  • kind: version, object or domain
  • locator
  • version, for a retired version
  • retiredAt and retiredBy
  • held: true while a legal hold keeps the item in the bin, whatever a domain owner decides
const bin = await client.domains.recycleBin(root);
await allowed(await client.domains.restore(bin[0]));
await allowed(await client.domains.shred(bin.filter((item) => !item.held)));

restore reverses a retire. The entry is live again in the folder index. shred is final. The Seald Healthcare Cloud destroys the object’s key material, then the object itself. Nothing brings it back, including break-glass recovery. Only the tombstone remains. It keeps the locator, the version and their access events for the audit trail.

What the SDK does for you

  • Rewrites the folder index to mark an entry retired or restored. A retire leaves the object itself untouched.
  • Refuses objects.delete, domains.delete and shred outright while a legal hold applies.
  • Destroys the object’s key material before the object itself. A shred never leaves an object half-destroyed and still readable.
  • Records one Delete access event for a retire or a shred.
  • Records one Restore access event for a restore.

Decisions and errors you may see

Outcome or ErrorCodeWhenWhat to do
heldA legal hold covers the target.Wait for the hold to lift, or see legal holds.
retentionThe dataset’s retention floor still applies.Wait until the floor passes, or ask an Owner to confirm the floor.
deletedThe target was already shredded.Nothing to do. The tombstone is all that remains.
deny (other)The caller is not a domain owner.Only a domain owner may retire, restore or shred.

Next