---
title: "Deletion preserves history and makes Memory erasure explicit"
version: "zh"
---

> Documentation Index
> Fetch the complete documentation index at: https://botharness.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Deletion preserves history and makes Memory erasure explicit

> Status: Accepted

# Deletion preserves history and makes Memory erasure explicit

Deleting a PersonaBot or Channel ends its active participation while preserving historical attribution; physical content erasure is an explicit additional scope. The Human confirmed an unchecked **Also delete Memory files** checkbox in PersonaBot deletion, with access to the actual Memory folder, and ordinary Channel deletion retaining history. This avoids making a familiar removal action silently erase learned continuity or shared messages, while still providing a deliberate erasure path. This is accepted target design for [#138](https://github.com/BotHarness/BotHarness/issues/138), not a claim that the deletion controls or Purge Ledger already exist.

## PersonaBot confirmation

The confirmation identifies the PersonaBot and its resolved Memory Repository, shows the dependency report, and offers **Open Memory folder** through the existing native Host file-opening path. A folder/application chooser may accompany the one-click action. Opening the folder does not select erasure or confirm deletion; remote-Web Humans are told that it opens on the Host. A missing path or unavailable native handler produces a visible explanation and never creates a substitute directory.

**Also delete Memory files** starts unchecked on every opening, including after cancellation. The final confirmation explicitly includes the checkbox selection and the reviewed repository identity; the Host rechecks that scope before execution. Changing the Bot, repository or relevant dependencies invalidates the confirmation. The selection is not a saved preference and must not be inferred from an earlier deletion.

Unchecked deletion retains all Soul/Memory files, including uncommitted changes and local Git history. Checked deletion removes the resolved, dedicated, exclusively owned managed Memory Repository, including its local Git metadata, only after closing execution and verifying ownership. The location can be outside the default layout; a custom path alone is not proof of exclusive ownership. Shared or overlapping repositories, symlink escapes, unrelated directories, unresolved paths or an inability to prove ownership make Memory erasure unavailable with an explanation; ordinary deletion can still retain that repository. Opening a folder grants no deletion authority.

The checkbox authorizes only the disclosed Memory Repository. It does not select Messaging Content Purge, Workspace deletion, removal of DSH Session history, Git-remote deletion, credential deletion, or external export/backup deletion. **Purge Everywhere** retains its separate dependency report and selected-derivative confirmation from ADR-0037.

## Lifecycle and dependency matrix

| Resource                                                       | Ordinary PersonaBot deletion                                                                                                  | Ordinary Channel deletion                                                              | Explicit erasure / limitation                                                                                                                                    |
| -------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Identity and attribution                                       | Retain a deleted-identity tombstone; remove active registration without reusing its ID                                        | Retain Channel identity and deletion tombstone                                         | Keep the minimum identity, causal and audit envelope; display-name reuse never inherits authority                                                                |
| Execution                                                      | Close new admissions, wakes, Session creation/resume and effects; stop the owned AgentHandle execution tree before completion | End membership, routing and new Channel work; do not stop unrelated Bot work           | A started model/provider request is not assumed cancelled; its native/Outbox outcome remains explainable                                                         |
| Session ownership and reports                                  | Retain historical ownership, Assignment Reports and lifecycle facts as read-only history                                      | Retain history and source navigation where available                                   | DSH Session Persistence remains the execution-log authority; copied prompts/results may survive local Content Purge and must be disclosed                        |
| Workspace/Tool/Browser/Computer authority                      | Revoke this identity's execution authority, scopes and saved approval applicability                                           | Revoke Channel-scoped authority only                                                   | Do not delete Workspace files or grant a same-name replacement Bot any inherited access                                                                          |
| Provider identities, grants and Triggers                       | Disable this Bot's bindings, grants and wake/ingress paths; retain attribution                                                | Disable only the deleted Channel's placements/routes and dependent paths               | Do not remove a shared provider account, another target route, or DSH credentials                                                                                |
| Source Events and Inbox/Outbox                                 | Retain message bodies, admissions and audit; prevent new delivery/effects for the deleted Bot                                 | Retain message bodies and historical references; disable new Channel admission/effects | Content Purge alone removes selected bodies; an in-flight Unknown Outcome is not silently retried or reported cancelled                                          |
| Soul/Memory                                                    | Retain by default, with a durable locator in deleted-identity history                                                         | Unchanged                                                                              | Checked Memory scope removes only the revalidated exclusive repository; failure is reported as incomplete, never as an atomic cross-file/database success        |
| Attachments                                                    | Retain referenced files                                                                                                       | Retain referenced files                                                                | Remove only selected exclusively referenced managed files; shared references retain bytes, and both legacy CAS and current real-file bindings must be considered |
| Local exports, Git remotes, manual backups and provider copies | Retain and disclose                                                                                                           | Retain and disclose                                                                    | Outside copies cannot be recalled; neither deletion nor local purge claims global erasure                                                                        |

A local group is ended locally. Deleting a bridged Channel closes only its local routes and Channel-scoped grants, not the external conversation or other authorized Channel/Inbox destinations. A Source Event shared across placements remains one content authority: a purge preview lists every affected placement, Admission and derivative; it cannot claim that removing a Channel placement erases its shared content. **Hidden Channel** remains reversible roster presentation and never enters this lifecycle.

Deletion is terminal for normal runtime controls: unarchive, restart, credential reappearance and late delivery cannot revive the deleted identity or Channel. Retained Memory may be inspected or explicitly imported into a fresh PersonaBot, which receives fresh identity and authorization. A supported identity-preserving Profile Restore follows ADR-0042–0044, starts cold and requires explicit activation; it is not an undelete shortcut or proof that the original holder stopped. Older standalone files remain limited to their captured state.

## Content Purge and the restore dependency

ADR-0037 already requires a monotonic **Purge Ledger** governed outside restorable database snapshots. The production owner must exist before [#886](https://github.com/BotHarness/BotHarness/issues/886) can claim complete Profile Backup and purge-safe restore. Design acceptance or a serialized empty placeholder does not satisfy that dependency.

The first purge slice is a real Channel path: dependency preview → separately confirmed Source Event scope → durable ledger acceptance → Messaging body removal and reference-aware file cleanup → retained tombstone → cold restart. The ledger retains selectors and minimum actor/time/reason/causal metadata, never the erased bodies. Its acceptance precedes content removal; an interruption cannot expose a selected body while cleanup is pending. Application is idempotent, and missing/corrupt/uncommittable required ledger state keeps Messaging unavailable with bounded diagnostics. Physical file cleanup failure is visible as incomplete cleanup rather than false success.

The owning purge command revalidates the reviewed scope and shared references, fences new reads/delivery/effects for accepted purge selectors, and serializes against the Backup Barrier. Post-commit Cordis notifications are refresh signals only. Duplicate ingress, provider reconciliation and stale readers must not recreate purged bodies or send an effect from an obsolete content revision; already issued requests retain their actual Outbox outcome rules.

Profile Backup includes the verified checkpoint and all retained managed Memory, including repositories belonging to deleted identities. Restore merges the package and destination ledgers monotonically, applies the union before Messaging becomes readable, and rejects invalid or unsupported checkpoints. A package cannot weaken destination purge facts. A new offline destination enforces only the package checkpoint; an old manual backup cannot know a later purge. No automatic backup catalog, pruning, retained-file deletion or online ledger requirement is introduced.

## Ownership and delivery

Deletion, the dependency report, Content Purge and the ledger are application-defined BotHarness capabilities owned by Host deep modules. The existing Typert/API Gateway seam carries Human commands; Client Slots compose the confirmation. Registry/lifecycle owns identity gates and tombstones, Messaging owns Source Events/Admissions/Outbox and purge application, Memory owns repository resolution and managed file cleanup, and Portability owns the checkpoint handoff and Backup Barrier. DSH owns AgentHandle execution and Session Persistence. Co-location does not authorize ad-hoc cross-module SQL or deleting native Session files.

The bounded follow-ups are: (1) PersonaBot deletion with the unchecked Memory choice and native folder action, lifecycle gates and durable historical locator; (2) one separately confirmed Channel Content Purge with the real ledger, restart/failure evidence and checkpoint/union contract; then (3) complete-core export/restore-as-new #886. Each runtime PR must provide real DSH UI evidence and wait for Human QA. Broad Purge Everywhere, additional provider recall, and Session-erasure support follow separately after a validated path; none is smuggled into #886.

## Considered Options

- **Always delete Memory with its PersonaBot** — rejected: deleting a contact would silently erase uncommitted knowledge and Git recovery history.
- **Require a separate page to select Memory erasure** — rejected: the Human chose a default-unchecked scope in the deletion confirmation, with direct folder inspection.
- **Erase messages when ending a Channel** — rejected: Channel lifecycle and destructive Source Event removal have different dependency and recovery consequences.
- **Treat existing Registry purge as the full contract** — rejected: deleting one directory and usage records does not implement shared-reference checks, Messaging purge, a ledger, or native Session erasure.
- **Export a placeholder purge checkpoint now** — rejected: a design document is not a production non-resurrection boundary.

Source: https://botharness.ai/zh/dev/adr/0130-deletion-preserves-history-and-makes-memory-erasure-explicit/index.mdx
