# Archive policy

**Version 1. Dated 2026-09-09.**

This document is fixed. It is never edited. If it is found to be wrong, a new
version is written as a new document.

This is a specification. It states what may be done to the case archive, and
when.

---

## 1. The archive was cleared once

On **2026-09-09** the case archive was cleared. Five files were deleted:

| bytes | file |
|---|---|
| 14,762 | `brent-2026-08-31-live-4b00be9-dirty-d0133d91c37e83d3.json` |
| 14,698 | `brent-2026-08-31-live-0ed0022-dirty-d0133d91c37e83d3.json` |
| 183,560 | `brent-2026-08-31-live-0ed0022-dirty-d0133d91c37e83d3.inputs.json` |
| 3,492 | `brent-2026-08-31-live-0ed0022-dirty-...@2026-09-09.drift.json` |
| 1,931 | `calibration.json` |

Both cases were produced while the machinery that writes them was being built.
Neither was published. Neither was signed. Neither was relied on by anything.
No public repository existed at the time of the clearing.

The clearing was a normal deletion commit. Git history was not rewritten,
nothing was force-pushed and nothing was amended. The commits that introduced
those files stand, and every deleted file can still be recovered from history.
That these cases existed, and that they were removed deliberately and when, is
itself part of the record.

---

## 2. From the first case issued after this date, the archive is append-only

> **Nothing in `archive/cases/` is ever deleted, edited, or rewritten.**

This applies to case files, frozen inputs, drift observations, scores,
deferral logs and score revisions alike.

`archive/calibration.json` is the single exception and is not a record: it is a
view, rebuilt in full from the cases and scores on every run, holding nothing
they do not. Overwriting it restates what they already say.

---

## 3. A wrong case is corrected by issuing the next one

A case that turns out to be wrong — wrong inputs, wrong configuration, a defect
in the model — is **not removed and not amended**.

It is corrected by issuing the next case, which carries its own inputs, its own
timestamp and its own note stating what was wrong with the earlier one. The
earlier case stays exactly as issued.

A record that can be edited proves nothing, whether or not it ever is. The
value of the archive is that what was said before an outcome was known cannot
be changed after it.

---

## 4. Clearing is not available again

Section 1 records a one-time act, performed before any case had been published,
under conditions that no longer hold and cannot recur: there was no published
record to protect, because there was no record.

From the first case issued after 2026-09-09 there is one, and section 2 governs
it without exception. A future clearing would not be a housekeeping decision;
it would be the destruction of the thing the archive exists to be.

---

## 5. What enforces this

Nothing in this repository deletes from `archive/`. There is no delete
function, no cleanup routine, no retention policy and no expiry.
`tests/test_archive_policy.py` asserts it by scanning the source.

That is a guard, not a guarantee. A person with a shell can delete any file.
What makes the archive append-only in practice is that it is committed to git:
a deletion is itself a commit, visible in the history, and the deleted content
remains recoverable from it. The policy is enforced by the record of breaking
it being permanent.
