AgentEnv data controls
server/src/modules/agentenv/export/dataControls.ts.This doc publishes the retention, deletion, ownership, and export control for every durable AgentEnv artifact class. There are 13 classes. Ownership is the workspace tenancy boundary proven on PostgreSQL by AER-R6-A: a cross-tenant read/mutation is an opaque not-found. Deletion is reversible (every table ships a down-migration) and, for workspace-columned tables, per-tenant. Customer data ownership is exercised by the trajectory export, which delivers the exact JSONL bytes to the customer's own storage through the platform SSRF/egress policy (safeEgressFetch); Gessa keeps only an audit-ready delivery receipt. Provider secrets in the credential vault are NEVER exported (only the AES-256-GCM envelope is stored, and the plaintext is never persisted).
Artifact classes
| Artifact class | Storage | Ownership | Retention | Deletion | Export |
|---|---|---|---|---|---|
credential_vault | agentenv_credential_vault | workspace_scoped | Held until revoked (AER-R6-B) or rotated; the plaintext secret is never persisted (only the AES-256-GCM envelope). | Revocation (fail-closed resolve) then per-workspace erasure (workspace_id column); reversible via 0406_agentenv_credential_vault.down.sql. | never_secret |
human_baseline_consent_event | agentenv_human_baseline_consent_events | workspace_scoped | Consent audit trail; DORMANT per RD-10 - no active writer. | Reversible via 0262 down-migration; retained as consent evidence while its session exists. | not_exported |
human_baseline_session | agentenv_human_baseline_sessions | workspace_scoped | Consent-gated; DORMANT per RD-10 (human baseline deferred) - no active writer. | Reversible via 0262_agentenv_human_baselines.down.sql; consent withdrawal erases the session. | not_exported |
manifest | agentenv_manifests | global_immutable_content | Immutable published environment artifact; retained while any run references it. | Reversible via 0390_agentenv_manifest_artifacts.down.sql; not per-tenant (global content). | not_exported |
observation_trace | agentenv_protocol_observation_traces | workspace_scoped | Append-only evaluation evidence retained for the run's lifecycle. | Reversible via 0391_agentenv_observation_traces.down.sql; erased with its run. | trajectory_jsonl |
pack | agentenv_packs | global_immutable_content | Immutable published pack artifact; retained while any manifest references it. | Reversible via 0390 down-migration; not per-tenant (global content). | not_exported |
protocol_action_authority_binding | agentenv_protocol_action_authority_bindings | workspace_scoped | Bounded to the episode's runtime authority window. | Reversible via 0389 down-migration; erased with its run/episode. | not_exported |
protocol_episode | agentenv_protocol_episodes | workspace_scoped | Inherits the owning run's retention (child of the run aggregate). | Reversible via 0389 down-migration; erased with its run. | trajectory_jsonl |
protocol_execution_idempotency | agentenv_protocol_execution_idempotency | workspace_scoped | Operational execution de-duplication ledger. | Reversible via 0389 down-migration; erased with the tenant. | not_exported |
protocol_idempotency | agentenv_protocol_idempotency | workspace_scoped | Operational de-duplication ledger; retained only as long as replay protection is meaningful. | Reversible via 0389 down-migration; per-actor rows erased with the tenant. | not_exported |
protocol_run | agentenv_protocol_runs | workspace_scoped | Durable for the run's evaluation lifecycle; bounded operational retention thereafter. | Reversible via 0389_agentenv_protocol_repository.down.sql; per-workspace erasure by workspaceId (record->>'workspaceId', indexed). | trajectory_jsonl |
reward_trace | agentenv_protocol_reward_traces | workspace_scoped | Append-only evaluation evidence retained for the run's lifecycle. | Reversible via 0389 down-migration; erased with its run. | trajectory_jsonl |
trajectory_export | customer storage (egress) | customer_storage | Customer-controlled: the exact JSONL bytes are delivered to the customer's own storage; Gessa retains only an audit-ready delivery receipt (exportId, contentHash, byteCount), never a second copy of the bytes. | Customer-controlled in their storage; the delivery is idempotent and SSRF-bounded (safeEgressFetch). | trajectory_jsonl |