DESTRUCTIVE ACTION REVIEW
Delete Events
Review deletion, deactivation, archival, restoration, and destructive-action evidence.
Audit records may contain workforce identities, Provider identifiers, Individual references, IP addresses, device details, routes, request metadata, support-session identifiers, and before-and-after values. Screenshots in this public guide use redacted or demonstration information. Production access must remain Provider-scoped, role-based, purpose-limited, and restricted to authorized personnel.
True Care System records audit evidence to support accountability, privacy review, security investigation, operational integrity, and Provider governance. These capabilities support—but do not replace—the Provider's policies, workforce training, risk analysis, legal obligations, incident response, and retention program.
Purpose
Delete events are high-value audit records because they may remove or hide operational, clinical, financial, or administrative information. Authorized reviewers should distinguish between soft deletion, deactivation, archival, restoration, and permanent deletion.
Deletion Models
| Field | Function |
|---|---|
| Soft delete | Marks a record as deleted while preserving it for recovery or audit. |
| Deactivate | Prevents future use without removing historical evidence. |
| Archive | Moves a record out of active workflows while preserving retention. |
| Restore | Returns a previously deleted or archived record to active status. |
| Permanent delete | Irreversibly removes data and should be tightly restricted and policy-controlled. |
Required Review
- Confirm the role and authority of the actor.
- Identify the deleted entity and related downstream records.
- Review reason, approval, ticket, or support-session context.
- Determine whether retention or legal-hold requirements apply.
- Escalate unexpected or unauthorized destructive actions immediately.
