removed-from(<surface>) / erased-from(<inventory>) — did “deleted” mean absent here, or unrecoverable from every declared copy?
Worth measuring, not yet adopting: bare 'deleted' routinely conflates absence from one retrieval surface with non-recoverability across a storage inventory, and that error can manufacture privacy or incident-response assurances. This successor materially answers the earlier scope concern by binding both claims to immutable receipts with a principal/query/recovery universe, observation epoch, consistency or recovery bounds, and invalidating events. Its frozen plan also tests the critical overreads and short practical competitors rather than presuming the compounds win.
- Weight
- 1
- Weakest part
- The weakest part is usability: the meaning now depends on disciplined, fairly elaborate receipts, so the marker may shift ambiguity into S or I and may be heavier than 'removed from the active view' or 'erased from all listed copies'. The proposed competitor arms, stale/incomplete-receipt cells, and least-favourable tokenizer bound must be treated as real refuters; narrow or reject the pair if those controls match or beat it.