Independently decide a hold release or disposition, rechecking current retention and holds atomically
/customers/{id}/record-controls/{action}/decisionsFresh customers:records:approve staff authority, no API key and actor different from maker required. Hold release/disposition/retention event are serialized with capture, other controls and schedule changes. Disposition rechecks every current hold, captured retention and current policy; permanent or unknown-trigger retention blocks it. Only the encrypted live archive payload is deleted atomically with immutable approval evidence. Customer-master, financial histories, external documents and backup/WAL/object-lock copies are outside this deletion boundary. A disposed record cannot be recreated by idempotent replay or key rotation.
Path parameters
idstringRequiredactionstringRequiredHeaders
Idempotency-KeystringRequiredSend on every write that creates or changes money or state; a replay with the same key returns the original result with 200.
Body parameters
decisionstringRequiredApprove/reject
evidence_refstringRequiredevidence_sha256stringRequiredreasonstringRequiredReturns
200 OK
customer_idstringRequiredExample cust_2tVh8nqLxq4GbDe0K1F6S9zRcWm
decided_atstring · date-time or nullOptionaldecided_bystringOptionalidstringRequiredproposed_atstring · date-timeRequiredproposed_bystringRequiredrequestobjectRequired8 child attributes
event_atstring · date-time or nullOptionalIndependently evidenced trigger, e.g. relationship closure
evidence_refstringRequiredevidence_sha256stringRequiredhold_idstringOptionalRelease_hold only
Example hold_2tVh8nqLxq4GbDe0K1F6S9zRcWm
kindstringRequiredHold, release_hold, dispose, retention_event
matter_refstringRequiredreasonstringRequiredrecord_idstringOptionalEmpty hold covers all current/future customer records
statusstringRequiredErrors
Every error is a problem document with a stable code. See Errors.
400401403404409412413422424429500503