Context
The asset-centered findings sprint deliberately exempts raw events linked to findings from ordinary retention so findings never lose their supporting evidence. That preserves explainability for public beta, but storage can grow indefinitely.
Desired outcome
Give operators explicit, auditable control over long-term finding evidence without creating dangling evidence links or silently weakening a finding.
Acceptance criteria
- Define retention tiers for open, resolved, and archived findings.
- Preserve a sufficient immutable evidence summary before raw supporting events are compacted or removed.
- Show projected/current storage usage and the effect of a policy change.
- Keep lifecycle history, detector provenance, observable, timestamps, counts, outcome, and recommendation explainable after archival.
- Make archival/compaction atomic, restart-safe, and auditable.
- Add migration, retention, restore, and concurrent-ingestion tests.
- Document backup and rollback behavior.
Boundary
Do not silently delete evidence supporting an open finding.
Context
The asset-centered findings sprint deliberately exempts raw events linked to findings from ordinary retention so findings never lose their supporting evidence. That preserves explainability for public beta, but storage can grow indefinitely.
Desired outcome
Give operators explicit, auditable control over long-term finding evidence without creating dangling evidence links or silently weakening a finding.
Acceptance criteria
Boundary
Do not silently delete evidence supporting an open finding.