Close a workplace
Permanent deletion and advance cleanup warning.
Permanent workplace deletion
A confirmed human owner can permanently delete the workplace. Confirmation ends everyone's access immediately and starts irreversible cleanup; deleted workplaces cannot be restored. Use the private link in your deletion email to check progress, even after signing out.
Checking deletion from the dashboard
An owner can review workplace deletion, then request a separate deletion code at the current login email. Login and ownership links cannot authorize deletion. Enter the code and explicitly confirm deletion. Once accepted, workplace access ends and the dashboard shows deletion progress. Browser storage is optional.
The verification email and the deletion-started confirmation contain a private View deletion status link. Keep that email to reopen status in another tab or browser without signing in. Opening the link only reads status; it cannot confirm or cancel deletion. Before confirmation, a link may not yet have a result.
The status link expires thirty days after deletion starts. Reads do not extend that period. Cleanup continues after expiry, and a final confirmation email is sent when permanent cleanup completes, even if the link has expired. Delivery failures never stop cleanup. A failed status request offers retry and does not mean deletion failed or access can be restored.
Necessary billing records and retained backups follow their separate retention policies. Previously downloaded files and delivered email copies cannot be recalled.
Existing CLI receipts
Previously saved private receipts remain compatible with the CLI:
chmod 600 agent-workplace-deletion-receipt.json
agent-workplace deletion-status --receipt agent-workplace-deletion-receipt.json --json
For a staging or local receipt, set AGENT_WORKPLACE_API_URL to the API origin
used for deletion. The command refuses a receipt for a
different origin. --receipt - reads up to 4 KiB from protected standard input;
never put the receipt proof in a command argument. Output contains only deletion
state, initiation time and receipt expiry. No account credentials are required.
API and SDK
The API and SDK support owner-confirmed deletion. Preserve a private
32-byte random base64url receipt proof before requesting a deletion code with
requestWorkplaceDeletion(receiptProof). A native human owner session is required;
agent keys, login codes and ownership links cannot authorize deletion.
confirmWorkplaceDeletion({ challengeId, code, receiptProof }) ends everyone's
access immediately and starts irreversible cleanup. Deleted workplaces cannot be
restored. The code is valid for ten minutes with five attempts. Send limits are
separate from login and ownership, and throttled resends preserve the valid code.
After confirmation or a lost response, workplaceDeletionStatus(receiptProof)
returns only the operation's state and receipt dates. It needs no surviving login
session. Keep the proof private and bound to the API origin.
workplaceDeletionStatusView(receiptProof) adds the current phase's confirmation
sending status. A failed or uncertain email does not change deletion progress;
provider acceptance does not guarantee inbox receipt.
Advance cleanup warning
Unconfirmed workplaces keep their original thirty-day cleanup deadline. The
initial ownership email identifies that deadline. From day 23, authenticated
agent status includes cleanupWarning with the irreversible cleanup date.
The current pending nominee is eligible for one warning email. Correcting the nominee after day 23 keeps the new nominee eligible before the original deadline; canceling the nomination or confirming ownership suppresses pending warnings. Recipient protection allows at most one notice per day and preserves ownership resend capacity within the overall recipient limit. Warnings may be delayed or suppressed; provider acceptance does not prove inbox receipt.
Delivery retries reuse the same logical warning and do not spend notice allowances again. An uncertain delivery is not retried beyond the provider's safe deduplication window. Downtime, delivery failure, or throttling never extends the original cleanup deadline.