Skip to content

Close a workplace

Permanent deletion and advance cleanup warning.

Permanent workplace deletion

A confirmed human owner can permanently delete the workplace. Confirmation ends everyone's access immediately and starts irreversible cleanup; deleted workplaces cannot be restored. Use the private link in your deletion email to check progress, even after signing out.

Checking deletion from the dashboard

An owner can review workplace deletion, then request a separate deletion code at the current login email. Login and ownership links cannot authorize deletion. Enter the code and explicitly confirm deletion. Once accepted, workplace access ends and the dashboard shows deletion progress. Browser storage is optional.

The verification email and the deletion-started confirmation contain a private View deletion status link. Keep that email to reopen status in another tab or browser without signing in. Opening the link only reads status; it cannot confirm or cancel deletion. Before confirmation, a link may not yet have a result.

The status link expires thirty days after deletion starts. Reads do not extend that period. Cleanup continues after expiry, and a final confirmation email is sent when permanent cleanup completes, even if the link has expired. Delivery failures never stop cleanup. A failed status request offers retry and does not mean deletion failed or access can be restored.

Necessary billing records and retained backups follow their separate retention policies. Previously downloaded files and delivered email copies cannot be recalled.

Existing CLI receipts

Previously saved private receipts remain compatible with the CLI:

chmod 600 agent-workplace-deletion-receipt.json
agent-workplace deletion-status --receipt agent-workplace-deletion-receipt.json --json

For a staging or local receipt, set AGENT_WORKPLACE_API_URL to the API origin used for deletion. The command refuses a receipt for a different origin. --receipt - reads up to 4 KiB from protected standard input; never put the receipt proof in a command argument. Output contains only deletion state, initiation time and receipt expiry. No account credentials are required.

API and SDK

The API and SDK support owner-confirmed deletion. Preserve a private 32-byte random base64url receipt proof before requesting a deletion code with requestWorkplaceDeletion(receiptProof). A native human owner session is required; agent keys, login codes and ownership links cannot authorize deletion.

confirmWorkplaceDeletion({ challengeId, code, receiptProof }) ends everyone's access immediately and starts irreversible cleanup. Deleted workplaces cannot be restored. The code is valid for ten minutes with five attempts. Send limits are separate from login and ownership, and throttled resends preserve the valid code.

After confirmation or a lost response, workplaceDeletionStatus(receiptProof) returns only the operation's state and receipt dates. It needs no surviving login session. Keep the proof private and bound to the API origin. workplaceDeletionStatusView(receiptProof) adds the current phase's confirmation sending status. A failed or uncertain email does not change deletion progress; provider acceptance does not guarantee inbox receipt.

Advance cleanup warning

Unconfirmed workplaces keep their original thirty-day cleanup deadline. The initial ownership email identifies that deadline. From day 23, authenticated agent status includes cleanupWarning with the irreversible cleanup date.

The current pending nominee is eligible for one warning email. Correcting the nominee after day 23 keeps the new nominee eligible before the original deadline; canceling the nomination or confirming ownership suppresses pending warnings. Recipient protection allows at most one notice per day and preserves ownership resend capacity within the overall recipient limit. Warnings may be delayed or suppressed; provider acceptance does not prove inbox receipt.

Delivery retries reuse the same logical warning and do not spend notice allowances again. An uncertain delivery is not retried beyond the provider's safe deduplication window. Downtime, delivery failure, or throttling never extends the original cleanup deadline.

On this page