KCAE.CHANGE:4.5 - Handle deletion and permission change explicitly
Source deletion can mean removal from current membership, withdrawal of a claim, retention expiry or access revocation. Obtain that meaning from the source policy. Keep authorized historical material only when retention permits it. Purge or quarantine prohibited copies in indexes, caches, summaries, logs and memory according to that policy; removing one search row is not a complete deletion procedure.
Where a provider removes index entries eventually, enforce current membership and permission at result release and source opening as well as at query filtering. A stale candidate identifier must not expose withdrawn content. Overfetching and post-filtering can change recall and latency; measure that cost. Rechecking permission still leaves a time-of-check/time-of-use question. Use the source service’s enforcement at the actual read or action when immediate revocation matters, and state any remaining race rather than claiming universal instantaneous revocation.
A permission cache has its own allowed age. Source-generation pinning must not freeze permission to an obsolete grant. If source content may be retained historically but a particular reader loses access, the generation remains a historical object while that reader’s operation is denied.