Data & administration
Maintenance
A periodic hygiene sweep keeps the workspace accurate: what's stale, what needs your decision, what's genuinely urgent. Say “run a maintenance sweep” — roughly monthly, or before a release.
With the SQUAT plugin, use /maintain for hygiene, audit, backup, trash, retention, artifact, and protection checks. Use /review for ledger and saved-report reads, and /concierge for imports, deletion requests, recovery, or a multi-step job. /start helps choose the workspace or project. In a client without slash skills, ask for the same job in plain language or choose the matching MCP prompt if it is shown. The client presents the scope and asks for confirmation before a change.
Workspace maintenance
This section is for the person who operates a SQUAT workspace through an AI client. You can ask for these checks in plain language; you do not need to run shell commands or configure the hosted service. System administrators handle deployment schedules and service credentials separately. Keep requests scoped to a project when that is what you are reviewing.
| Operator task | What to ask for | What happens and how to check it |
|---|---|---|
| Run a hygiene sweep | “Run a maintenance sweep for this workspace” (or name a project) | SQUAT reviews stale squad members and scenarios, harness notes, invalidated rounds, the issues queue, browser-login readiness, trash, and backup posture. It reports candidates and recommendations; it does not retire, delete, or purge anything without your confirmation. |
| Check current state | “Show the project status and ledger” or “What is open?” | The project status view separates scored UAT from qualitative panels and reports whether the open-round list is complete. If it says more rounds exist, ask for the next page before treating the list as a full inventory. For an open panel, the progress view tells you the next safe action. |
| Check integrity | “Run an integrity check” | This is a report-only check. It can identify references to missing or trashed records and broken stored-object pointers. For newly created event-ledger rounds it also verifies the immutable chain and the revealed semantic commitment for every content-bearing turn. It does not change data. Review each finding before deciding what to repair or invalidate. |
| Back up the workspace | “Create a portable export” or “Create a full backup before purge” | A portable export is a readable current-state copy. A full backup is the recovery record for deletion work and includes protected history, reports, trash, and project artifacts. Wait for a complete manifest and store the resulting copy somewhere separate from the hosted workspace. Credentials, keys, licenses, audit rows, and sign-in state are excluded. |
| Review or restore trash | “List the trash”, “Restore round …”, or “Prepare a purge” | Soft-deleted rounds remain recoverable for 30 days. An irreversible purge is a separate prepare → human type-back → run/status ceremony. If it stops part-way through, resume the same operation; do not prepare a replacement. A completion certificate records the result. |
| Remove saved analysis | “Remove these Round Summaries/Research Reports/UAT Reports” | SQUAT prepares a reviewable, resumable deletion for the selected report or summary versions and their supporting stored files. Source rounds and artifact sets remain. A summary cited by a report must be selected with that report so the saved research stays coherent. |
| Manage project artifacts | “List the artifacts for this project”, then rename, update retention, or delete an item | The artifact library is the durable source for files used in later rounds and reports. Rename and retention changes preserve immutable versions. Deletion is refused while a round or report still references the item. Bytes stay in protected object storage rather than in the ledger document. |
| Review retention | “Show due retention” | Expiry metadata is only a policy until an owner activates retention for the artifact set. The scheduled service performs due work; you can review its status and any blocked items from the workspace tools. Occasionally an item cannot be deleted right now; SQUAT support can tell you why and when it will be free. |
| Review action history | “Show the workspace audit history for this action” | Owners and admins can review who performed an important action, when, through which client/tool, and whether it succeeded. The audit view records metadata for accountability; it does not reproduce transcript or artifact content. |
Maintenance asks are workspace operations. You should not need to administer the hosted service. If a scheduled retention run is unavailable, preserve your work and ask the deployment operator to check the service; do not try to recreate it from the client.
How to monitor a maintenance action
Confirm the scope. Check the project name, round/report/artifact names, and the displayed counts before approving a mutation.
Watch the operation state. Deletion requests move through inventory, authorization, execution, and completion states; they can also be blocked, failed, or partial. Purges use their own prepared, authorized, running, partial, and complete states. A partial operation is recoverable only by resuming its original operation ID.
Check the receipt. Look for the stable completion certificate or completed export manifest. Keep the ID with your project notes if you need to discuss the action with support.
Run a follow-up read. Recheck the project status, trash, artifact library, or report library that the action affected. A read-only integrity check is useful after deletion or recovery work.
For imports and local recovery, use Importing & content packs and review the package before sending it to the hosted workspace. Historical rounds are written atomically only after their personas and scenarios resolve; SQUAT will report missing mappings rather than inventing them.
When to run it
Run maintenance after a release, when the squad has grown past a handful of members, when you find yourself asking “what's stale?”, or roughly monthly for an active workspace. Recruiting, rounds, and reviews remain available, and nothing in the sweep acts without your confirmation.
What the sweep checks
Stale squad members. Active personas cross-referenced against recent round activity. A member who has not run in a meaningful stretch (your call what that means for your cadence) is a candidate for retirement, not a verdict. Lack of recent activity alone does not establish that the persona is no longer useful, and nothing is retired without your approval.
Persona depth & squad coverage. Every active persona is graded for persona-specific claims, motivations, conditional patterns, tensions, knowledge limits, and non-caricatured communication range. Synthetic personas are valid. Coverage is behavioral casting advice; SQUAT never infers demographic coverage from names, prose, jobs, or hobbies.
Source and runtime governance. Unclassified sources, withdrawn permissions, blocked dependencies, stale or unreviewed communication ranges/auditions, and legacy actor prompts that still include provenance are named. Auditions remain synthetic calibration and never become evidence or sources. Only an authorized operator approves, withdraws, or recompiles.
Stale scenarios. A scenario whose feature was removed, or whose flow changed shape entirely, gets flagged with two straightforward options: edit it to match the current product, or leave it with a note so the next round knows to skip it.
Harness notes. The workspace's operating lessons — an inconsistent scenario result, a slow staging build, or a login quirk — reviewed for whether they are still true. Stale notes are retired while their history remains available.
Invalidated rounds — a second look. The sweep skims invalidation reasons and flags anything vague for your attention, and confirms nothing that should have been invalidated was missed. A compromised session still counting in the trend is worse than one flagged and excluded.
The issues queue. Long-open issues with no disposition are either still real (worth a reminder) or have quietly stopped mattering (worth a wontfix or deferred to clear the queue). Regressed issues — claimed fixes that didn't hold — surface first, always. The dispositions remain your calls; the sweep only surfaces candidates.
Browser-login readiness. Scenarios that require authentication are checked for a current non-secret policy and readiness attestation. SQUAT never asks for or stores the login secret.
Trash & cleanup. What's sitting in the trash (deleted rounds waiting out their 30-day retention) and what's eligible for purging, plus a report-only integrity check. Purge is prepared against exact targets, waits for you to type the 6-digit code shown only on your account page, and checkpoints every destructive step so a failed blob deletion can be resumed safely — see Deleting data and the trash.
Export backup. Owners and admins can take a safe portable copy periodically or a complete customer-content backup before purge or recovery work. The sweep suggests a cadence — after a big round, monthly, before any workspace-affecting change.
The sweep ends with a short, scannable summary: what's clean, what needs your decision (with the specific candidates named — never “some personas look stale”), and what's genuinely urgent: a regressed issue with no disposition, an unexplained invalidated round, or an incomplete purge backup.
Deleting data and the trash
Sometimes data shouldn't be cleaned up — it should be gone: a botched import, test noise from trying things out, a workspace you want to reset before real use. That's deletion, and it's deliberately different from invalidation. An invalidated round stays visible and simply leaves the trends — a data-quality correction. A deleted round goes to the trash — a lifecycle decision that it shouldn't be there at all. Both deleting and purging require an admin or owner seat.
Deleting a round moves it to the trash, where it sits for 30 days, fully recoverable — ask to restore it and it comes back completely, as if nothing happened. Nothing is destroyed until an explicit purge.
Exact-resource and participant requests
For an exact-resource request, or participant data registered in the workspace index, SQUAT inventories the records and files without putting their content in the request record. An owner reviews and authorizes that scope, then SQUAT deletes it in resumable steps while rechecking references and file versions. Whole-account or whole-workspace deletion is not executed from a partial inventory. When complete, SQUAT keeps a content-free deletion certificate with the scope, dates, counts, and outcome.
You can also remove saved Round Summaries and Research Reports by selecting the records to remove. SQUAT includes their saved versions and supporting stored files in the same reviewable request, and the owner can resume the operation if a step is interrupted. Source rounds and uploaded artifact sets stay in place unless you choose a separate request for them. A summary that is still cited by a report must be selected with that report so the saved research remains consistent.
Occasionally an item cannot be deleted or retained right now. SQUAT support can tell you why and when it will be free.
Artifact retention
An artifact's expiry date does not act by itself. An owner must activate automated retention for that set. When it is due, SQUAT runs its own safety checks and verifies round and report references and the exact stored file version before deleting anything. Your deployment operator must also enable the scheduled retention run; until then, maintenance can report and execute due work on request.
Starting clean
Asking SQUAT to “delete all my rounds” or “start clean” triggers a deliberate three-part confirmation:
You see what will be deleted. SQUAT shows you the counts first, per project — the full blast radius, before anything happens.
You're offered a backup. An export is free and strongly recommended, and SQUAT waits for your answer before going any further.
You type the phrase yourself. The deletion only proceeds when you type
DELETE ALL ROUNDS, exactly. The server refuses anything else — and your AI assistant is never allowed to type it for you.
Afterward, everything sits in the trash for 30 days and can be restored, round by round or all of it.
The trash and purging
The maintenance sweep reviews the trash: what's in it, and what has passed its 30-day retention. Purging is forever — it destroys the rounds, results, reports, dialogue records, and any associated protected artifacts. Before anything is destroyed, SQUAT verifies a completed full backup or records your explicit decision to decline one, prepares an exact target inventory, and displays a 6-digit confirmation code — only on your signed-in account page (Account → Confirmations), never to your assistant. The code lasts 5 minutes: you read it in your browser and type it back, so no purge can proceed without a person at the screen. SQUAT then locks those exact rounds, removes eligible artifact objects, and checkpoints each step. If anything fails, the operation stays partial and resumes under the same id; it never silently drops the round record needed to recover.
Deleting to trash is recoverable. Once a purge is authorized, its targets are locked; after completion, recovery is impossible. If there is any doubt, complete a full backup before preparing the purge.
Exports and the portability promise
Owners and admins can ask for an export anytime — it remains free at every tier, by design. A portable export is the readable, size-bounded current-state package: your personas and their governance material, current project content, live results, saved research reports, and artifact references, with no trash, history, or attachment bytes. A full backup is explicit and streams current and archived customer content, live and trashed rounds, results, reports, and protected artifacts to a durable object. It is complete only when its manifest says so.
Security and access material never travels in either profile: licenses, sign-in state, audit rows, support grants, managed-protection configuration, and deletion records are excluded. Export content remains protected in transit and at rest.
Hosted content protection is service-managed. You do not need to preserve a separate client content key or recovery file to open an authorized export.
Treat exports like any other backup: periodic, and stored somewhere that isn't the thing being backed up. One export from last year isn't a backup strategy.
Key and license hygiene
- License key replacement is a matter of your account with your SQUAT operator — the sweep reminds you of the cadence, but replacement itself happens through your account, not in-product. SQUAT cannot recover the raw key. If a key is lost or exposed, issue a replacement, confirm it connects, and revoke the old credential. Your workspace data remains intact.
- Removing a teammate prevents future authorized access. It cannot erase content they already exported or copied while authorized. See Roles & security.