Nothing here is a summary written after the fact. These are the problem, mechanism,
and move of each article, in the reading order, joined by its own connective lines.
Any one of them opens into the full argument.
Begin with the person at the delete button, who is not performing maintenance but closing a chapter, and needs the act to be theirs.
The most consequential material a person produces is disposed of through a settings page and a warning dialog, while the person doing the disposing is trying to end a chapter, and every culture that moves someone across a threshold does it with a performed act instead.
Mechanism
Closure is an action rather than a state, so a deletion the person performs deliberately and the system answers irreversibly does work that the same bytes expiring quietly on a retention schedule cannot do.
Move
Give the ending back to the person who is having it: a moment they choose, words of their own if they want them, an answer from the system that is true, and no argument at the threshold.
The rite only works if the system's answer is true, which turns out to be the harder half, because a record has copies and consent has layers.
By the time a person asks for their data back, its value has usually moved into derivatives, which is why regulators now order the destruction of models trained on improperly collected material rather than only the material itself.
Mechanism
Consent separates into a display-binding proof, a durable receipt, a standing permission, and a short-lived runtime lease, each answering a different question, so a system that collapses them reads evidence that someone saw a screen as authority over everything downstream of it.
Move
Stop asking whether a product has a delete button and start asking it to name its derivatives, because a revocation is only as real as the provenance that can find every copy.
One instrument resolves the sharpest version of the problem, where the record must be permanent and the person still has a right to go.
A system that must prove what it did keeps an append-only history, and a person described inside that history has a legal right to have their part erased, so the ledger and the right appear to rule each other out.
Mechanism
Erasure operates on the key rather than on the history, so destroying the key leaves the sequence, the hashes, and the replayability intact while the personal content inside becomes unrecoverable.
Move
Hold personal content under a per-person key stored somewhere else, and state the caveat as loudly as the capability, because the guarantee is exactly as strong as the key management underneath it.
Widen from a person leaving a record to a customer leaving a company, and the same proof discipline decides whether anyone can afford to commit.
Software strategy has treated the cost of leaving as an asset to be raised, which produces customers who stay on platforms they dislike because their records are inside them and the arithmetic of exit gets worse every month.
Mechanism
A buyer weighing a long commitment is pricing the worst case, so a proven exit removes the worst case from the calculation and makes the commitment cheaper to make, which is why the ability to leave is what makes staying safe.
Move
Prove the exit rather than promising it, on a clean host, with a signed inventory and a verifier the recipient runs from their own copy, and let retention be earned by everything that is not the difficulty of leaving.
You have walked Endings end to end: the rite, the cascade, the key, and the door. Every one of them is the same argument in a different register, that a thing which cannot end well cannot be trusted with a beginning.