From 52cd362343ca6721b57cb5eb08433c30c7f5f553 Mon Sep 17 00:00:00 2001 From: Albrecht Degering Date: Wed, 22 Jul 2026 03:40:29 +0200 Subject: [PATCH] docs(poll): describe response retirement contract --- README.md | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/README.md b/README.md index e13b7ed..831b7b0 100644 --- a/README.md +++ b/README.md @@ -116,6 +116,13 @@ submission. Option removal and option changes invalidate only answers bound to that option, and repeated removal/revocation is an idempotent replay even after the Poll has moved out of an editable lifecycle state. +Owning modules can also retire a participant's responses through the optional +response-retirement extension. Retirement is idempotent and soft-deletes the +live rows so aggregation and capacity checks stop counting them, while answers +and a reason/source retirement record remain available for audit. The boundary +accepts only server-trusted respondent or invitation identities and rejects +secret-like metadata. + ## Identified response invariant Poll stores at most one active response for each identified respondent in a