Governance

A hold should be visible when deletion is attempted

A legal or investigative hold only matters if the product changes behaviour when somebody tries to remove the content.

Hold is an active state

A dispute, investigation or litigation matter can create a preservation requirement. Recording the hold in a document outside the content system is useful for process, but the product still needs a state it can evaluate when deletion is requested.

That state should identify enough context for authorised administrators and audit to understand why the object is frozen.

Delete should fail safely

When a hold is active, deletion should return a clear blocked outcome rather than succeeding and relying on later recovery. The user does not need a legal essay in the interface, but operations need enough information to identify the governing hold and next step.

The denied attempt itself can also be relevant audit evidence.

Release is another governed change

Eventually a hold may be lifted by the authorised process. That transition should be recorded, and ordinary retention or access policy should continue to apply afterwards.

Lifting the hold does not have to mean immediate deletion; it simply removes one constraint from the lifecycle decision.

Test at the delete attempt

The informative moment is the blocked delete. Confirm the product names the hold, keeps the object available under policy and records both the hold and the refusal.