Take a copy of everything, delete a memory, and what a deletion leaves behind.
Everything your organization writes into Mana is yours. You can take all of it out at any time, and you can delete any of it. This guide says exactly what each of those does.
Both are the organization owner's: an admin sees them, a member does not. A member who wants a memory gone asks an admin, or dismisses their own, which is a different thing and is explained at the end.
Open Settings, then Your data, then Export everything. Your browser saves one JSON file holding every memory and record the export could read, each with its key, its title, its text, who wrote it, when, and what it is allowed to be read by.
The file names what it does not contain. Knowledge labelled restricted is never exported, and knowledge above the exporting admin's clearance was not read, so the count of what was left out travels in the file. An archive that quietly leaves things out is worse than one that says so.
There is also a Markdown tree, one file per key, for anyone who would rather keep their knowledge in a repository. That is the mana export mirror command of the local tool.
Open the memory in the Library. At the end of the reader there is a line reading Delete this memory. Opening it asks you to type the memory's key, which is the line directly above the title, and to say why.
The reason is kept. It is not a formality: it is what the ledger records, and it is what somebody reading the history in a year will find where the memory used to be.
It leaves at once. Search, the Library, the standing instructions, every agent, and every count stop returning it the moment you confirm. Nobody can read it from that point.
Its content is erased within thirty days. The text, the stored bytes, and the evidence it cited are removed. After that it is gone and cannot be brought back.
Inside those thirty days you can put it back. Settings, then Your data, lists what is deleted and still recoverable, with the date its content will be erased. Put it back returns it to search and to every agent that may read it.
One thing survives the erasure, and we would rather tell you than have you find it.
Mana keeps a hash-chained ledger of everything that happened to the store. That is what makes it possible to check that nothing has been altered behind your back. The ledger records that a memory existed and was deleted, by whom, when, and the reason that was typed. It does not hold the memory's text.
The memory's key stays in it too. So a key that is itself sensitive stays readable there after the memory is gone. Keys are addresses, not contents, and it is worth naming them as addresses.
An agent can dismiss a memory, and so can you through an agent. A dismissed memory is retired: it leaves search and retrieval, and it stays in the store as a rejected revision that anyone with the right to read it still can.
Dismissing is a judgement about whether a record is worth keeping. Deleting is an organization act about whether it should exist at all. That is why dismissing belongs to the person who wrote it, and deleting belongs to the owner.
No agent can delete anything. Deletion is not one of the tools a connected agent holds, in any grant. It is a human act, from the dashboard or the local tool.
Export first, then write to support. Closing an organization deletes what it holds on the same thirty-day path as any other deletion.