Reconcile RAG Document Expiry, Chat History, and Cold Audits

Read the full interview experience this question came from →

Quick Overview

Design 24-hour document deletion, seven-day chat history, fast sidebar reads, and cold audits while resolving conflicts over derived content and physical erasure.

Reconcile RAG Document Expiry, Chat History, and Cold Audits

Company: Qualified Health

Role: Software Engineer

Category: System Design

Difficulty: hard

Interview Round: Onsite

Design the data lifecycle and history store for a document-grounded conversation system with these reported requirements: - Uploaded documents and vector indexes expire after 24 hours and must be physically deleted with zero residual data. - Conversation history remains available for 7 days. - The user's sidebar should load past conversation history in less than 10 milliseconds. - An enterprise may additionally request read-only conversation auditing for months or years. Explain how these requirements interact, which ones need clarification, and how the system behaves when a user opens a four-day-old conversation whose documents have expired. ### Constraints & Assumptions - A retained answer may itself contain information copied or derived from an uploaded document. - The selected vector store may lack native per-record TTL; do not assume that deleting a primary row removes every replica, backup, cache, or derived artifact instantly. - The source does not define the start of the 24-hour clock, the measurement boundary of the 10-millisecond target, or whether “all history” means conversation summaries or full transcripts. - Long-term audit retention must be reconciled with the shorter deletion rules; it is not an automatic exception. ### Clarifying Questions to Ask - Is expiry measured from upload, session creation, or last activity, and does it cover extracted text, embeddings, answers, logs, and backups? - Is exact physical erasure required at the deadline, or is access revocation at the deadline followed by a bounded verified deletion process acceptable? - May a day-four conversation remain readable but lose document-grounded follow-up capability? - Which audit fields may be retained without contradicting document or transcript deletion obligations? ### Part 1 — Enforce Expiry Across Stores Describe ownership, expiry metadata, access gating, deletion scheduling, vector cleanup, and evidence that the deletion process completed. #### What This Part Should Cover - An inventory of raw and derived copies with a common lifecycle identity. - Query-time expiry enforcement and physical-reclamation mechanisms appropriate to each store. - Retryable deletion and honest treatment of replicas, backups, and exact-deadline feasibility. ### Part 2 — Serve Historical Conversations Design conversation-list queries and the expired-document product state. Explain how the sidebar target can be approached without reading every full transcript. #### What This Part Should Cover - Tenant/user-scoped time indexes, bounded projections, and pagination where permitted. - Separate availability of transcript history and document-grounded querying. - Cache expiry and authorization consistent with retention rules. ### Part 3 — Reconcile Long-Term Audit Describe a cold audit path that does not slow the online database, and identify the policy conflict that must be resolved before archiving sensitive content. #### What This Part Should Cover - Explicit permitted audit scope and retention, not a hidden copy of supposedly deleted content. - Immutable/read-only storage controls, lifecycle rules, and offline query paths. - Verification that archive and backup behavior matches the agreed deletion semantics. ```hint Follow one paragraph into every copy Deleting the uploaded file does not remove a quoted paragraph from a chat answer, an extraction cache, or an archived log. Decide which copies the deletion requirement covers. ``` ### What a Strong Answer Covers - Technically enforceable lifecycle boundaries and explicit unresolved conflicts. - A usable history experience after document expiry. - Bounded fast history reads and a separately governed audit path. ### Follow-up Questions - Why is a database TTL index alone insufficient to prove exact-time physical deletion? - How would you handle a failed vector-delete request at the expiry boundary? - Can encryption-key destruction satisfy the stated requirement if it specifically demands physical byte removal?

Overview: Design 24-hour document deletion, seven-day chat history, fast sidebar reads, and cold audits while resolving conflicts over derived content and physical erasure.

Read the full Qualified Health Software Engineer interview experience this question came from

|Home/System Design/Qualified Health
Qualified Health logo
Qualified Health
Sep 8, 2026
hardSoftware EngineerOnsiteSystem Design
0
0

Design the data lifecycle and history store for a document-grounded conversation system with these reported requirements:

  • Uploaded documents and vector indexes expire after 24 hours and must be physically deleted with zero residual data.
  • Conversation history remains available for 7 days.
  • The user's sidebar should load past conversation history in less than 10 milliseconds.
  • An enterprise may additionally request read-only conversation auditing for months or years.

Explain how these requirements interact, which ones need clarification, and how the system behaves when a user opens a four-day-old conversation whose documents have expired.

Constraints & Assumptions

  • A retained answer may itself contain information copied or derived from an uploaded document.
  • The selected vector store may lack native per-record TTL; do not assume that deleting a primary row removes every replica, backup, cache, or derived artifact instantly.
  • The source does not define the start of the 24-hour clock, the measurement boundary of the 10-millisecond target, or whether “all history” means conversation summaries or full transcripts.
  • Long-term audit retention must be reconciled with the shorter deletion rules; it is not an automatic exception.

Clarifying Questions to Ask Guidance

  • Is expiry measured from upload, session creation, or last activity, and does it cover extracted text, embeddings, answers, logs, and backups?
  • Is exact physical erasure required at the deadline, or is access revocation at the deadline followed by a bounded verified deletion process acceptable?
  • May a day-four conversation remain readable but lose document-grounded follow-up capability?
  • Which audit fields may be retained without contradicting document or transcript deletion obligations?

Part 1 — Enforce Expiry Across Stores

Describe ownership, expiry metadata, access gating, deletion scheduling, vector cleanup, and evidence that the deletion process completed.

What This Part Should Cover Guidance

  • An inventory of raw and derived copies with a common lifecycle identity.
  • Query-time expiry enforcement and physical-reclamation mechanisms appropriate to each store.
  • Retryable deletion and honest treatment of replicas, backups, and exact-deadline feasibility.

Part 2 — Serve Historical Conversations

Design conversation-list queries and the expired-document product state. Explain how the sidebar target can be approached without reading every full transcript.

What This Part Should Cover Guidance

  • Tenant/user-scoped time indexes, bounded projections, and pagination where permitted.
  • Separate availability of transcript history and document-grounded querying.
  • Cache expiry and authorization consistent with retention rules.

Part 3 — Reconcile Long-Term Audit

Describe a cold audit path that does not slow the online database, and identify the policy conflict that must be resolved before archiving sensitive content.

What This Part Should Cover Guidance

  • Explicit permitted audit scope and retention, not a hidden copy of supposedly deleted content.
  • Immutable/read-only storage controls, lifecycle rules, and offline query paths.
  • Verification that archive and backup behavior matches the agreed deletion semantics.

What a Strong Answer Covers Guidance

  • Technically enforceable lifecycle boundaries and explicit unresolved conflicts.
  • A usable history experience after document expiry.
  • Bounded fast history reads and a separately governed audit path.

Follow-up Questions Guidance

  • Why is a database TTL index alone insufficient to prove exact-time physical deletion?
  • How would you handle a failed vector-delete request at the expiry boundary?
  • Can encryption-key destruction satisfy the stated requirement if it specifically demands physical byte removal?

Submit Your Answer to Earn 20XP

Sign in to leave a comment

Loading comments...