docs(conversion): the owner deletes segments, and the source-delete affordance is retired master
Operator ruling. The open call this plate carried -- legacy segments holding one source's data beside another's, where an owner deleting one source either loses the segment whole or keeps the data they asked to remove -- is CLOSED by removing the question rather than answering it. There is no source-delete affordance. The owner deletes a segment, or a set of segments, and there is no affordance for a partial owner-directed delete of any kind. The legacy-mixed problem existed only as a resolution step, turning "delete my <source> data" into a set of segments; with the owner naming segments directly there is nothing to resolve and no disposition to choose. The surface already exists -- the per-segment delete route, with containment and a 10-second undo window. So the whole-segment verb takes a SET, one receipt covers it, and per-target failures are receipt rows: an owner deleting forty segments must not lose the thirty-nine that succeeded because the fortieth was unreadable. Retired with it: the owner-facing source-delete route, the source-delete implementation and both its branches, the deletable-source-stream allowlist, and the mixed / location-only classification. The reserved-name set divergence loses its last load-bearing consumer -- it fed the mixed classifier, and there is no classifier. Also ruled: the plate keeps TWO units of removal, with the no-partial rule binding owner-directed deletion only. Reading it as binding both makes this plate's own terminal-empty hand-off contradictory, because handing retention a raw file would destroy the marker the audio handler had just written along with the transcript. And a fifth strand is minted: S:*:journal-retention, the removal request, owned by retention as the one-to-many end per rule 1. Four plates request removals and until now that contract had four callers and no name -- the two-places-own-one-thing class the rule exists to make unrepresentable. A request carries its own precondition, so the offload pass's confirmed-snapshot guard travels with the request rather than staying behind in the caller.