Correct ![]()
It depends
In a simple version I’d invoke an internal context function which is not exposed outside to web & co. I’d strive to make this function private, so it’s not accidentally invoked. If the function is private you can’t invoke it from iex, so it motivates you to provide an account which is deleting it (like e.g. some admin account).
A variation is to introduce a “system” account which has full privileges, and pass that to the context function which accepts the account. This allows us to log who performed each operation, even if the operation has been performed from within by the system itself, which can assist with auditing.


















