Account access-state (Activa/Desactivada), no-soft-delete-for-inactivity
Fleet initiative: explicit account access-state (Activa/Desactivada) on users, orthogonal to deletedAt, so inactive/failed/never-onboarded accounts are GATED not soft-deleted (soft-delete of live users breaks auth/FKs - the 89-user 07-15 incident). Full converged design = brainstorm bs-mrtgza1djze DECISION (2026-07-20, aro:evolutiva-fleet). Three independent axes (account-access / enrollment-roster / login-recency), durable lifecycle columns (deactivatedAt/By/reasonOptionId + reactivatedAt/By, lookup-backed reason), ONE central active-account guard, human-only reactivation (no OAuth self-heal), report-only June/July review queue (predicate: never-logged-in floored-at-go-live AND zero durable participation; NEVER date-auto-disable), Desactivar replaces every delete affordance (true-delete a separate locked workflow), /cuenta-desactivada Soporte-reachable landing, mandatory vocab split (ban Inactivo). Per-app legs: mars net-new columns + swap salud-datos delete; pluto reconcile+standardize + RETIRE live fn_lifecycleInactivity autoDeactivate/warn-email cron FIRST (backlogged 103 real-user emails, PLUTO-135); venus net-new on users NOT overloading alumnos.isActive + digest rides VENUS-294 + landing wires VENUS-143; enamel greenfield. STATUS: awaiting Elazar GO on the plan + his OK to urgently neutralize the pluto cron. Do NOT dispatch coders until GO.