Scan rule · RSC-DET-005
Test data could not be removed
Architecture & SEOSeverity: Info
Names records the write check created and could not delete again.
Why this matters
The write check cleans up after itself. If that fails — for instance because the policy allows creating but not deleting — it must appear in the report. Same promise as with the throwaway account: whatever the scan leaves behind, it names, so it can be removed.
That an account may create but not delete is itself a hint at an incompletely considered access policy.
Scan tier
Active (after domain proof)
How to fix it
Remove the listed rows.