(column: AnyPgColumn, at: Date)
| 504 | // never backwards, so a row that somehow carries a newer WorkOS timestamp |
| 505 | // keeps it and the upsert guard stays at least as strict. |
| 506 | const noEarlierThan = (column: AnyPgColumn, at: Date) => sql`greatest(${column}, ${instant(at)})`; |
| 507 | |
| 508 | // A membership tombstone keeps the row, marks it `inactive`, and records the |
| 509 | // deletion in `deleted_at`: the instant the caller holds, or `now()` when it |