Per-tenant retention configuration. Look up a TTL via
ttl_for(tenant_id); None means “keep forever” for that
tenant.
The default rule (from the bead): the CP heartbeat tenant
(system) defaults to 30 days. The CP emits ~69k heartbeat
events/day; without retention this grows unbounded for data
that has no audit value past the dashboard window. Other
tenants default to no TTL — user data stays put unless the
owner opts in.
Per-tenant overrides win over default_ttl; “no entry” falls
back to default_ttl.
Per-tenant overrides. Some(None) would mean “explicitly no
TTL”; the API uses Option<Duration> directly so an entry
can record an explicit “keep forever” decision distinct
from “no entry”.