Backup and Restore Service  ·  View 22 of 26  ·  6 · Operations

The Protection Status Loop

How a datastore moves between unproven and proven, and why being proven wears off with time.

Editable source SVG draw.io All views
Captured unproven Rehearsed isolated restore PROVEN date + depth + RTO Ageing interval running UNPROVEN > 2× interval Owner paged Protection status scheduled rehearsal asserts pass time passes no new proof page fix · next capture The Protection Status Loop — Proven Is a Date, Not a Flag Data store Application we own Opportunity Decision point Risk / gap Person or role v 1.0 · owner Backup Platform · date 2026-09

Decisions

  • PROVEN always carries three values: the date, the depth reached, and the measured restore duration. A status without a date looks like a guarantee and is not one.
  • Proof expires at twice the verification interval. A Tier 1 datastore not proven in 48 hours becomes UNPROVEN and appears on the same report as unprotected resources, in the same colour.
  • Only a successful rehearsal moves a datastore to PROVEN. A successful capture moves it to Captured, which is shown as unproven.

Numbers

  • Monthly targets: 100% of Tier 1 proven inside its interval, 98% of Tier 2, 95% of Tier 3. Measured RTO within target in the last 4 drills: 100% for Tier 1.

Why a loop

  • Recoverability decays. Schemas change, extensions are added, engines are upgraded. A copy proven in March says little about a restore in September, and the loop makes that decay visible.