Backup and Restore Service · View 26 of 26 · 7 · Assurance
Decisions
- Every row's protection is structural: a right the identity does not have, a lock enforced by storage, a copy in a separately administered place, or a monitor outside the platform. None of them depends on someone being careful.
- Wherever possible, detection is a rehearsal, not an alert. Key loss, version drift and a too-slow restore all appear first as a failed drill, when finding them costs nothing.
Gamedays
- Every quarter, one whole scenario is run and timed by people following the written procedure: data-centre loss, custody credential loss, catalogue loss, or deletion of a production namespace. The measured times are published next to the targets, and the authors of the runbook are not allowed to run it.
Residual risks
- A regional disaster that takes both data centres leaves only tape, with a multi-day RTO.
- An application-level corruption that no invariant checks for passes depth 3 and is found only by the business. Clean-point search can recover from it, but only once someone can describe it.