Command center recovery evidence
The dependency cockpit contains operator playbooks for uncertain payment outcomes, interrupted inbox publication, partial privacy work and dependency outages. Assign a named incident owner and record the time, affected service, exact workflow identifiers, current control state and missing evidence. Guidance does not execute recovery or declare an incident resolved.
Maintenance windows are calendar records. An active/completed entry, planned notice or requested read-only preference does not activate a circuit control or publish a member notice. The calendar opens the existing reviewed General settings workflow for actual maintenance configuration. Calendar read failures remain unavailable; an empty schedule says nothing about live platform health.
Isolated representative drill
Set DEBELU_DB_RUNTIME to the installed local @electric-sql/pglite/dist/index.js, then run:
node --test scripts/recovery-drill.test.mjs
node scripts/command-center-recovery-drill.mjs
node scripts/command-center-recovery-drill.mjs --verify .artifacts/command-center-recovery-drill.jsonThe runner creates disposable in-memory databases and runs eight existing SQL fixture suites: checkout reservation/crash recovery, payout dispatch fencing, payout outcome reconciliation, protected export expiry/receipt binding, campaign interruption, full unsettled wallet refund consistency, scoped privacy erasure/retained-data receipts and expanded owned-data exports. It strips hosted credentials, database URLs and Node preload options from fixture subprocesses. No deployed database, customer data or provider is contacted. Do not substitute a production connection or turn a fixture into live test traffic.
The JSON artifact contains each assertion, exit status, bounded output, timing, exact Git revision, working-tree state and input source hashes. Timeouts, oversized output, missing asserted evidence, failed assertions or changing inputs produce a failed/invalid outcome. An SHA-256 receipt detects alteration; it is not a digital signature or independent authorship evidence. Preserve the artifact with the incident or release review. A successful serial fixture run does not establish native concurrency, a production restore, provider delivery or release readiness.
Operational completion gates
- An uncertain payment keeps its existing reference. Independently reviewed reconciliation must produce the established ledger receipt; an unavailable provider observation stays uncertain. Do not directly edit request statuses, balances or transaction rows.
- Inbox recovery reuses the durable intent and verifies one actual notification identifier. Live authority, campaign consent, cancellation and expiry remain enforced. Push/SMS/WhatsApp delivery requires separate evidence.
- Privacy recovery keeps the case revision, identity and hold authoritative. Separate database deletion counts from exact-version storage results. Retained account, finance, audit, shared, unclassified, backup and external data remain documented; scoped execution does not complete the request.
- A backup restore runs in an isolated environment. Record backup identity/time, the agreed recovery objective, actual restoration duration and independent review. Verify restored authority, wallet/escrow/ledger, audit, storage and queued work together.
- Native baseline replay and independent-session checks use
scripts/db-flow-tests.shand the guarded native concurrency runner in CI. Authorized browser journeys and controlled restoration of circuit controls remain separate release gates. Connection probes establish only their declared read/ping scope.
This workflow adds reproducible fixture evidence and operator guidance. It does not schedule backups, establish recovery objectives, restore a hosted environment, configure missing providers or waive production migration reconciliation.