Governed recovery objectives and evidence
Migration039 adds an operator evidence register, not a recovery executor. It does not schedule backups, contact providers, restore production or change financial rows. Existing BCP targets and topology descriptions are not imported as verified configuration. Operators explicitly supply nullable RPO and RTO objectives in milliseconds; blank values mean unknown.
Current global canManageSettings staff with verified AAL2 own cases. Accepted commands freeze actor, reason, exact revision and immutable receipt. An independent current settings reviewer decides an unexpired proposal. Revoked proposers cannot gain approval; rejection remains available, followed by audited handover only when the former owner has lost authority. Active owners cannot be displaced. Changing objectives clears the current outcome, preserving historic commands.
Evidence is either operator_provided or runner_artifact_integrity. The latter means the backend validated a bounded native runner JSON envelope and its SHA256 checksum. It does not authenticate an author or prove that the uploaded report was actually executed. Neither provenance certifies hosted restore or delivery. Artifact identity, source digests, backup time, measured restore duration and reported recovery point are retained with authority, finance, audit, storage and queue invariant outcomes. Retain the original artifact outside this minimized register to independently reproduce and compare the checksum.
reviewed_objectives_met means independently reviewed local evidence meets the configured objectives. It requires known objectives and observations, measurements within bounds, a checksum-valid local artifact reporting a passed run and all five invariants reported passed. Unknown RPO, missing objectives, failed/unknown invariants, exceeded targets, rejected evidence and operator-only assertions produce reviewed_blocked. productionRestoreVerified and providerOutcomesVerified remain false in every receipt. Storage metadata invariants refer to SQL object/version manifests; storageBytesVerified separately states whether object bytes were checked. A native database dump is not a storage object backup.
The admin recovery panel shows ownership, objectives, evidence and immutable receipts. Pasting JSON never executes recovery. A confirmed command with unknown network outcome keeps the original identifier and input for exact retry; a definitive rejection requires reinspection.
API mount: /api/admin/recovery-evidence, GET /, GET /:id, POST /commands. Actions: open, configure, takeover, propose, review. A proposal accepts exactly one of evidence (operator-provided normalized observations) or artifact (native runner {body,sha256} envelope). Requests and evidence are bounded to 1MiB, source manifests to1000 entries and lists/receipts to100 entries. Table RLS, revoked direct ACLs and write/truncate guards preserve the workflow even if a service role inherits broad privileges.
Verification: scripts/db-recovery-evidence-checks.mjs covers authority/MFA, revisions, replay, independent review, unknown objectives/RPO, false production proof, operator provenance, invariant failures and revoked-owner recovery. The separate scripts/db-native-backup-restore-drill.mjs performs a synthetic native database dump into a second disposable database; its artifact contract is debelu_native_backup_restore_v1, scope isolated_synthetic. No customer backup, hosted connection or provider traffic belongs in that test.