The planned scenario
Recovery is a sequence of decisions, not just a restore button. Backup Recovery Drill organizes an exercise around the information those decisions need: incident status, business assets, restore requests, recovery plans, and stakeholder updates. A team can examine whether its proposed recovery order is supported by the available records.
The public routes represent coordination. Private records represent backup inventory, recovery sequencing, exercise evidence, and audit exports. Together they support a structured tabletop or an investigation into recovery information exposure. Users define the exercise question, decision criteria and review process.
Public surfaces
These reference routes describe possible entry points in the scenario model. They are not live customer services or a guarantee of the routes in a particular product release. Use your configured exercise inventory as the authoritative scope.
| Route | Surface | Context |
|---|---|---|
/ | incident-status | Incident status and executive update portal. |
/restore | restore-requests | Restore request and prioritization workflow. |
/assets | asset-catalog | Business service and asset catalog facade. |
/comms | comms-portal | Stakeholder communication and update surface. |
Private systems
These service names and segments describe the internal context of Backup Recovery Drill. They help define exercise boundaries and interpret the generated records.
backup-vault-inventoryBackup vault inventory and retention metadata. Catalog segment: private data.
recovery-orchestratorRecovery sequencing and dependency workflow data. Catalog segment: private application.
tabletop-evidenceTabletop exercise evidence store. Catalog segment: private data.
immutable-log-storeImmutable log and audit export representation. Catalog segment: private data.
Configure your exercise
Choose a question for the assignment and define the evidence participants should collect.
- What information is needed to prioritize a restore request against the business asset inventory?
- Which dependencies must be resolved before an operator could reasonably declare a service restored?
- Do stakeholder updates distinguish a requested action, an approved plan, and evidence that an action completed?
What to hand in
Create a recovery decision record with the proposed order, supporting artifacts, unresolved dependencies, and evidence still needed. Treat missing confirmation as an open question rather than a successful restore.
Records and evidence
Assets and restore requests define scope. Backup vault metadata and recovery plans describe the intended context. Communications and audit exports help trace how a decision was explained. Use the records to identify which confirmation a recovery decision still needs.
assetsrestore-requestsbackup-vaultsrecovery-planscommunicationsaudit-exports
Preserve the scenario and product version, the record or observation, and its source with each finding. Distinguish what a participant observed from what the reviewer inferred. Use synthetic data and your defined evidence-retention rules.
Public self-service at launch
Managed Verse is planned for 1 January 2027. Users will create an account, choose a scenario and configure their own authorized exercise boundaries. Vulnverse will host and operate the platform and cloud; users will not need to provision or maintain an exercise cloud.
Managed Verse is planned to replace all previous services. All new inquiries are paused during the transition. Read Managed Verse →.