Define recovery boundary
An analytics platform includes metadata, dashboard definitions, permissions, source connections, source data, identity, and scheduled delivery. State which parts recovery covers and the accepted data-loss boundary.
Inventory dependencies
List application metadata stores, warehouses, files, secrets, mail, identity, DNS, and reporting databases. A restored dashboard is not usable if its source or sign-in path is absent.
Run an isolated restore
Restore into an isolated environment. Use a normal account to sign in, open a known dashboard, verify permissions, and run a representative query without exposing production data.
Record failures and recovery order
Record timing, missing secrets, broken connection strings, permission differences, and dependencies that must precede the application. Update the runbook and repeat the failed stage.
Recovery record
Keep evidence with the platform.
| Component | Test | Result |
|---|---|---|
| Metadata | Restore | Dashboard returns. |
| Identity | Sign-in | Restricted user works. |
| Source | Query | Expected data path. |
| Permissions | Access | Excluded data remains blocked. |
Questions
Are snapshots enough?
Only if the full recovery path has been exercised.
What proves recovery?
A user journey and operator check succeed in isolation.
When retest?
After material dependency or architecture changes.
Recovery cycle
Name components and objectives.
Exercise the stated boundary.
Update after change.
Checks
Retain dated evidence.
Dependency map
Dependencies are ordered.
User test
A normal account works.
Limit record
Gaps are stated.

