ENTITY Documentation Portal
Core tutorial 12

Recover governed meaning, not just files

ENTITY recovery is about restoring signed logical state—identity, authority, rights, events, evidence, provenance, value and economic records—without allowing a backup file or provider database to become the authority.

1. Export a core sovereign bundle

bundle = fabric.export_bundle(object_id)

The bundle collects the root object's ancestry plus active rights/authority, events, provenance, values, attestations, resolution records and the required identity manifests. The bundle carries a semantic SHA-256 and provider_independent=true.

2. Verify before trusting

result = fabric.verify_bundle(bundle)
assert result["valid"] is True

Verification must establish manifest/signature integrity and the semantic bundle hash. A copied JSON file is not automatically authoritative merely because it came from a backup directory.

3. Export the complete market/economic state

market_bundle = MarketStateRecovery.export(
    exchange_path,
    economic_path,
    identity,
    core_bundles=[bundle],
)

The market-recovery profile requires complete logical state across the exchange and participation systems. Required exchange tables include venues, instruments, balances, listings, orders, trades, clearing, entitlements, disclosures, usage, revenue rules/rule sets, trade-revenue bindings, surveillance, RFQs, quotes, RFQ acceptances, cancellations, settlement-verifier authorizations and payment attestations. Economic participation adds treasuries, participation policies, reserve allocations, economic events, obligations, position snapshots and settlement verifiers.

4. Verify the market bundle

verification = MarketStateRecovery.verify(
    market_bundle,
    verify_manifest=identity.verify_manifest,
    verify_signature=VERIFY_SIGNATURE,
    verify_core_bundle=fabric.verify_bundle,
)
assert verification["valid"] is True

The verifier checks per-table semantic hashes, complete required-table coverage, database-level state hashes, embedded manifests, controller attestations and the overall semantic bundle root.

5. Restore only into a clean compatible destination

MarketStateRecovery.restore(
    market_bundle,
    NEW_EXCHANGE_DB,
    NEW_ECONOMIC_DB,
    verify_manifest=identity.verify_manifest,
    verify_signature=VERIFY_SIGNATURE,
    verify_core_bundle=fabric.verify_bundle,
)

The restore path requires an empty compatible destination. This prevents stale/foreign state from being silently merged into the recovered authoritative state.

6. Test partial recovery failure

Remove one required economic table or alter one signed/hashed record in a test copy. Verification must fail. A partial market is not allowed to call itself a complete recovered market.

7. Test destruction/cold recovery separately

The BTDU qualification campaign has already demonstrated 100% exact reconstruction for the tested destruction/cold-recovery case, including the Memnox 865/865 tracked Git blobs plus archive, manifest and upstream-acceptance proof without the original workspace, Git, GitHub or network. That is bounded evidence for the tested campaign, not a universal promise about arbitrary damaged data.

Recovery invariant: a provider can disappear without becoming the owner of the authority, rights or economic state it hosted.