ENTITY Documentation Portal
Tutorial 4 · continuity

Run a provider-independent recovery drill

A recovery test is successful only when the logical authority, information and economic meaning survives—not merely when a database file can be copied. This drill separates identity continuity, BTDU reconstruction and market/economic-state recovery.

Safety rule: perform this tutorial on a test/copy environment. Do not destroy production identity keys or the only authoritative backup just to prove a recovery path.

1. Capture the baseline

Before simulating loss, record the state you expect to recover.

2. Produce the recovery material

Use the current operator backup/export and market-recovery procedures to produce a protected recovery set. Keep identity/key material separate from public evidence. For market recovery, preserve canonical logical rows, semantic hashes, identity manifests and controller attestations rather than treating database bytes themselves as the authority.

3. Simulate provider/workspace loss

Move the working copy aside or restore into a clean compatible destination. The important property is that the recovery destination does not depend on the original application's live database or workspace.

For a stronger BTDU test, select at least one object whose original workspace copy is unavailable to the recovery process and require exact reconstruction from governed state.

4. Restore identity and governed state

  1. Restore/verify the Entity public identity and authorized private key material using the protected operator procedure.
  2. Open the recovered BTDU/ADAM state and verify its root before mutation.
  3. Restore the market snapshot into a clean compatible destination.
  4. Restore economic participation state alongside exchange state.
  5. Reject the recovery if a required subsystem/table is absent instead of treating a partial market as complete.

5. Verify the recovered system

LayerVerification
IdentityManifest and continuity proofs verify; recovered keys have no broader authority than before.
BTDUAtomic root/state verifies and selected reconstructed objects match expected SHA-256 exactly.
Market structureVenues, instruments, balances, listings and disclosures match semantic hashes.
ExecutionOrders, trades, RFQs, quotes, acceptances and cancellations are preserved.
Post-tradeClearing, entitlements, usage, verifier authorizations and payment attestations are preserved.
EconomicsRevenue rules, treasuries, allocations, obligations and participation state survive.

6. Run negative checks

7. Compare with the qualified destruction-recovery result

The public BTDU evidence includes a stronger qualified case in which the tested Memnox campaign recovered 865/865 tracked blobs plus archive, manifest and acceptance proof without the original workspace, Git, GitHub or network. Your tutorial run should use the same principle: define what must survive, remove dependencies, reconstruct, then compare exact evidence.

8. Success criteria