Backups: the gap
This is a stub, published deliberately. Every other item on the eight-item sentence that gives this site its scope has material behind it somewhere in the corpus. This one does not.
Why the absence is worth a page
Three reasons, and the third is the one that makes it urgent rather than untidy.
- It is on this estate's own list. The eight-NFR sentence is quoted verbatim wherever this site states its scope. Quoting a list and then silently omitting one of its items would be the exact failure mode the reality-document rule exists to prevent.
- The topic is dense and the doctrine is empty. Frequent mention with no governing document is the signature of a thing everybody assumes somebody else has handled. It is a more dangerous state than obvious neglect, because it reads as coverage.
- This is an estate with irreversible operations. Publishing cannot be undone, and vaults can be frozen. Those are precisely the conditions under which a missing restore path is discovered at the worst possible moment — and the memory thesis raises the stakes again, because a network positioned as durable memory that cannot restore itself has a durability claim it cannot support.
The question to answer before writing the doctrine
Is the vault model — versioning plus escrow — already the backup doctrine, unnamed?
This is the right first question, and answering it either way collapses most of the work:
| If the answer is yes | If the answer is no |
|---|---|
| The doctrine largely exists and has never been written down or named, which is the same shape as the resilience doctrine and the PM system. The work is to state it, name its recovery objectives, and test a restore — because an untested restore path is a belief, not a backup. | There is a real gap, and it needs a written discipline covering what is backed up, how often, where it is held, who can restore it, and how the restore is verified. The estate would be starting from close to nothing. |
Either way, one requirement survives both branches and is worth stating now: a restore that has never been performed is not a backup. Whatever the vault model turns out to provide, that test has not been run.
Why this page exists in this state
Because the alternative was to leave the item off the navigation and hope nobody counted. A site whose credibility rests on publishing a mixed scorecard cannot quietly drop the one row that is entirely amber. The stub is here so the gap is visible, dated, and awkward — which is the most useful thing an empty page can be.
What replaces it: either the doctrine, or a page explaining that the vault model already was it. Tracked on the comms page and listed on what is proposed and not built. Cross-reference: sgit.ai owns the vault layer whose properties decide the answer.