Engine · Operations & diagnostics

Library restore

Select a verified copy, plan exact recovery and restore without overwriting unrelated data.

Workflow

  1. Request restore planName the source, intended operation and policy without assuming provider availability.
  2. Validate identity and contractCheck stable identity, supported operations and policy before any write or restore.
  3. Perform bounded operationExecute only the declared provider operation and preserve partial, offline and retry state.
  4. Return unavailableThe workflow returns an explicit unavailable or refused outcome without inventing content or mutating unrelated records.
  5. Return item-level restore receiptReturn a provider-neutral, source-linked outcome that does not hide partial or unavailable work.

Failure boundaries

  • No adapter/record implementationProposal-only/unavailable: Do not simulate success
  • Provider offlineUnavailable/retryable: Preserve pending state
  • Receipt cannot verifyIncomplete: Do not mark complete

engine.ops.restore