Dossier · Reversibility audit

Execute a reproducible exit test

Export the assets, rebuild an isolated target and have the internal team recover critical functions against criteria fixed before the exercise.

On this page
Test proposition

Demonstrate a defined recovery within a defined window

The test does not ask whether exit appears possible. It verifies that an identified minimum service can be restored on a given target using authorised assets and within limits approved by the authority named in the mandate.

Production may remain untouched: the exercise uses a controlled source state and an isolated target. Any extrapolation to the full system is written as a limitation.

Entry conditions

Do not start until the exercise can be interpreted

Six prerequisites prevent a preparation failure from being confused with an impossible exit.

  • Inventory — assets and dependencies within scope are available
  • Target — capable of receiving and executing the selected assets
  • Rights — export, use, copy, transfer and erasure have been examined
  • Criteria — thresholds and critical functions approved before execution
  • Security — window, rollback and stop conditions are defined
  • Authorities — source, target, security and decision owners are named
Sequence T0–T10

Preserve the evidence chain throughout the exit

Every phase reuses register identifiers and emits a dated trace. Any phase not executed remains visible in the conclusion.

TRARDI Reversibility Test sequence
PhaseOperationPass evidence
T0Freeze scope, version and criteriaApproved mandate and inventory
T1Produce the complete exportManifests, volumes and errors
T2Check integrity and exclusionsHashes, reconciliations and gaps
T3Load assets on the targetImport logs and available objects
T4Rebuild the environmentReplayed deployment and resolved dependencies
T5Execute critical journeysResults compared with criteria
T6Test incident and restorationAlerts, decisions and traces
T7Switch within the planned windowObserved start, interruption and recovery
T8Revoke source accessRotated keys and removed accounts
T9Execute rollbackControlled return or documented reservation
T10Close the exerciseConclusion, gaps and retained evidence
Integrity

Reconcile what was expected with what can actually be read

An export manifest is not enough. Volumes, hashes, schemas, metadata, time conventions and access rights are checked, then the data is actually read or queried on the target.

An exclusion may be legitimate. It must still be exhaustive, justified, linked to its effect on the service and accepted before the conclusion is signed.

Reconstruction

Run the service without an unplanned source dependency

The target is rebuilt from versioned artefacts. Interfaces, identities, observability, backups and incident procedures are replayed. Secrets are recreated on the target, never copied in clear text.

Functional equivalence is not technical identity. Shared features and acceptable deviation between source and target are defined before comparison.

Decision measures

Attach every measure to an acceptance condition

The stopwatch is only one measure. The file also records data loss, manual work and residual calls to the source.

  • Coverage — critical assets present or exclusion accepted
  • Integrity — no unexplained critical discrepancy
  • Journeys — selected functions meet the prior threshold
  • Recovery — duration and data loss within approved objectives
  • Autonomy — critical operations executed without unplanned help
  • Erasure — source inaccessibility shown under the applicable framework
Exercise safety

Stop before the test creates an incident of its own

The lead suspends the exercise if production data could be altered, a secret leaves controlled custody, return to the safe state becomes impossible or a newly discovered dependency falls outside the authorised scope.

Every stop retains the time, observed fact, consulted authority and resumption condition. Rollback is executed or its impossibility appears as a reservation.

Conclusion

Sign what the exercise demonstrates — and nothing more

The conclusion distinguishes demonstrated, conditional and unproven exit. It identifies unexecuted phases, gaps, residual dependencies, owners and the reassessment date.

Primary sources

Sources this page relies on

Last documentary review: 6 September 2026.

Before you write to us

Frequently asked questions

Must an exit test interrupt production?

No. It can use a controlled source state and an isolated target. The report then limits its conclusion to the scope, version and conditions actually exercised.

Who sets the acceptable recovery time?

The authority named in the mandate approves it before the exercise based on service criticality and applicable obligations. The method sets no universal time target.

Is a complete export enough to pass the test?

No. Integrity must still be checked, the target rebuilt, critical journeys executed, source access revoked and target-team autonomy demonstrated.

Reversibility dossier

Which exit scenario must you be able to execute?

Present the source, target and expected minimum service. We assess whether the conditions for an interpretable exercise are met.

Scope the test