Protection and recovery
Turn “I have backups” into a recovery objective you can test.
Start with the irreplaceable-data forecast from the storage planner. State the failure boundary, acceptable data loss, downtime, and retention, then map each protection layer and expose the first unmet recovery objective.
Protection-gap planner
Can the protected data return within its loss and downtime limits?
Map the primary array, snapshots, independent local copy, and offsite copy to distinct failure boundaries, then compare the eligible recovery path with explicit RPO, RTO, retention, and transfer limits.
The values below are editable planning baselines. Change the few inputs you know; open Advanced assumptions only when they change your decision.
Protection matrix
Keep every layer tied to the failure it can actually cover.
Schedules and retention describe recovery points. Storage location and access separation describe the failure boundary.
Primary array
——
—Snapshots
——
—Independent local copy
——
—Offsite copy
——
—First recovery gap
—
—
Recovery brief
Carry the objective, gaps, and restore window into a real test.
Copy the layer schedules, eligible recovery point, transfer bottleneck, and next verification together.
Next decision
Plan tools
Keep this useful version close, shareable, and easy to revisit.
Recent saved plans 0
RPO
The eligible independent copy must run often enough for the selected failure boundary. A fast snapshot does not replace a slower offsite recovery point.
RTO
Restore time uses the smallest of network, source-read, and destination-write throughput, with protocol efficiency shown separately.
Proof
The result becomes credible when a representative restore confirms throughput, credentials, retention, dependencies, and the documented procedure.