Operator Brief: Run a Cold Recovery Walkthrough

SUMMARY: A cold recovery walkthrough asks an operator who did not design the recovery plan to restore a critical workflow using only the materials available after a realistic failure.

Recovery instructions often succeed because the author silently supplies missing context. They remember which account owns the domain, where a backup key is stored, which warning can be ignored, and who can approve an emergency change. The document appears complete because the person testing it already knows the answer.

A cold walkthrough removes that hidden assistance. It tests whether retained knowledge can survive the absence of its usual operator without risking the production system.

Set the Scenario

Choose one bounded workflow, such as restoring publication access, recovering a member directory, or moving DNS after a provider failure. State which people and services are unavailable. Use a sandbox, copied configuration, or tabletop simulation whenever a live test would create unnecessary risk.

Give the Operator Only the Packet

Provide the documented recovery packet, offline credentials intended for the scenario, and the approved contact list. The plan’s author may observe but should not translate internal vocabulary, reveal locations, or supply omitted steps.

Record Every Stop

Access stop: a credential, device, network, or physical location is unavailable.

Authority stop: the operator can perform a step technically but cannot establish permission to do so.

Knowledge stop: a label, dependency, or decision point assumes undocumented context.

Validation stop: the operator completes a step but cannot determine whether the restored state is trustworthy.

Repair and Repeat

Update the packet immediately, assign an owner to each missing dependency, and repeat the blocked section with another operator. A walkthrough is complete only when restoration and validation can proceed without privileged memory.

Start with a dependency register to define the workflow boundary. Use recovery authority to separate possession of a credential from permission to act, then compare the result with the broader recovery rehearsal.

Operator rule: documentation is not recoverability until a fresh operator can use it under constrained conditions.

Continue the discussion in the Resilient Systems forum.