Operational Methodology
Recovery Policy
RECOVERY is not “hoping it comes back”. It is a Fleet state with mandate, budget, and exit criteria.
Authorized or forbidden — no middle ground
If Recovery is not pre-authorized with Recovery Budget and clear gates, RECOVERY is an incident, not a strategy.
Step-by-step guide
RECOVERY · Budget · Exit
- 1
Define what RECOVERY means
RECOVERY = Telemetry shows active recovery (e.g. grid/rebuild management). It is a Protocol/Fleet state, not an opinion. You must recognize it in Command Center.
- 2
Pre-authorize Recovery Budget
Before the Mission assign a maximum Recovery Budget. Exceeding it = stop. Without a monetary ceiling, Recovery is open-ended capital.
- 3
Choose: intervene, contain, or stop
Intervene = manual action per runbook. Contain = let Engine policy run inside gates. Stop = close exposure / Mission. Decide triggers in advance.
- 4
Set depth and drawdown gates
Define max levels (depth, DD, time in RECOVERY). Every gate has a mandatory action. Soft gates with no action are not policy.
- 5
Exit RECOVERY explicitly
Valid exit only to ONLINE/IDLE with coherent Telemetry and Risk under threshold. Do not “hope the badge disappears”.
- 6
Run a post-mortem after every RECOVERY
Record cause, budget consumed, gates hit, outcome. Recovery without learning repeats the same drawdown under a new name.