- Restore order: core catalogs → contacts/identities/consents → tracked_events partitions in range → loyalty (programs, currencies, ledger, lots) → REBUILD projections (contact_balances from ledger; segment_members via full recompute) → messaging config → sends/status (optional, from exports).
- NEVER restore projections from backup if their sources restored — rebuild them (ADR-017 discipline).
- Post-restore checks: balance reconciliation clean · segment counts within 1% of pre-incident snapshot · resolveChannels smoke test · webhook endpoints PAUSED until tenant confirms (avoid replay storms).
Runbook — Tenant Restore (Engage/CRM extension)
Extends the suite tenant-restore runbook (pre-G1 requirement) with module data: - Restore order: core catalogs → contacts/identities/consents → tracked_events partitions in range → loyalty (programs, currencies, ledger.
Extends the suite tenant-restore runbook (pre-G1 requirement) with module data:
⌘I