Project Mad AdderHelp Centre
All help articles

Current PMA guide

PMA Vault — Complete Backup & Restore

PMA Vault creates a recoverable package containing organization-scoped PMA records, integrity evidence, and optional private media. Restore Centre proves that an archive is readable before any change, compares archived record IDs with a target workspace, and lets the workspace owner recover selected categories.

Safe recovery boundary

PMA Vault restore is non-destructive. Missing-record mode leaves matching records unchanged. Complete recovery may restore archived values to matching record IDs, but it does not delete records created after the backup. Passwords, sessions, secret keys, billing state, entitlements, platform controls, and automatic permission grants are excluded.

Before you begin

  • Use an owner or administrator account to create archives. Restore execution requires the workspace owner.
  • Remain online until PMA confirms the archive has downloaded or the restore has completed.
  • Keep at least two copies of important archives in separate physical or cloud locations.
  • Do not edit, rename internal entries, or recompress a `.pmaarchive` file.
  • For large media collections, keep the device powered and prevent the browser tab from sleeping. PMA Vault deliberately blocks browser-built media archives above 512 MB rather than producing an incomplete “verified” archive; create a records-only archive when that boundary is reached.

1. Create a complete recovery archive

  1. Open Settings & Data → Backups & Restore.
  2. Review the Protection Status card and the date of the latest verified archive.
  3. Enable Include audit and governance history only when you need audit records, issue history, and operational documents.
  4. Select Complete recovery archive.
  5. Keep the page open while PMA prepares the structured snapshot, lists private Storage files, downloads each media object, creates SHA-256 fingerprints, and seals the archive.
  6. Store the downloaded `.pmaarchive` file somewhere protected.
Expected result: PMA records a Ready archive only after the structured snapshot and archive inventory are sealed and the final file fingerprint is calculated.

2. Choose another backup format

Complete

Recoverable PMA records and private media. Recommended for disaster recovery.

Records only

Structured PMA records and settings without media bytes. Faster and smaller.

Media only

Private media bytes and integrity evidence. Use alongside a records archive.

The Portable ZIP/CSV export is intended for human access and portability. It is not a substitute for a PMA Vault recovery archive because it does not preserve every internal record relationship or private media byte.

3. Test an archive without restoring

  1. Select Inspect archive.
  2. Choose a `.pmaarchive` or compatible PMA Vault ZIP.
  3. PMA verifies the manifest, application identity, workspace identity, every listed entry, entry sizes, SHA-256 fingerprints, the snapshot fingerprint, and record totals.
  4. Restore Centre sends the verified snapshot to PMA for a dry-run comparison against the selected target workspace.
  5. Review totals for archive records, existing records, missing records, and records that require manual review.
Expected result: The page says Recovery test passed and explicitly states that no production records were changed.

4. Restore into the current workspace

  1. Choose Current workspace before inspecting the archive.
  2. Select the categories to recover.
  3. Choose Restore missing records when you only want absent record IDs added.
  4. Choose Complete non-destructive recovery when matching record IDs should receive archived values.
  5. Decide whether workspace preferences and branding should be restored. Plan and access controls are never changed.
  6. Type the target workspace name exactly.
  7. Select Restore selected categories.
Expected result: The database restore completes atomically. PMA then restores media objects and reports any media file that needs separate review.

5. Disaster recovery into another workspace

Not a workspace-cloning tool. PMA blocks execution while the original source workspace still exists or when any archived primary-key identity belongs to another workspace. You may inspect the archive and review the dry run, but you cannot use PMA Vault to duplicate a live collection.
  1. Use this mode only for supported disaster recovery after the original source workspace is no longer present.
  2. Choose Disaster recovery workspace, enter a distinct name, and create the empty target.
  3. Inspect the archive against the target. PMA reports whether the source still exists and whether archived record identities conflict elsewhere.
  4. Proceed only when Restore Centre shows no blocking reason.
  5. Choose the categories and recovery behaviour, type the target name exactly, and restore.
  6. Open the recovered workspace and verify animal counts, housing, care history, breeding records, operations, media, and workspace preferences before using it operationally.

What is intentionally excluded

  • Passwords, authentication sessions, recovery tokens, and identity-provider credentials.
  • Integration API keys, webhook secrets, public share tokens, and customer portal tokens.
  • Payment credentials, subscription billing state, PMA plan entitlements, and managed-slot accounting.
  • Platform administration, release-control, and deployment records.
  • Automatic membership or permission restoration. Archived roles appear for review but cannot grant access.

Troubleshooting

Archive creation stops while downloading media

Keep the tab open and confirm the device is online. A complete archive intentionally fails if a listed media object cannot be protected; create a records-only archive while investigating the Storage object.

Integrity verification fails

Do not restore the file. Use the original downloaded archive, compare its recorded SHA-256 fingerprint, and create a fresh backup if the file was copied, edited, truncated, or recompressed.

Some archived records are manual-only

PMA excludes automatic restoration when a record could grant access or alter protected platform state. Recreate those settings through the normal governed interface after reviewing the archived role summary.

Complete recovery leaves newer records in place

This is intentional. PMA Vault does not delete records that were created after the archive. Review and archive unwanted records through their normal PMA workflow.

Some media files report warnings

The database restore may still be complete. Review the Restore History entry, confirm Storage permissions and available capacity, then inspect the archive again before another controlled restore.

Restore says the source workspace still exists

This is the expected live-cloning safeguard. Restore into the original workspace, or use another workspace only after the source has been removed through the supported disaster-recovery process.

Recovery ownership

An archive is sensitive even though credentials are excluded. It may contain animal records, customer information, operational documents, health history, and private media. Store and share it as confidential business data.