Protection
The Protection view answers one question: what does the cloud configuration say is backed up, snapshotted or replicated? It answers it carefully, because a protection report that overstates is worse than none.
What DRM reads
Protection is read from cloud configuration through the platform's read-only connection. That includes, for example:
- backup plans and their retention;
- database automated backups and multi-zone deployments;
- snapshots;
- read replicas;
- storage replication, including cross-region replication.
Which mechanisms DRM recognises varies by cloud and by resource type.
Configured is not protected
A configured mechanism is reported as discovered — never as protected or tested. Those are statements a person makes.
Configuration shows that a mechanism is set up. It does not show:
- whether last night's backup job succeeded;
- whether a restore has ever worked;
- whether the copy is complete or usable.
DRM does not pretend otherwise. The way to prove a recovery works is a drill run with your own tools and recorded in DRM — see RTO, RPO & Drills.
What DRM cannot see
DRM reads the cloud provider's control plane. Anything that only happens inside a server is invisible to it:
- a database dump or backup job scheduled inside a virtual machine;
- the job history of a third-party backup product.
There are no connectors to backup products. A resource with no configured mechanism that DRM can see may still be protected by something it cannot — treat it as a question for the resource's owner, not as a verdict.
Per resource and per application
Protection is a property of a resource, so DRM records it whether or not the resource has been grouped into an application yet. A database nobody has tagged still shows the backup its configuration has.
Where a resource belongs to an application, protection is also shown per application. A resource used by two applications gets one pairing for each: the same replica can be critical to one application and incidental to another, and approving it for one is not approving it for the other.
How protection feeds the rest of DRM
- Recovery plans use only approved protection pairings.
- Predicted RPO comes from replication links — the worst link, taking the larger of the lag last observed and the configured target. An application protected only by backups, with no backup frequency recorded, gets no predicted RPO rather than a guess. See RTO, RPO & Drills.
- Drift reports protection that changed since you approved the baseline — for example a new resource without protection. See Approvals, Baselines & Drift.