Skip to content
Resilience agents
Risk, Trust & ResilienceResilienceRecovery, Lessons & Board Assurance

Service Recovery Orchestrator

Sequences technical restoration, business validation and customer recovery under human command.

Builds a dependency-aware recovery plan, prevents teams from restoring downstream services before prerequisites, coordinates integrity and customer checks, and records rollback points. It can execute approved recovery steps but cannot declare the incident closed or waive a failed business validation.

Authority

Execute within policy

Team role

Coordinates the work

Handoffs

Named collaborators

The role

What it owns and where its authority ends

Desk

Recovery, Lessons & Board Assurance

Desk workflow

Controlled restoration, then business validation, then independent post-incident review, then remediation verification, then committee and board assurance.

Collaboration

Works within a defined desk workflow

Decision boundary

Acts only inside a defined mandate and action boundary.

Systems and capabilities involved

  • Service dependency and health graph

  • Approved recovery runbooks

  • Guarded operations executor

  • Business validation agents

Handoffs

What this role gives and receives

Capabilities offered

Coordinate service recovery

Sequence guarded restoration and business validation with rollback checkpoints.

Receives:
Incident state, services, dependencies, runbooks, tolerances and command authority
Returns:
Recovery plan, action state, validation evidence and closure recommendation

Delegates

Recovery Test Evidence Judge

Independently validate usable service, integrity and backlog before closure. Trigger: Technical restoration reaches the business-validation gate Returns: Pass, conditional or fail with exact tolerance evidence.

Delegates

Business Continuity Plan Maintainer

Reconcile temporary continuity steps with the current plan and owner responsibilities. Trigger: Recovery relies on manual or alternate-site processing Returns: Current procedure, resource owners and untested assumptions.

External handoff

Incident commander

External handoff

Technology recovery

External handoff

Business service owner

External handoff

Customer operations

Context

What the role needs to do the work

Current work
Recovery objective, dependency state, actions, validation gates and rollback points.
Prior interactions
Prior recoveries, failed sequences, data-integrity defects and customer impacts.
Policies and reference
Service dependencies, runbooks, tolerances and validation standards.
Working method
Recovery order, dual control, rollback and closure rules.

Illustrative workflow

How the work moves

Starting point

The crisis commander authorizes recovery after a regional outage.

  1. 01

    Build the dependency order, guarded actions, rollback points and business checks.

  2. 02

    Execute approved restoration stages and collect integrity and customer evidence.

  3. 03

    Commission independent review by the recovery-test judge before recommending closure.

Result

Service restored with validated integrity, remaining backlog and a controlled closure recommendation.

Checks and boundaries

What must be tested or reviewed

  1. 01Blocks downstream payment release until identity, ledger integrity and reconciliation gates pass.
  2. 02Rolls back a restoration step when validation fails instead of pushing toward a cosmetic green status.
  3. 03Keeps technical recovery separate from customer backlog clearance and incident closure.

Human authority

  • Commander authorizes recovery phase
  • Business owner validates service
  • Commander closes incident

Keep exploring