Home / Tools / Infrastructure Decision Frameworks / Transition Recovery Window

Infrastructure decision framework

Transition Recovery Window

Check which recovery methods remain available after the next change, and whether they can restore service before the deadline.

The next step can change the recovery you have

A migration step uses time and may remove the configuration you would need to roll back. A recovery that was possible before the step may be unavailable afterwards. Assess the method you could actually use from each state, including the checks needed to confirm that restored service meets the operating requirement.

Compare recovery before and after the step

Measure decision time and the service deadline from the same starting point. Add the executable recovery duration to the decision time to find the recovery finish. Subtract that finish from the deadline, then deduct the chosen contingency allowance. Check resources, evidence, permission and operating restrictions alongside the timing result.

At minute 240, 90-minute rollback leaves 30 minutes. At minute 255, 150-minute forward recovery exceeds the minute-360 deadline by 45 minutes.

Illustrative example.

Removing rollback changes a spare margin into an overrun

In the illustrative six-hour window, rollback at minute 240 takes 90 minutes and finishes at minute 330.

A further 15-minute migration removes rollback. Forward recovery from minute 255 takes 150 minutes and would finish at minute 405. A revised sequence keeps 90-minute rollback executable, leaving a smaller positive margin.

Illustrative service deadline: minute 360. The 15-minute positive margin is neither an approved contingency allowance nor permission to proceed.
Decision state Executable recovery Finish Margin before allowance
Minute 240, rollback retained 90 minutes Minute 330 +30 minutes
Minute 255, rollback removed 150 minutes Minute 405 −45 minutes
Minute 255, revised sequence retains rollback 90 minutes Minute 345 +15 minutes

Check recovery at each step

Use the method for cutovers, migrations and interventions with a fixed service-return requirement. For each step, confirm which recovery methods remain possible and what people, equipment, access and verification they need.

What you bring

Required service and return time; elapsed time at each decision; recovery destination, sequence and duration; chosen allowance; resources, procedure evidence, permission and stop triggers.

What the comparison provides

Recovery finish, latest start and remaining margin for each available method, with unmet prerequisites and the decision authority visible.

A positive margin supports only the timing assessment

Confirm the method against the actual configuration and operation. The example prescribes no universal buffer. Unknown recovery duration needs investigation; lost rollback is unavailable, not zero-duration recovery. Use a detailed schedule for parallel work or competing resources, and keep technical, operational and other applicable approvals separate.

Apply the framework

Compare the recovery available after the next change with the deadline for restoring service.

When another framework helps

Integration Dependency and Evidence Map

When evidence, configuration or permission for the proposed state remains unresolved.

Delivery System Architecture

When recovery depends on a sequence involving several parties or shared resources.

Discuss your next irreversible change

Tell us which change comes next, when service must return and what recovery remains possible afterwards.