After the first run
For operator attention, see Human notifications and migration limits. A retained record does not imply that anyone has been notified.
Use the versioned guide for the profile you actually ran: maude-plan-consultation/v1 in alpha.1, saved-check-attention/v1 in alpha.2, objective-saved-check-read/v1 in alpha.3, connected-cache-c in alpha.4, installed-saved-check/v1 in alpha.5, or reviewed-local-copy/v1 in alpha.6. These are separate scopes; no release implies a full application migration.
Saved checks and local attention
The mutable saved-check attention guide and released alpha.2 snapshot give exact pinned setup, retained state locations, inspection and no-blind-retry rules for the public-only finite example. Its create-only generator is not a restart command. Keep NQ and Nightshift stores, configuration, receipt and inbox records together; restoration, rollback and unattended recurring installation are not qualified.
The alpha.5 profile exercises one installed-cadence tick directly. Preserve its nightshift.sqlite, nq.sqlite and sidecars, state/ticks/, configurations, transcript, inspection JSON and inbox together. Same-slot replay is not a general restart command. An acquisition_started or nq_started summary remains indeterminate; inspect the exact owner records before considering another occurrence. The qualified single-user fixture used NQ's debug-only same-UID helper exception; an installed release build needs its distinct enrolled helper. Response loss after NQ acceptance, systemd activation, live Slack/Discord, human acknowledgment, migration, restore and rollback are not established.
Reviewed governed actions
The alpha.6 reviewed local-copy profile retains its plan store, evidence and currentness records, Nightshift/Foreman occurrence, Switchyard review custody, AG state, Docket state, executor journal, manager checkpoints, exact configuration identities and source/artifact pins as one recovery set. Stop writers before a consistent backup. Restart only the original durable owner and inspect before considering another submission; a stopped process does not settle an attempt. The release does not qualify migration, restore onto changed component revisions, or rollback.
Inspect before you restart
For the released alpha.3 objective saved-check reader, use its wrapper-specific retained-state commands. It temporarily starts Phosphor for each read; it does not install a service. Preserve the plan, exact reader enrollment, nested NQ/Nightshift stores, command transcript and per-read diagnostics. Its create-only caller is not a restart command. The guide distinguishes an unchanged retained result from current evidence and does not claim verified restoration or rollback.
For the consultation profile, keep the exact public revision, kit revision, local store location, and selected draft and revision identifiers together. Select the existing store explicitly and use only maude-plan --read-only list or maude-plan --read-only inspect DRAFT_ID. These commands neither initialize a missing store nor authorize work. Their JSON can report unavailable with exit status 0; parse the schema and availability field. Do not retry a mutating command automatically.
The following design-demo restart material is a separate legacy four-store guide. It is not required by, and does not extend, maude-plan-consultation/v1.
The deterministic generator creates plans.sqlite, presentations.sqlite, proposals.sqlite, and owner-facts.json. Stop its foreground server with Ctrl-C. To restart without regenerating the corpus, run from the same Maude checkout:
PYTHONPATH=src .venv/bin/python -m maude.design.server \
--store /absolute/retained-demo/plans.sqlite \
--presentation-store /absolute/retained-demo/presentations.sqlite \
--proposal-store /absolute/retained-demo/proposals.sqlite \
--owner-facts /absolute/retained-demo/owner-facts.json \
--port 8427
Open http://127.0.0.1:8427/phosphor/design. Use the exact retained directory you originally supplied to scripts/run-phosphor-design-demo.sh; do not rerun that generator over it. If the four inputs no longer agree, preserve them and use a new absent directory for a separate exercise.
Legacy design-demo configuration, credentials, and ownership
The deterministic fixture route needs no model-provider credential. The optional enrolled-provider route has a separate caller-owned credential file and budget; creating or starting that route does not authorize a provider call. Keep credentials out of commands copied into notes, shell history shared with others, logs, and issue reports.
Assign one local owner for the four-file set, relevant server log, configuration record, and any SQLite sidecars (-wal and -shm). Record the exact source revision, Python environment, command, port, paths, and relevant plan/check/lock/proposal identifiers. Do not treat a source checkout, browser tab, or generated fixture as a shared service.
Legacy design-demo stop, restart, and uncertain attempts
Stop the foreground walkthrough with Ctrl-C, then retain the four inputs and sidecars if they contain records you may need. Restarting this authoring UI does not establish that a governed attempt stopped or settled. Where a separate connected governed attempt has an uncertain outcome, use that runtime's documented same-attempt reconciliation; do not repeat work merely because a client was interrupted.
Inspect or stop the connected cache alpha
The alpha.4 release guide and pinned Maude cache operations guide identify the state owners and give checked inspection commands, manager limits, and the next step after interruption. The clean public-only newcomer and two pre-effect refusal cases passed. A stopped process does not settle an attempt. The driver has no automatic resume, and cross-owner restore, migration, rollback, and interrupted-effect recovery are not verified.
Read saved checks from a historical archive
NQ's verified historical-read procedure preserves one compatible store and its exact verifier. Use a separate inspection configuration pointing to the archived database; its sealed configuration still names the original source. A separately pinned archiver checks saved-check, maintenance and notification histories and was verified against a copy of the profile's populated store. Five inspection commands returned matching results without changing the archive. This does not upgrade the alpha.2/3 writer, amend frozen manifests, retrofit older archives, or establish restoration or rollback. Rollover is operator-controlled: use the documented rollover procedure to create and record the archive location before read-only inspection.
Legacy design-demo back up and restore deliberately
Cross-store backup, restore, migration, and rollback for this four-file set have not been verified as a lifecycle procedure. Do not describe a file copy as a qualified backup. If preserving diagnostic material, first stop the writer and retain all four inputs, applicable SQLite sidecars, source revision, environment, and command together. Test any proposed restore only on a separate disposable copy.
No public compatibility or migration promise exists for these authoring stores. Preserve the original bytes and coordinates rather than inventing an upgrade or rollback path.
Retain evidence; clean up disposable exercises
A fresh walkthrough corpus is disposable only after you decide that its drafts, checks, proposal dispositions, and logs have no replay or diagnosis value. Retain records for an interrupted or uncertain exercise until their state is understood. Remove only the local disposable directory you selected, never an unreviewed shared store or another operator's workspace.
Worked operational example: governed cleanup
One unfinished demo left four disposable containers and a network behind. A governed cleanup inspected their current condition, authorized that exact cleanup, let Docket execute it, and then checked that the named resources were absent. Source and records stayed retained.
This is evidence about that cleanup and its recovery boundary, not a public Recipe C or reproducible installation. Its standing was an explicitly named synthetic substitution. It does not authorize reuse of a prior occurrence or make a production cleanup command safe to copy. For any new cleanup, select a fresh target, retain the inspection and terminal record, and use the component's documented authority boundary.
For symptoms and a minimal support report, use the troubleshooting guide. For source detail, use Maude's design-server guide at the documented public revision. For initial setup, return to Start with the source.