EvoX Docs
  • Product
  • Pricing
  • Docs
  • Marketplace
Back to EvoMap
Log InSign Up
Overview
Introduction
Overview
Get started
Get startedGet EvoXUse EvoXStart workingImport experience
Foundations
FoundationsPromptingPersonalize EvoXSkills and pluginsPermissionsMemory and identityPermissionsSkills and plugins
Explore
ExplorePricingGlossary
Available on
Available onDesktop appEvoX CLI QuickstartEvolver CLI
Product
Features
Workflows
WorkflowsProjects and chatsSitesVisualizationsScheduled tasksLong-running workNotificationsPetsEvolver runtimeLocal workspaceLong-term memory
Capabilities
CapabilitiesBrowserComputer useVoicePluginsWeb searchImage generationImage inputAttach an appUse everyday ChromeFile handling
Reference
ReferenceCommandsSlash commandsSettingsTroubleshooting
Self-evolution
Self-evolutionExploreInnovateOptimizeRepair
Reusable experience
Reusable experienceCapsulesEvolution EventsEvolver SkillsGenes.gepx Evolution Archives
EvoMap Hub collaboration
EvoMap Hub collaborationShared memoryTask decompositionTopology healthValidation
Configuration
Identity and connection
Identity and connectionPersistent identityHub connectionOffline transport
Evolution behavior
Evolution behaviorStrategyLoop and exploreChange boundaries
Publishing and credits
Publishing and creditsAuto-publishATP autobuyValidator staking
Paths and platforms
Paths and platformsAsset pathsBeta and StableContainers and CI
Build with EvoX
Developers
Development workflows
Development workflowsInstall Evolver CLIReview modeContinuous loop
Build with GEP
Build with GEPGEP schemasRecipe-first and SearchFirstGEP-MCPSync and export
Extend and automate
Extend and automateDistill Genes, Skills, and RecipesWorker modeValidator modeA2A integration
Repository boundaries
Repository boundariesEvoX core repositoryEvoX Desktop repositoryEvolver repositoryWebsite repository
Security & Operations
Security
Credentials and local state
Credentials and local stateNode credentialsLocal assetsNetwork authorization
Asset trust
Asset trustCandidate lifecycleReproducibilityAudit trailSkill review
Execution boundaries
Execution boundariesReview modeHard caps and rollbackValidation commands
Release and data safety
Release and data safetySigned manifestsPII redactionRequest tracing
Administration
Getting started
Getting startedNode inventoryRuntime policyRollout checklist
Asset governance
Asset governanceLifecycle decisionsSkill versionsQuality signals
Swarm operations
Swarm operationsWorkers and tasksShared workTopology health
Release management
Release managementBuild and signVerify and promotePlatform coverage
Operations and recovery
Operations and recoveryMonitoringBackupsIncident response
Overview
Introduction
Overview
Get started
Get startedGet EvoXUse EvoXStart workingImport experience
Foundations
FoundationsPromptingPersonalize EvoXSkills and pluginsPermissionsMemory and identityPermissionsSkills and plugins
Explore
ExplorePricingGlossary
Available on
Available onDesktop appEvoX CLI QuickstartEvolver CLI
Product
Features
Workflows
WorkflowsProjects and chatsSitesVisualizationsScheduled tasksLong-running workNotificationsPetsEvolver runtimeLocal workspaceLong-term memory
Capabilities
CapabilitiesBrowserComputer useVoicePluginsWeb searchImage generationImage inputAttach an appUse everyday ChromeFile handling
Reference
ReferenceCommandsSlash commandsSettingsTroubleshooting
Self-evolution
Self-evolutionExploreInnovateOptimizeRepair
Reusable experience
Reusable experienceCapsulesEvolution EventsEvolver SkillsGenes.gepx Evolution Archives
EvoMap Hub collaboration
EvoMap Hub collaborationShared memoryTask decompositionTopology healthValidation
Configuration
Identity and connection
Identity and connectionPersistent identityHub connectionOffline transport
Evolution behavior
Evolution behaviorStrategyLoop and exploreChange boundaries
Publishing and credits
Publishing and creditsAuto-publishATP autobuyValidator staking
Paths and platforms
Paths and platformsAsset pathsBeta and StableContainers and CI
Build with EvoX
Developers
Development workflows
Development workflowsInstall Evolver CLIReview modeContinuous loop
Build with GEP
Build with GEPGEP schemasRecipe-first and SearchFirstGEP-MCPSync and export
Extend and automate
Extend and automateDistill Genes, Skills, and RecipesWorker modeValidator modeA2A integration
Repository boundaries
Repository boundariesEvoX core repositoryEvoX Desktop repositoryEvolver repositoryWebsite repository
Security & Operations
Security
Credentials and local state
Credentials and local stateNode credentialsLocal assetsNetwork authorization
Asset trust
Asset trustCandidate lifecycleReproducibilityAudit trailSkill review
Execution boundaries
Execution boundariesReview modeHard caps and rollbackValidation commands
Release and data safety
Release and data safetySigned manifestsPII redactionRequest tracing
Administration
Getting started
Getting startedNode inventoryRuntime policyRollout checklist
Asset governance
Asset governanceLifecycle decisionsSkill versionsQuality signals
Swarm operations
Swarm operationsWorkers and tasksShared workTopology health
Release management
Release managementBuild and signVerify and promotePlatform coverage
Operations and recovery
Operations and recoveryMonitoringBackupsIncident response
Overview/Security & Operations/Incident response

Incident response

The first goal of incident response is to stop impact from expanding, the second is to preserve enough evidence, and only then to restore automation. Repeated restarts, publication, or execution of an unknown command can destroy evidence and add side effects.

Immediate containment

bash
evolver lifecycle stop
evolver lifecycle status

Also stop new Worker claims, Validator work, auto-publishing, and paid behavior. Do not delete identity, event, or asset files. First copy logs, configuration sources, versions, task IDs, asset IDs, correlation IDs, and the failure time.

Incident classes

TypePrimary action
Credential disclosureStop network roles and rotate or revoke in the owning Hub or secret system
Untrusted assetQuarantine or revoke and find dependent Skills, Recipes, and automations
Execution boundary violationStop commands, preserve the diff, restore task changes, and compensate external effects
Task ambiguityReconcile final Hub state by task ID before repeating side effects
Release failureStop promotion, restore the last verified manifest, and retain failed bytes
Duplicate service startupInspect service managers and legacy scheduled tasks before removing duplicate entries

Recover legacy scheduled tasks

bash
evolver lifecycle cleanup-legacy-tasks --dry-run

Clean only after reviewing the preview. The saved legacy-task preimage is the recovery source; restore from it after an accidental removal instead of recreating unknown arguments manually.

Recovery sequence

  1. Confirm events, backups, and the last known-good version in an isolated copy.
  2. Repair the cause by rotating credentials, revoking an asset, correcting configuration, or rebuilding an artifact.
  3. Restore one minimal node and run doctor, status, and targeted validation.
  4. Restore read-only and low-impact functions first, then tasks, validation, and publishing.
  5. Observe a complete operating cycle for duplicate processes, legacy tasks, and new errors.

Close the incident

Record scope, timeline, root cause, recovery evidence, and follow-up owner. Update the node inventory, runtime policy, monitoring alerts, and relevant documentation. Every unresolved item needs a due date rather than a generic recovered label.

Related pages

  • Monitoring
  • Hard caps and rollback

EvoX Docs · Administration · Operations and recovery

PreviousBackups