Endpoint lost or offline
Use scoped snapshot browse and single-file download from a clean browser. The stored-data path does not contact the original endpoint.
ARIVARAN TWIN · PLANNED RECOVERY DIRECTION
Planned direction: open a live, browser-accessible digital twin when the original endpoint is unavailable. Available today: authenticated, role- and organization-scoped browsing of a completed snapshot, with single-file download. Where policy grants it, the assigned owner of an endpoint can browse their own stored files and download one at a time from a clean browser. Booting a full Twin, restoring to another endpoint, and an owner restoring files to the original endpoint are not available yet.
Planned outcome: no restore queue. No administrator wait.
The diagram shows the mechanism, its current result, and the limit that remains in force.
Step 1 of 3Catalog plus immutable block identity
The browser resolves a stored file through its catalog and verified block references without treating the source device as the recovery path.
Step 2 of 3Browser file recovery
Authorized users can inspect stored snapshots and recover a selected file when the required snapshot and blocks exist.
Step 3 of 3Limits
File browse and download do not prove a bootable Twin, in-place restore, standby, or migration outcome.
The browser resolves a stored file through its catalog and verified block references without treating the source device as the recovery path.
Agent, filesystem, and restore coverage vary by platform and must be checked before deployment.
File browse and download do not prove a bootable Twin, in-place restore, standby, or migration outcome.
A completed enrollment, a finished snapshot, a stored catalog and blocks, and authorization for the signed-in user.
Evidence reviewed 2026-08-26
Verified path
The original endpoint can be offline because browsing and file reassembly use the stored catalog and content blocks. Access still depends on a valid identity, role, tenant, and organization scope.
Three supported beats end at a single-file browser download. No in-place restore is depicted.
Step 1/3Store a recovery point
An enrolled endpoint must complete a snapshot with a persisted file catalog.
Step 2/3Browse the snapshot
A signed-in role with file browse permission can open the stored catalog inside its tenant and organization scope.
Step 3/3Download one file
A role with file download permission can reassemble one stored file in the browser.
Outcome matrix
Availability belongs to each outcome, not to Twin as one broad promise. Every available row carries its access and data conditions.
| Outcome | Status | Condition |
|---|---|---|
| See only assigned endpoints | Available | Available for an assigned user with a trusted sign-in and a non-admin role that policy grants recovery. They can open, browse, and download from only the endpoints assigned to them; another user's endpoint is refused. |
| Browse stored files | Available | Available after a completed snapshot with a persisted catalog, for roles with file browse permission inside their tenant and organization scope. |
| Download one file | Available | Available for roles with file download permission when the snapshot and stored content blocks are accessible. Folder and whole-snapshot export are not included. |
| Restore to the original endpoint | Unavailable | Not part of owner self-service. An administrator with restore permission can send a restore from the dashboard to the original endpoint while it is enrolled and online. That administrator path is in beta: the files land in a new restore folder, never over the files in use. |
| Original endpoint lost or offline | Available | Stored browse and single-file download remain available under the same access conditions. This does not make in-place restore possible. |
| Identity compromised | Unavailable | Unavailable as a bypass. Recover or revoke the identity through the configured identity provider or an authorized administrator first. |
| Restore to another endpoint | Unavailable | Unavailable. A different target is not dispatched by the current dashboard restore request. |
| Boot a full Twin | Planned | Planned. No bootable endpoint replica is marketed as generally available. |
| Owner policy and audit proof | Available | Available for file browse and single-file download. Each allowed download and each refused request is kept as a durable record of who asked, for which endpoint, and the decision, without file content. |
Recovery boundaries
Twin can recover stored data only after identity and authorization succeed. Losing a device does not weaken those checks.
Use scoped snapshot browse and single-file download from a clean browser. The stored-data path does not contact the original endpoint.
Twin does not bypass sign-in, revocation, or administrator controls. Recover the identity before requesting data.
Restore to another endpoint and full boot are not available yet. Owner self-service is limited to browsing files and downloading one file at a time from an assigned endpoint.