How to use back-up and restore
ISOPlanner keeps a change history of your data, so you can put your organization back the way it was at an earlier moment: after a bulk edit that went wrong, an import that produced the wrong result, a deletion nobody intended, or simply to look up what a risk assessment said three weeks ago. You can restore into a new organizational unit to inspect the old state next to the current one, or restore over the current data.
- The feature is currently in preview: if the Backups tab is not there while your subscription and role are in order, ask ISOPlanner support to enable it for your organization.
- Not all features and backup-windows are available for all subscriptions yet.
In short: every change to your data is written to a change history that is kept for a fixed number of days - the history window. Any moment inside that window can be restored, whether or not you prepared anything. A backup is a named marker on such a moment: it is created instantly and costs nothing, and it exists so you can find the moment back by name. A pinned backup additionally keeps a copy of the data, so it survives after the history window has moved past it and you can open and read it. Restoring is done in two ways: Restore as new organizational unit leaves your current data untouched, and Overwrite current organization replaces it - locking the organization while it runs, and taking a safety backup of the current state first.
Before you start
- You need the administrator role. The page is at Admin > Company > Backups. A manager or a normal user does not see the tab and cannot start a restore.
- Backups and restores always concern one organizational unit - the one you are working in. Parent and child units are never read and never changed, and other organizations are never affected.
- The history window is shown on the page, together with the earliest restorable moment. Everything older than that window is gone unless you pinned a backup of it, so pin the moments you may need months from now.
- The contents of files stored in SharePoint are not part of a backup: only what ISOPlanner itself keeps about a document is. SharePoint has its own recycle bin and version history for the files.
- One backup or restore at a time. While something is running, the other commands are switched off and the page says a backup or restore is running.
- An overwrite restore is an interruption for everyone: the organization is locked while it runs and nobody can work in it. The dialog lists the users who were active in the last hour, so you can warn them first.
1. How the history and the backups relate
The history window
ISOPlanner records every change to your data as it happens and keeps those records for a fixed number of days. That period is the history window, and the stats box at the top of the page shows it together with the earliest moment you can still restore. The window moves along with time: the oldest day drops off as a new one is added.
Because the history is kept for every moment inside the window, you do not have to prepare anything to be able to go back. Restore to a moment works even if you never created a backup.
A backup marks a moment
Use New backup before you start something you may want to undo - a bulk import, a large re-classification, the yearly review. The backup is ready the instant you create it, because nothing is copied: it records the moment and the name you gave it, and the change history does the rest. Creating backups therefore costs no storage and no waiting time, and you can create as many as you like.
A backup disappears by itself once its moment falls outside the history window - the Kept until column says when that happens. From that point on the moment can no longer be restored.
A pinned backup keeps its data
Pin a backup and ISOPlanner makes a real copy of your organization as it was at that moment. A pinned backup is not deleted automatically, stays restorable after the history window has moved past it, and is the only kind you can view. Pinning takes a while - the status goes from Pending through Creating to Ready - and you can keep five pinned backups. Delete one to make room for another.
Use pinning for the moments that have a meaning of their own: the state at the certification audit, the state at the end of the year, the state before a migration.
2. The Backups page
The stats box shows the History window, the Earliest restorable moment, the number of Backups saved, the number of Pinned backups and the Last backup. Below it, the list holds one row per backup.
| Column | What it shows |
|---|---|
| Moment | The moment the backup stands for. This is what a restore returns your data to. |
| Name | The name you gave it, or the name ISOPlanner generated. |
| Type | Manual - you created it. Before restore - the safety backup ISOPlanner takes automatically before an overwrite restore. Moment - the moment you picked in Restore to a moment. |
| Status | See the status table at the end of this article. A Ready status with a warning colour means the backup is restorable but something else did not work out; hover it for the message. |
| Created by | Who created the backup, or ISOPlanner itself for a safety backup. |
| Kept until | When the backup drops out of the history window, or Pinned when it does not. The time is an hour earlier in the day than the moment itself: ISOPlanner lets a backup go one hour before its moment is as old as the history window, so a restore never runs into history the database is about to clean up. |
| Contents | How many items the backup holds. Hover it for the count per kind - tasks, risks, controls, requirements, standards, objectives, processes, assets, KPIs, categories, library items, forms and processing activities. Other kinds of items are in the backup too; they are simply not listed here. |
Below the list, Restore history records every restore that was requested for this organizational unit: when, by whom, in which mode, its status, the step it is on and the error if it failed. Refresh re-reads both lists; while a backup or restore is being processed the page refreshes itself every few seconds.
3. Create a backup
Choose New backup, give it a Name you will recognise later ("before ISO 27001 import"), and confirm with Create. The backup appears in the list as Ready straight away.
New backup is switched off while a backup or restore is running, and when the change history is not available (see the troubleshooting section).
4. Pin, view and delete a backup
Select a row and use the Backup menu in the command bar.
| Command | What it does |
|---|---|
| View the contents of this backup | Opens the backup as if it were an organizational unit, read-only. Only available for a pinned backup that is Ready. |
| Pin | Keeps this backup beyond the history window and makes it viewable. Takes a few minutes; the status follows along. The command is switched off when the backup is already pinned, when another backup or restore is running, and when the five pinned backups are used up. |
| Restore | Starts a restore from this backup - see the next step. |
| Delete | Removes the backup. Ask yourself first whether you may still need the moment: after deleting, it can only be reached through Restore to a moment, and only while it is inside the history window. |
Viewing a backup
Viewing switches you into the backup the way you switch to another organizational unit: the whole application is there, filled with the data as it was at that moment. A banner at the top says you are viewing a backup, the data is read-only, and nothing you do in it is saved. Use Leave backup to come back to the organizational unit you started from.
This is the safe way to answer "what did this look like back then?" and to copy a text or a value out of the past by hand, without touching your live data at all.
5. Restore
There are two ways in: Restore in the Backup menu, for the backup you selected, or Restore to a moment in the command bar, for any moment inside the history window.
Restore to a moment
| Field | What it does |
|---|---|
| Date and Time | The moment to restore to, in your own time zone. All data returns to the state it had at that moment. The picker opens on the latest restorable moment, so move it back to the moment you want. |
| Available | The window you can choose from: from the earliest restorable moment to now. A moment outside it is refused with a message under the picker. |
Choose Next and you land in the same restore dialog a backup takes you to. ISOPlanner also records the moment you picked as a backup of type Moment, so the restore history keeps pointing at something you can find back.
Choose how to restore
The dialog first asks for the mode.
| Mode | What happens |
|---|---|
| Restore as new organizational unit | A new organizational unit is created next to your current one and filled with the data from the backup. Your current data is not touched and nobody is interrupted. Use it to inspect the old state, to compare, or to copy items back by hand. Undo it by deleting the new unit. |
| Overwrite current organization | The data of the current organizational unit is replaced by the contents of the backup. The organization is locked while it runs and a safety backup of the current state is created first. Use it when the current state is wrong and the old one is right. |
Next then asks for the details of the mode you chose, and a final confirmation follows before anything happens. Back takes you to the mode choice again.
Restore as a new organizational unit
You only give the Name of the new organizational unit; a name with the original unit and the date is proposed. The unit is created, filled and then simply there, in your organizational unit switcher, for everyone who is authorized for it.
Two things are deliberately different in such a unit. Its items are new items, so links you saved to the originals - a bookmark to a risk, a Planner task, a calendar item - keep pointing at the originals in the live unit and not at the copies. And it starts without the integration connections of the original: the copy does not talk to Microsoft 365, Planner or any other connected system, which is what keeps an inspection copy from sending mail or writing tasks a second time. Connect what you need if you decide to keep the unit.
Overwrite the current organization
The dialog states what you are about to do and lists the users who were active in the last hour and will be interrupted. It also names three things that are worth knowing before you confirm:
- Settings that apply to all organizational units - such as the Outlook add-in, user synchronization and the risk matrix - and the Planner configuration are restored for this unit only, and can therefore differ from the other units until they are saved again.
- Integrations return to the state they had at the moment of the backup and start running again on their own schedule. If the integration subscription changed in the meantime, the difference is detected automatically and reviewed by support.
- Links between controls of different organizational units that point to controls created after this backup are removed - the control on the other side does not exist at this moment.
What an overwrite restore does not break is your links: the restored items keep their own identity, so deep links, Planner tasks, calendar items and everything else that refers to an item keep working.
While the restore runs
The Backups page shows the progress with the step it is on and reloads itself when the restore is finished. Everyone else in the organization is told their organization's data is being restored and can come back in a few minutes. The steps are:
| Step | What happens |
|---|---|
| Locking organization | Nobody can work in the organization from here on, so nothing changes underneath the restore. |
| Creating safety backup | A backup of type Before restore is created for the state you are leaving. This is your way back. |
| Removing current data | The current data of this organizational unit is removed. |
| Copying data | The data from the backup is written back, item by item, keeping every item's identity. |
| Reconciling | Derived data such as the search index is rebuilt, integrations are picked up again and expired trials are closed off. |
| Unlocking organization | The organization is released and everyone can work again. |
Refreshing or closing the page does not affect the restore; it continues on the server and the page picks the progress up again when you come back.
6. What is in a backup, and what is not
Everything ISOPlanner keeps for your organizational unit is in a backup: tasks, events and their answers, risks, controls, requirements, standards, objectives, processes, assets, KPIs and their measurements, categories, library items and their metadata, forms, processing activities, audits, authorization schemas and the settings of the unit. The Contents column names the totals of the most common kinds.
| Not restored | Why, and what happens instead |
|---|---|
| The contents of files in SharePoint | The files live in SharePoint, not in ISOPlanner; only what ISOPlanner knows about a document is restored. Use SharePoint's own recycle bin and version history for the file itself. |
| Users, roles and licenses | Restored additively: a user who was deleted since that moment comes back, but a user who exists now keeps their current name, license and roles, and nobody is removed. Your license count and subscription are never changed by a restore. |
| The name, subscription and billing of the organization | These belong to your contract, not to your data. |
| Personal preferences of a user | They follow the user, not the organizational unit. |
| Notifications and mails | Already sent is sent; a restore does not re-send anything and does not bring queued messages back. |
| Logs, change trails of the platform and AI traces | Restoring old records here would falsify the history of what really happened. |
| Work that was in progress in the background | Synchronizations and other scheduled work are picked up again after the restore rather than replayed. |
Backups and privacy
The change history keeps data you deleted for as long as the history window lasts, which is what makes a restore possible at all. A pinned backup keeps it until you delete that backup. If you have to erase personal data completely and immediately, delete the pinned backups that contain it and ask ISOPlanner support to purge the change history for it.
The statuses at a glance
Backups
| Status | What it means |
|---|---|
| Ready | Restorable. A plain backup is Ready the moment you create it. |
| Pending | You asked to pin it; the copy has not started yet. |
| Creating | The copy of the pinned backup is being made. |
| Deleting | The backup and its copy are being removed. |
| Failed | The copy could not be removed cleanly. The backup keeps its message; contact support if it stays. |
Restores
| Status | What it means |
|---|---|
| Pending | Requested and waiting to start. |
| Running | Busy; the Step column says where it is. |
| Completed | Done. After an overwrite restore the organization is unlocked again. |
| Failed | Stopped with an error, which the row shows. After an overwrite restore the row adds holds the lock: the organization stays locked until a restore succeeds. |
Questions and troubleshooting
New backup and Restore to a moment are greyed out
A backup or restore is running for this organizational unit - the tooltip says so, and you can continue when it has finished. Only one runs at a time on purpose: two at once would work on the same data. The commands are also switched off when your subscription does not include backups, and when the change history is not available.
The moment I want is outside the available history window
It is older than the earliest restorable moment the page shows. The window moves along with time, so a moment can also fall out of it while you are looking at it - refresh and choose a more recent moment. If you pinned a backup of that period, restore it from the list instead: a pinned backup is not bound to the window.
I cannot pin: the maximum has been reached
Five pinned backups is the maximum, and each one holds a full copy of your data. Delete a pinned backup you no longer need and pin the new one. Backups that are not pinned do not count towards the maximum, so you can keep creating those.
View the contents of this backup is greyed out
Only a pinned backup can be viewed, and only when it is Ready - viewing reads the copy, and a backup that is not pinned has none. Pin it first, wait for Ready, then view it.
A backup is Ready but shows a warning
Pinning it did not work out; hover the status for the reason. The backup itself is fine and still restorable - the moment is in the change history either way - so the pin is all that failed. Try pinning again, and contact support if it keeps failing.
My older backups are gone
They fell outside the history window and were removed automatically; the Kept until column announces that in advance. A backup you want to keep longer has to be pinned before it expires.
My colleagues say the application is not available
During an overwrite restore that is exactly right: the organization is locked and everyone gets a message that its data is being restored. Their pages work again after the restore finishes; the Backups page reloads itself and the rest of the application reloads on the next refresh.
A user I deleted is back after the restore
Users are restored additively: someone who existed at the moment of the backup is added back, because a restore that left them out would leave their tasks and their audit trail without an owner. Nobody's current name, license or roles are overwritten, and no user is removed. Delete the user again if you do not want them.
A document has an older name but the file is unchanged
That is the split between ISOPlanner and SharePoint: the metadata ISOPlanner keeps is restored, the file itself lives in SharePoint and stays as it is now. Use the version history in SharePoint to put the file back as well.
What happens to my integrations after an overwrite restore?
They return to the state they had at the moment of the backup and resume on their own schedule, so a synchronization that was switched on then is switched on again. Trials that expired in the meantime are closed off, and a difference with your current integration subscription is picked up automatically and reviewed by support. Check the integration settings once after a restore that goes back a long way.
Does a restore affect other organizational units?
No. A restore reads and writes one organizational unit - the one you started it from. Parent and child units keep their own data. The only thing you may notice elsewhere is described in the overwrite dialog: links from controls in other units to controls that did not yet exist at that moment are removed, and settings shared by all units are restored for this unit only.
I only wanted to look at the old data
Then use Pin and View the contents of this backup, or Restore as new organizational unit - neither touches your current data. A new unit you created for an inspection can simply be deleted when you are done with it.
Can I get the backups of an organization whose subscription changed?
Backups of an organization that is no longer entitled to the feature are kept for another 30 days and then removed. Restore or export what you need inside that period, or contact support before the subscription changes.