Back to all posts

Vault is not a backup

Retention, holds and discovery are not the same capability as recovery, and the difference only becomes visible on the day somebody needs the second one.

Slavi Georgiev. August 2026.

The request arrives roughly once a year, usually from someone senior, usually urgent. A shared drive has been reorganised, or a folder is gone, or a departed employee tidied up on their way out. The question is always the same shape: can you restore it to how it looked on Tuesday. And the answer people expect is yes, because the company pays for Vault, and Vault is the thing that keeps data.

It is worth being able to answer this precisely and quickly, because the alternative is discovering the limits during the incident.

What Vault is for

Vault does three things, and they are all in service of one purpose, which is producing evidence.

Read that list again with recovery in mind. Nothing in it puts anything back.

Why it cannot do the thing being asked

The gap is not a missing button. It is structural.

Export is not restore. Vault gives you files, out of the environment, in an export format. Getting them back into the right shared drive, in the right folders, with the right permissions and the original owners, is manual work that nobody has scoped. For one file that is fine. For a reorganised department it is a project.

There is no point in time to go back to. Vault holds versions of items, not a snapshot of how the workspace was arranged. "How it looked on Tuesday" is a statement about structure, sharing and location, and that is not what is being retained.

Deletion by a user is not what Vault is defending against. Retention and holds stop data being purged. They do not stop the day to day mess of somebody moving four hundred files into a folder nobody can find.

It is scoped to particular services. Vault covers a defined set of Workspace services. If the thing that was lost lives outside that set, Vault was never going to be part of the answer, and confirming which services are covered is a five minute job you want to have done before the call rather than during it.

What actually recovers data, in order

When the request comes in, work down this list rather than starting at Vault.

  1. The user's own trash and version history. A surprising share of these incidents end here, in under a minute. Drive keeps previous versions of a file, and a document that was overwritten rather than deleted is often recoverable by the person who owns it without you touching anything.
  2. The admin restore path. An administrator can restore items a user deleted, and a deleted user's data, but only inside a limited window measured in days, and it is shorter than people assume. Know your edition's actual numbers now, because the window is usually the reason a recovery fails and the numbers are not something to look up while somebody waits on the phone.
  3. Shared drive membership and audit logs. Often the data is not gone at all, it moved, and the Drive log tells you where and who moved it. Restoring an ownership or a location is far cheaper than restoring content.
  4. A third-party backup product, if the company bought one. This is the tool that does point in time restore back into place, and it is a separate purchase from Vault because it is a separate capability.
  5. Vault, last, and only when the requirement is really evidence rather than working files.

The conversation to have before you need it

The useful version of this is not a correction in the middle of an incident. It is a decision made in advance, by the people who own the risk.

Put it to them as a question with a cost attached: if a shared drive is lost or maliciously wiped, what is the recovery expectation, and is it funded? There are only two honest answers. Either the business accepts that recovery is limited to the admin restore window and version history, which is free and genuinely covers most real incidents, or it wants true point in time restore, which means buying a backup product. Both are defensible. What is not defensible is assuming the second while paying for the first.

Get that answered in writing once and the annual conversation stops being an argument about what Vault does and becomes a reference to a decision somebody already made.

The short version

Vault is retention, legal hold and discovery. Holds override retention, which is what makes it work for litigation. It exports rather than restores, it has no notion of a point in time, and it covers a defined set of services. Recovery comes from version history, the admin restore window, the audit log, or a backup product bought for the purpose. If someone in the business believes Vault is the backup, the fix is a funded decision rather than a better explanation.

Next What a leaver's account costs Keeping departed staff's data means paying for accounts nobody uses. How to decide the retention period per person, and what it takes to actually get back into one.

Written from administering Google Workspace from 2016 to 2025, six of those years as Super Admin for 500+ staff across five global offices. More on the blog, which is searchable by term, and there are 95 questions with worked answers if you are preparing for an interview.