Skip to main content
When an agent deletes or overwrites something through Passport, Passport first saves what’s about to go, where it can. The action’s row then says Backup taken, and for 7 days you can Undo it from the session, Activity, or Home, from the terminal, or by asking your agent. Passport only backs up actions it can see: app tools, the production toolkit, and passport exec. A command an agent runs with a key on your computer gets no backup, which is one reason to move your keys into Passport.

What Passport backs up

Not backed up: Railway volume, service, and environment deletes (Railway removes a volume’s backups with it and can’t restore the others), Neon branch deletes and resets, Supabase branch deletes and resets, and schema changes on Supabase. Irreversible actions never get a backup, because they can’t be taken back even with one. Variable values and table rows are encrypted and deleted after 7 days. Branches Passport made on Neon are removed after 7 days (Neon also expires them on its own), or as soon as you undo. Neon won’t delete or reset a branch that has backups under it, so when you delete or reset one, Passport removes its own backups of that branch first and the action’s row says how many.

How backups change decisions

  • Hands-off: a delete runs only once its backup is taken. If Passport can’t take one, it asks you instead: “Couldn’t take a backup first, so Passport is asking.” To let Hands-off deletes run without a backup in Development, Staging, or Other apps, turn on Run deletes without a backup for that row in Rules. It’s off by default, and it isn’t offered for Production.
  • Careful and Balanced: deletes ask as before. The request says whether Passport will take a backup right before it runs.
  • An exception that always runs an action, or an approval for the session, runs it even when no backup was possible. Its row says No backup.

Undo

Undo first shows what comes back, what won’t, and how old the backup is. Some things never come back: notifications and webhooks already sent, and anything other systems did because of the change. If the thing changed again since, a plain restore would overwrite that change, so Passport offers a safe alternative instead where there is one, such as restoring a file as a copy, a variable under a new name, rows into a new table, or a Neon backup as a new branch. Undo isn’t available once the backup is 7 days old, while someone else is undoing it, or if you can’t reach the app (connect it in Passport first). You can undo your own actions and those of agents you own; workspace admins can undo anyone’s, with their own connection. An undo is an action too: its row says Undone by you and links to what it undid, and most undos can be undone again. From the terminal:
Agents can call passport_undo. An undo from the terminal or an agent is decided like a change in that environment, so in Production it asks you first. When your team needs someone else to approve Production deletes, the undo of a Production delete goes to them too, whether you start it in Passport, the terminal, or an agent. Undo again once they approve. See Slack and Production approvers.