Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Capture and restore a company test configuration. Capture supported settings, send an encrypted operation to a separately provisioned company Dev or QA target, read back its receipt, and restore the previous configuration if necessary. This is not a full production clone. Current availability: Configuration transfer and recovery implemented; hosting allocation and customer acceptance required. Before you start. An active paid Company Workspace and a verified administrator with environment-management permission. TLS owner verification is required to register a hosting target or record a received payment. A separate company deployment using the reviewed application release, its own database and object bucket, a unique vault key and the intended private hosting audience. Never reuse the shared TLS Development or QA projects. Professional includes limited clean Dev for five test users; Enterprise includes ten. Separately purchased QA or Dev requires an actual received-payment record with an expiry. Recording that receipt does not create a charge. Step 1. Open Licenses & billing > Company environments and request the intended Development or QA hostname. Under Configuration replicas & recovery, choose the same requested environment. The request alone does not allocate infrastructure. Step 2. TLS provisions the separate hosting project, database and bucket, publishes the exact reviewed code and applies its additive migrations. Record the project ID, actual published source commit and infrastructure binding identities in the protected acceptance record. Unattended hosting allocation is not implemented. Step 3. In that target’s protected runtime settings, set CONNECT_ENVIRONMENT to development or qa, CONNECT_REPLICA_TARGET_ID to the source environment record ID, CONNECT_REPLICA_ORGANIZATION_ID to the exact company ID, and CONNECT_REPLICA_SOURCE_COMMIT to the verified 40-character deployed source commit. Generate a unique 32-byte random import key as 64 lowercase hexadecimal characters for CONNECT_REPLICA_IMPORT_KEY. Set a distinct INTEGRATION_VAULT_KEY. Never put keys in chat, source or a tutorial. Step 4. The TLS owner opens Register an isolated target in production. Enter the target native HTTPS URL, hosting project ID, deployed source commit and import key. Enter the authorized private hosting connection token if the target requires one. Verify and save target performs an encrypted identity probe and rejects the shared TLS targets, another company or a reused production vault key. Database and bucket IDs still need independent review. Step 5. Review target scope and confirm replacement of the supported test configuration. Choose Capture and queue configuration. QA includes portal title, welcome text, time zone and accent; connector definitions arrive disabled. User roles, groups and delegations are retained only as anonymous test fixtures. They do not create accounts, sign-in federation or access grants. Clean Dev starts with default text and no production connector or permission fixtures. Step 6. Choose Run now, or allow a separately verified hosting schedule to process queued jobs. Status progresses through queued, transferring, verifying and validated. The immutable encrypted operation has a two-hour execution window and at most three attempts. Two hours is an expiry limit, not a guaranteed build time. Only one active operation is allowed per environment. Step 7. A validated job means its target returned the matching operation digest, current job ID and revision. It does not mark the whole environment ready. Complete isolated identity, custom DNS/HTTPS, real workflow, capacity and external-action acceptance separately. Registered replica targets always suppress production external actions, even if the general test override is enabled. Step 8. If a transfer fails or its response is lost, inspect the status, then Retry the same operation while it remains eligible. The exact operation reference is retained and an already applied operation is not applied again. After expiry, a changed target connection or three attempts, inspect the actual target before capturing a replacement. Step 9. To undo the current import, open Roll back the latest import, confirm the selected test target and queue the rollback. Run and verify it. The encrypted before-image restores the replicated settings and connectors. It does not restore customer content, a hosting deployment, user accounts, MFA or passwords; those records are outside the transfer. Now verify the result. Verify distinct database and bucket binding IDs, keys and the intended audience; record these independently of the target probe. Keep a redacted company/environment/source/operation receipt. Exercise failed transfers, lost responses, retries and rollback with synthetic records. Confirm authentication factors, recovery codes and vault entries remain unchanged. Production data is not mutated. A concurrent target settings change must reject the import instead of silently overwriting that edit. The current schema supports up to 1,000 anonymous identities, 100 groups, 100 connector definitions and 2,000 delegations, within a 750 KB configuration payload. Larger captures fail; they are not truncated or described as complete. If you get stuck. Target setup required: complete isolated hosting and protected keys before queuing an operation. HTTP 401/403 or unreachable target: verify the approved private hosting token, import key and native URL in protected configuration. Do not make the site public to bypass an authentication failure. Another active job or changed target: wait for completion, retry an eligible failed job, or review the target after expiry before registering a new connection. Target rotation is blocked while a job is active. Incomplete replica scope: tickets, files, knowledge bodies, device agents, provider secrets, identity links, payment data, MFA, passwords and logo bytes are excluded. Names and emails in structured identity fields are removed; administrators must still review free-text portal and group settings for sensitive content. Recovery artifacts are retained until authorized infrastructure cleanup under the agreed retention policy. Keep encryption keys while retained backups are needed; automatic artifact deletion is not implemented. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.