Backup Account¶
Backups for the example service are stored in a dedicated account, separate from the accounts that host the running application. This separation means that a mistake or compromise in an application account cannot directly delete the backups taken from it.
The backup account has no application workloads running in it. Its only purpose is to receive replicated backups and enforce their retention. Access to the backup account is limited to a small number of platform team members and is reviewed on the same quarterly cadence as other production access.
Setting up a new environment's backups requires registering it with the backup account first, as described in Configure Backups.