Export a workspace
Run on the application host with PHP 8.5:
php artisan orbit:export WORKSPACE_UUID /secure/exports/orbit-2026-10-06.ndjson --no-interaction
Choose an existing private directory and a new filename. The command never overwrites a file or follows an existing destination symlink. Files are created with owner-only permissions (0600). Export includes archived records and revoked agent identities; it excludes credential hashes, credential metadata, idempotency responses, sessions, cache and infrastructure configuration. Keep the file private: it still contains business data.
The export uses a PostgreSQL repeatable-read snapshot. Concurrent changes do not produce a mixture of before/after relationships. Rows stream in chunks rather than loading the entire workspace into memory. A successful export creates an administrator audit event; ordinary failures remove the incomplete file. If the process or host crashes, a partial file may remain: require the final completion record before consuming it.
File format, version 1
The format is UTF-8 newline-delimited JSON (NDJSON), with one JSON object per line:
- First:
type: "manifest",format: "orbit-workspace",version: 1,exported_at, the workspace record and an exclusion list. - Middle:
type: "record",table, anddatacontaining one row. IDs, foreign keys, revisions, stored timestamps and typed JSON values are preserved. Empty objects remain objects rather than arrays. - Last:
type: "complete"andcounts, recording the number of exported rows for every table. Check these counts when processing a file.
Included tables are agents, field_definitions, tags, contacts, organisations, projects, tasks, affiliations, project_participants, activities, task_attempts, contact_tag, organisation_tag, project_tag, task_links, activity_links, and audit_events. The workspace itself is in the manifest. Agents include only ID, workspace ID, display name, role, revocation time and creation/update timestamps.
This is a portable data export, not a directly executable SQL dump or a complete application backup. There is no automatic import command. A reconstruction must preserve IDs, create fresh credentials, insert referenced records before relationships, and resolve the task/activity/attempt references in multiple passes. Do not reactivate exported claims on a different instance: their external work may still be running. Use a tested PostgreSQL backup for full operational recovery, including retry history and credentials, following Deployment.
Redact an activity
Ordinary corrections should append a new activity with corrects_id. For exceptional removal of sensitive activity content, an administrator can run:
php artisan orbit:activity:redact WORKSPACE_UUID ACTIVITY_UUID --reason=privacy --force --no-interaction
--force explicitly confirms irreversible removal. Reason is a category: privacy, incorrect_data, legal, or other; do not put removed content in the reason. The command verifies the workspace and clears title and source references, replaces the body with [Redacted], sets redacted_at, and scrubs stored activity append/link retry snapshots. IDs, authors, links, occurrence timestamps, correction references and existing task outcome references remain intact.
The audit event records the administrator source, reason category, target and affected fields without copying the removed content. Repeating the command is a no-op. A redacted outcome cannot be used for a new task completion; redacting an already-completed outcome does not reopen the task.
Existing backups, exports, logs from other systems, agent conversations and independently copied records are outside this command's reach. Apply the appropriate retention process separately. Redaction is not exposed through MCP and does not delete a whole record.