Returning to a working state.
WHY IT MATTERS
Fixing forward under pressure produces further mistakes.
Reverting is usually faster and safer.
WHAT MAKES ROLLING BACK POSSIBLE
The previous version still available Database changes that are reversible or compatible A process that has been tested
THAT LAST POINT
A rollback procedure never exercised will fail when needed.
WHAT TO TEST
Rolling back, deliberately, on a copy.
WHAT COMPLICATES IT
Database changes that destroyed data Changes already made by users under the new version External systems already notified
WHAT TO DO ABOUT THOSE
Avoid destructive schema changes in the same release as behaviour changes.
WHAT TO DECIDE IN ADVANCE
At what point you revert rather than continuing to investigate.
WHY IN ADVANCE
Under pressure, people persist too long.
WHAT TO SET
A time limit. If not resolved within it, revert.
WHAT TO DO AFTER REVERTING
Investigate calmly, with production restored.
WHAT TO RECORD
What went wrong, and what would have caught it.