Church Cashbook Maintenance Manual
Verify backups and test restore annually.
Backup configuration
Backups are managed by Akeeba Backup, configured to run automatically on a schedule. Backup archives transfer off-server automatically. The System Info page shows the age of the most recent detected backup archive — confirm this is within the expected window during monthly checks.
What is backed up
- The complete database (
church_accounts) including all transactions, users, Gift Aid declarations, and settings - The application codebase
- The
church_recordsstorage directory (exports, receipts, logs)
Note that Gift Aid declaration data is stored encrypted in the database. The encryption key is held in config.php — back this up separately and securely. Without the key, encrypted donor data in a backup cannot be recovered.
Monthly check
- ☐ Confirm the Akeeba Backup log shows a successful run within the last scheduled period
- ☐ Confirm the backup archive has transferred off-server (check the remote destination)
- ☐ Confirm System Info → Backup status shows Recent (green) not Older than 48 hours (amber)
Annual restore test
At least once per year, test that a backup can actually be restored. A backup that has never been tested is not a backup. The procedure is:
- Download a recent backup archive from the off-server destination.
- Restore to a test environment (local MAMP or a staging server) using Akeeba Kickstart.
- Confirm the application loads and that a sample of transactions are present and correct.
- Confirm Gift Aid data is accessible using the known encryption key.
- Record the test date and outcome in the maintenance log.
Encryption key: The Gift Aid encryption key must be backed up separately from the database. Store it in a secure, offline location accessible to the appropriate Diocese IT contact. If the key is lost, encrypted donor data cannot be recovered from any backup.