Active Disaster Prevention

The Growth-only safeguards that turn a recovery into one click, or no clicks at all — a backup Telegram account, a standby bot, standby channels with a live mirror, automatic failover with its email-fee consent, and the readiness checklist.

Detection and every recovery are yours on any plan. Active Disaster Prevention is the part of the program you set up before anything happens, so that when Telegram does take something away the fix is already in place. It lives on the Disaster Recovery page, under the recovery cards, with the badge Available with Growth.

On Free and Starter the section is visible but dimmed under an upgrade card, so you can see exactly what you would be getting; every control in it refuses until the account holding the project is on Growth. Growth is read from the project owner's plan, never from the teammate acting — a member of a Growth creator's team can set these up on their behalf.

Included on Growth — detection and every recovery stay on every plan

Active Disaster Prevention is included in Growth, with no addon to buy. On Free and Starter the section is visible but locked; upgrade from Billing → Plans and every safeguard below unlocks for all of that account's projects. The gate covers only the safeguards on this page: detection, the alerts, the three recoveries, the roll call, undo and the history are yours on every plan, including Free. See Subscriptions for the full plan comparison.

Downgrading with safeguards in place

Leaving Growth while a standby bot, a standby chat, automatic failover or a backup account is still configured is refused with a message telling you to remove them first. Nothing is ever deleted on a downgrade.

Backup Telegram Account

A second Telegram account you control, proven through the same bot handshake as an account relink (link or eight-character code, 15 minutes, from the backup account). Once registered:

  • you can sign in with Telegram from either account;
  • an account incident alert goes to the backup account, since the main one can no longer receive it;
  • our platform bot recognises you by either account;
  • the recovery page offers Switch to Backup Account — one click, no handshake — and the previous account becomes the backup, so the switch can be undone the same way.

Remove it with Remove Backup whenever you like; register another the same way.

Standby Bot

Each project can keep one standby bot: a second token from BotFather, stored without a webhook, so it receives nothing until it takes over and Telegram never sees it do anything. Our hourly probe checks it stays valid; if Telegram refuses the standby's token you receive Your standby bot for … no longer answers Telegram by email, because a standby that cannot take over is worse than none.

When the project's bot is banned, the recovery page offers Switch to Standby: the standby's token is written into the project's existing bot record, every member chat follows it, and the slot is emptied for a new standby.

Standby Channels and Groups

Each channel or group can have one standby chat of the same type, handed over through the platform bot's chat picker (Add Standby → tap the button on Telegram, or make the bot an administrator of the standby and confirm its offer). The button reaches your main account and, once you have registered one, your backup account as well, so a main account Telegram has restricted from creating channels is no obstacle: create the standby from the backup account and hand it over from there. The bot is an administrator of the standby from that moment, so a swap needs no Telegram round trip, and the standby is probed alongside the resource so you learn if it degrades before you need it.

Each row shows the standby's name with a health dot, and for a channel the Mirror Content (Copy Over) switch.

Live Mirror

Only channels are mirrored, and the page says why: a channel is content, and a banned channel takes every post with it; a group is conversation, and copying its members' messages into an empty standby would be noise. Groups still get a standby, and the failover still re-admits everyone.

With the mirror on, every post published in the channel is copied into its standby the moment it is made — text, media by file reference, without re-uploading — and an edit is reflected by replacing the mirrored copy. Nothing is backfilled: posts made before the mirror was switched on are not copied, because they can only be read while the channel is alive, and the mirror exists precisely for the day it is not. Switch it on early.

Switch it off and posts stop being copied; what was already mirrored stays in the standby.

Automatic Failover

Per project, one switch that lets the platform act the moment we detect a loss, with nobody signed in, in two situations:

  • a banned channel or group, or one our bot was removed from, is swapped for its healthy standby chat;
  • a project bot the platform refuses outright (token revoked or regenerated, bot deleted) is replaced by the project's standby bot.

A channel swap runs when all of these are true:

  1. the project owner is on Growth;
  2. the project's Automatic Failover switch is on;
  3. the resource has a standby and the standby is healthy;
  4. the reason is a real loss — Chat not found or Bot removed; a missing right never triggers a failover, because giving the right back is the fix;
  5. the Channels and Groups allowance has a use left (or a support grant covers it). An automatic failover counts exactly like a manual one.

When it runs, the resource is swapped, every member is re-admitted through the queue, and you receive Automatic failover: Signals now runs on Signals Standby by email and by Telegram, with the roll call and the 24-hour undo. The standby slot is then empty: link a new standby so the next failover is just as quick.

A bot switch runs when the owner is on Growth, the switch is on, a standby bot is registered and its last probe found it healthy, the refusal is platform-caused (a rate limit or a passing API error never counts), and the Project Bot allowance has a use left. The standby's token is written into the project's bot, the incident is resolved, the connector outage closes as replaced, plans return to sale, and every member with a verified or billing address is emailed the new bot link on your behalf at the per-email fee you accepted below, because the refused bot can no longer carry a message. You receive Automatic failover: Night Owls now runs on Night Owls Standby by email and on your connected account, saying how many members were emailed, and recovery.installation_failed_over fires. A bot switch cannot be undone from the dashboard, since the refused bot is gone as far as the platform is concerned; register a new standby bot afterwards.

When either cannot run, you are told why rather than left guessing: Automatic failover did not run for Signals (or for Night Owls's bot) names the reason — the allowance is spent, the standby is unavailable or unhealthy, the plan lapsed, or the swap was refused — and the incident stays open for you to handle by hand.

Switching Automatic Failover on asks you to tick one box: I accept $0.01 per email, added to my transaction fees, for members our bot cannot reach during an automatic failover. A failover runs with nobody signed in, and the project bot may be banned at the same time, so members the bot cannot reach on Telegram are emailed their new link on your behalf — there is nobody there to choose the CSV instead. Members the bot can reach cost nothing. The date you accepted is shown under the switch.

Readiness Checklist

At the top of the section, a grid of tiles scores what is in place. Two tiles are about your account and appear for everyone:

TileIn place when
Two-Factor Authentication or a PasskeyA second factor or a passkey guards the account that runs recoveries.
A Backup Sign-In AccountOne is registered.

The rest come from the connectors your projects run, each tile tagged with the connector's name, so a creator on Telegram sees Telegram's tiles and nothing about a platform they do not use. Telegram's four:

TileIn place when
A Standby Bot for Every ProjectEvery connected project has one.
A Standby for Every Channel and GroupEvery resource has a healthy standby.
Automatic FailoverEvery project with a standby has the switch on.
Live Mirror of Your ChannelsEvery channel with a standby mirrors into it.

A creator with several Telegram projects sees one tile per line, and its detail counts the projects ("2 of 3 projects") when they stand differently.

Two reminders the platform cannot verify sit under a separator: keep a copy of your content outside the platform, and keep a second human administrator in every space so the space itself survives a ban on your account. Each unfinished tile's Set Up button scrolls to the card on the page that fixes it; the two-factor tile opens your security settings.

The same checklist, with each line's state and the totals, is readable by integrations at GET /v1/recovery/readiness and by an agent through get_recovery_readiness. When a verifiable line changes state, after a recovery event or the nightly check, the recovery.readiness_changed webhook carries the whole checklist as it stands.

Example: the failover you sleep through

A trader on Growth runs Signals with a standby Signals (Standby), the mirror on since the day the standby was linked, and Automatic Failover on with the fee accepted. At 03:14 Telegram bans Signals.

  • 03:19 — the hourly probe finds Chat not found and opens the incident. All five conditions hold, so the failover job runs: Signals now points at the standby, which already holds every post since the mirror was switched on.
  • 03:20 — 340 members receive their new link through the bot; 22 who never started the bot are emailed at $0.22 in total, because the trader accepted the fee when switching the failover on.
  • 08:30 — the trader wakes to the Automatic failover: Signals now runs on Signals (Standby) email, opens the page, sees Re-admitted 340 / 340 · Joined 301, links a fresh standby for next time, and switches the mirror on for it. The Channels and Groups allowance is spent until December; a second ban before then goes through support.

How is this guide?

On this page

Subscriby is a product designed by you — for you.

No boardroom full of executives deciding what we ships next. Our roadmap always shaped by you with your feedback.

Share feedback or a request