Raghu Gollapudi
Hybrid Oracle database failover can return a successful command while still being unsafe: telemetry may be stale, redo apply lag may exceed policy, the old primary may remain write-capable, routes may leak active writers, or the promoted target may not yet accept durable application writes. This paper presents Auditable Recovery Decision Architecture with Guarded Admission and Transition Evidence (ARDA-GATE), an auditable admission-control layer for Oracle hybrid failover. ARDA-GATE does not replace Data Guard, broker-managed role transition, Fast-Start Failover, or infrastructure orchestration. Instead, it sits between failure detection and write release: it collects Oracle, broker, host, route, fencing, and write-probe observations; validates source freshness; applies non-compensatory safety gates; ranks only already admitted candidates; and preserves a replayable evidence bundle. A 30-run Oracle Database 19c pre-production fault-injection campaign compares immediate promotion, threshold-only promotion, pause-and-reconcile recovery, and ARDA-GATE under Maximum Availability and Maximum Performance conditions. The results distinguish command-time recovery from safety-credited recovery using validated recovery time, System Change Number (SCN) gap evidence, route and fencing proof, write-probe validation, rejected-target checks, manual intervention, and evidence completeness. Maximum Availability zero-gap outcomes are attributed to synchronized standby protection, whereas Maximum Performance tests show ARDA-GATE rejecting or holding unsafe high-lag candidates and recording bounded exposure when policy permits release. Six scheduled production disaster-recovery exercises validate operational feasibility under change controls with confidential identifiers redacted. The result is a practical admission-control framework for releasing writes only after one safe write authority is proven.