Maintenance & Data Retention
Routine maintenance of a Smart Corridor stack is small but regular: keep the license valid, keep retention honest, keep watchlists clean, and keep images updated deliberately. Most of it can be scheduled quarterly; retention runs itself once configured correctly. Face Matcher has its own lifecycle guides — Operations and Upgrade — and the corridor adds only the items below on top.
Data retention and GDPR
The corridor retention job deletes expired event records and images automatically at the configured TTLs — verify it actually runs (record counts should plateau, not grow) and that the TTLs still match your data-protection commitments. Deployments that must not store biometric event data at rest run STORAGE_ENABLED=false; everything still works live, only history queries return nothing. Full model in Event Storage & Retention. Face Matcher keeps its own detection and identification history with separate settings — see Data Retention and Cleanup — so a "no data at rest" policy has to be applied on both sides.
Watchlist hygiene
Watchlists degrade silently: subjects leave, duplicates accumulate, enrollment photos age. Schedule a periodic review in Station — remove stale subjects, re-enroll low-quality references (Enrollment Image Quality), and confirm that VPP_ADAPTER_ALLOWED_WATCHLISTS still reflects operational policy. Cleaner watchlists are faster and more accurate; see Tuning Identification.
License and credentials
The single iengine.lic in secrets/ is tied to host hardware and licenses both Face Matcher and the corridor — plan its renewal and re-issue it via the Customer Portal before any hardware replacement, not after. Registry robot-account tokens do not expire but should rotate with your secret policy.
Upgrades
A Face Matcher upgrade replaces the whole face-matcher/ folder with the new release checkout — never patch files inside it. Follow the Face Matcher Upgrade guide (including template migration when the extraction algorithm changes), then bump the corridor image versions in .env and run start.sh again.
Backups
With storage disabled there is little corridor state to lose: .env, .env.hub and secrets/ are the assets to back up, plus the Face Matcher database (watchlists, subjects) following Backup and Restore. With storage enabled, add the PostgreSQL event store and the S3 image bucket to your backup scope only if your audit requirements demand it — by design they are a short rolling window, and letting them expire is often the correct behavior.