"""The off-site copy of the CMS's backups (CMS audit C-1).

A backup on the host it protects is a copy, not a backup: losing the host
loses the documents and the record of them together. The CMS's shared host
cannot push anywhere — no shell, no credentials it should hold — so the copy
is a PULL, made from here over the same signed Agent API the platform already
uses for everything else.

Deliberately not part of the intake daemon. The CMS grants ``backups.read``
to a dedicated identity precisely so that an agent which handles documents
cannot walk off with the whole document store as a side effect — running the
puller inside the daemon, on the daemon's credentials, would undo that
containment from this end. It is its own process with its own key pair, run
by the operating system's scheduler.
"""
