Using Draughtsman
History, compare and the bin
Three safety nets, in the order you will need them: undo for the last few seconds, version history for the last few days, and a bin for the diagram you deleted by mistake.
Version history
Open the History tab. It lists the stored versions of the open diagram, newest first, with the time, who made them (agents are marked as such) and the size.

Where versions come from, and what is not a version:
- Automatic checkpoints. When an agent edits a diagram (over MCP or from the AI panel), the server first stores the diagram as it was. An agent's change can always be undone from here. The server keeps the newest 50 per diagram (
retention.checkpointsPerDocument). - Named versions. Choose Name this version, type a name, press Enter. Named versions are never pruned.
- Restore points. Restoring stores a checkpoint of the current state first, so a restore can itself be restored.
- Autosave is not history. It overwrites the current version every couple of seconds. There is no per-keystroke history; Cmd+Z covers that, in the open editor.
Compare
Choose Compare on any version. The panel lists what has been added, removed and changed since that version, and the canvas marks the same things: a dashed outline and a small + (added), ~ (changed) or − (removed) badge, drawn in outline style so it reads on any theme. Stop comparing clears the marks.

Compare is the same function the MCP diff_documents tool uses, so an agent can ask the same question.
Restore
Choose Restore on a version. The current diagram is saved as a checkpoint, and the chosen version becomes the diagram. Nothing is lost either way.
The bin
Deleting is not permanent. A deleted diagram goes to the Bin (the switch beside Documents on the home page), with its versions, and stays for 30 days (retention.binDays; zero or less keeps it until someone deletes it for good). A daily pass then removes it permanently and records each removal in the security log. Restoring brings it back exactly as it was.

| Who | Sees in the bin | Can restore | Can delete for good |
|---|---|---|---|
| Administrator | everything | everything | everything |
| Editor | entries they created, or deleted | those entries | only diagrams they created |
| API token | what its owner may see | what its owner may restore | never: a browser session is required |
Moving a diagram to the bin, restoring it and deleting it for good are each recorded in the security log (the three events Document moved to the bin, restored from the bin and deleted for good). Delete is also recoverable from the toast that appears straight after it ("Moved … to the bin. Undo"). Backups include the bin.
The home list
Search (press /), filter by type, sort, rename inline, duplicate, delete. There are no thumbnails, folders, tags or favourites yet, and the list has no owner or last-editor column.

Review
The Review tab runs a deterministic structural check over the diagram on the canvas: dangling connectors, isolated nodes, a decision with a single branch, an unreachable node, a database nothing uses, a table with no primary key, unbalanced activations in a sequence, and similar. It never gives an opinion of your content: same diagram, same findings. The MCP critique_document tool runs the same rules.

One organisation, one trust level
An Editor can open, change and delete any diagram, not just their own. The bin and version history are what make that survivable: an Editor who deletes a colleague's diagram can restore it, and so can the colleague. If you need per-document permissions, they are not built; see the FAQ.