Dossiers and escalation packets
Produce a stable evidence package that another team can understand without reconstructing the incident.
Purpose of the dossier
The dossier is a decision-ready incident record, not a dump of every message and log. It should let a qualified reviewer understand impact, scope, evidence, supported boundaries, actions, ownership, and validation without calling the original operator.
Required sections
- Incident identity, time window, and customer or service impact.
- Affected scope and healthy comparison.
- Evidence ledger with timestamps and sources.
- Candidate boundaries, eliminated boundaries, and current confidence.
- Command and action record with authorization.
- Owner handoff and next checkpoint.
- Escalation ask and the evidence already collected.
- Exit criteria, recovery proof, and residual risk.
Escalation quality
A strong escalation asks for a specific interpretation, action, or approval. It shows why the receiving team is the correct owner and prevents repeated evidence requests. "Please investigate" is weak. "Confirm whether the affected-versus-healthy controller state supports a control-plane boundary and identify the safe next collection step" is actionable.
Publication safety
Remove secrets and unnecessary identifiers. Mark assumptions as assumptions. Do not claim root cause when the dossier supports only a boundary. Preserve enough technical detail for review while respecting customer and security policy.