Chapter 04 · start here

Incident operating rhythm

Coordinate evidence, owners, checkpoints, and communication without turning the tool into another status dashboard.

1 min read·Updated 2026-07-24·3 role paths
01

Establish the clock

At the start of an incident, record the impact window, the next evidence checkpoint, the next decision checkpoint, and any external communication commitment. A checkpoint should have an owner and a concrete expected output. "Update in thirty minutes" is weaker than "Storage owner returns affected-versus-healthy latency evidence by 14:30."

02

Keep four records distinct

Record 01
Record
Evidence ledger
Purpose
What was observed, where, when, and by whom
Record 02
Record
Decision log
Purpose
What the team decided and the evidence used
Record 03
Record
Action record
Purpose
What changed, who authorized it, and expected outcome
Record 04
Record
Communication record
Purpose
What was shared, with whom, and the next commitment
03

Run the narrowing loop

At each checkpoint, ask what changed in the evidence state. Remove boundaries that are no longer supported. Promote boundaries only when evidence supports them. Assign the next unanswered question to a named owner. Avoid reopening settled questions unless new evidence contradicts the previous conclusion.

04

Close responsibly

Closure requires impact recovery, technical validation, owner agreement, and residual-risk recording. If the immediate service is restored but the underlying boundary remains uncertain, close the active incident only with a separate problem investigation, owner, and due date.