Skip to content

Incident record template

Status: release candidate template for adaptation.

Related chapters: 13, 16, 20, 23.

Intended user: incident commander, platform owner, security reviewer, capability owner and postmortem facilitator investigating an agentic failure or near miss.

What to adapt: severity levels, incident roles, evidence retention policy, privacy handling, notification paths, legal/compliance escalation and follow-up tracking.

Limitations: this is a technical incident record template. It does not replace the organization's security incident, privacy incident or legal response process.

Identity

  • Incident ID:
  • Date/time:
  • Reporter:
  • Incident commander:
  • Affected agent:
  • Affected capability:

Evidence freeze

  • Trace ID:
  • Session ID:
  • Run ID:
  • Change ID:
  • Rollout wave:
  • Policy bundle:
  • Model route:
  • Approval record:

Impact

  • User impact:
  • Data impact:
  • Tool or side-effect impact:
  • Business impact:
  • Severity:

Timeline

  • Detection:
  • First containment:
  • Investigation milestones:
  • Resolution:

Containment and recovery

  • Action taken:
  • Owner:
  • Scope:
  • Rollback or reconciliation:
  • Residual risk:

Corrective actions

  • New eval case:
  • Policy/verifier update:
  • Tool gateway update:
  • Registry or lifecycle update:
  • Documentation update:
  • Follow-up owner and date: