Incident record template¶
Status: release candidate template for adaptation.
Related chapters: 13, 16, 20, 23.
Intended user: incident commander, platform owner, security reviewer, capability owner and postmortem facilitator investigating an agentic failure or near miss.
What to adapt: severity levels, incident roles, evidence retention policy, privacy handling, notification paths, legal/compliance escalation and follow-up tracking.
Limitations: this is a technical incident record template. It does not replace the organization's security incident, privacy incident or legal response process.
Identity¶
- Incident ID:
- Date/time:
- Reporter:
- Incident commander:
- Affected agent:
- Affected capability:
Evidence freeze¶
- Trace ID:
- Session ID:
- Run ID:
- Change ID:
- Rollout wave:
- Policy bundle:
- Model route:
- Approval record:
Impact¶
- User impact:
- Data impact:
- Tool or side-effect impact:
- Business impact:
- Severity:
Timeline¶
- Detection:
- First containment:
- Investigation milestones:
- Resolution:
Containment and recovery¶
- Action taken:
- Owner:
- Scope:
- Rollback or reconciliation:
- Residual risk:
Corrective actions¶
- New eval case:
- Policy/verifier update:
- Tool gateway update:
- Registry or lifecycle update:
- Documentation update:
- Follow-up owner and date: