Operator resource

Incident Timeline Template

A useful timeline preserves the chronology and the reasoning. Record events in incident time, keep source links attached, and distinguish what responders observed from what they concluded.

Updated August 2, 2026

Start with timing anchors

Keep event time, discovery time, and record time distinct when they differ.

Impact start

The earliest supported time customers or systems were affected. Mark it as estimated until evidence confirms it.

Detection and declaration

Record the alert or report that surfaced the issue and when the team formally began incident response.

Mitigation and recovery

Record when each mitigation began, when signals improved, and when recovery was verified rather than assumed.

Use one event structure

Consistent fields make a noisy timeline easier to scan and export.

Event

A concise factual statement of what happened, written without hiding uncertainty.

Source and evidence

Link the alert, message, chart, log query, deploy, ticket, or person that supports the event.

Owner and state

Name who owns the action or conclusion and whether it is proposed, accepted, completed, or superseded.

Capture decisions, not just activity

The review needs to explain why the response changed direction.

Decision

State the option chosen, the alternatives considered, and the evidence available at that moment.

Expected result

Record what signal should move, by how much, and when the team will evaluate it.

Outcome

Add the observed result as a new event instead of rewriting the original decision with hindsight.