Start with timing anchors
Keep event time, discovery time, and record time distinct when they differ.
Impact start
The earliest supported time customers or systems were affected. Mark it as estimated until evidence confirms it.
Detection and declaration
Record the alert or report that surfaced the issue and when the team formally began incident response.
Mitigation and recovery
Record when each mitigation began, when signals improved, and when recovery was verified rather than assumed.
Use one event structure
Consistent fields make a noisy timeline easier to scan and export.
Event
A concise factual statement of what happened, written without hiding uncertainty.
Source and evidence
Link the alert, message, chart, log query, deploy, ticket, or person that supports the event.
Owner and state
Name who owns the action or conclusion and whether it is proposed, accepted, completed, or superseded.
Capture decisions, not just activity
The review needs to explain why the response changed direction.
Decision
State the option chosen, the alternatives considered, and the evidence available at that moment.
Expected result
Record what signal should move, by how much, and when the team will evaluate it.
Outcome
Add the observed result as a new event instead of rewriting the original decision with hindsight.