# Incident timeline template

Record events in incident time. Keep observation, hypothesis, decision, action, and outcome distinct. Add a source link whenever evidence exists.

## Timing anchors

- Impact start (confirmed or estimated):
- Detection time:
- Declaration time:
- First responder engaged:
- Mitigation start:
- Recovery observed:
- Recovery verified:
- Incident closed:

## Event template

Copy this block for each meaningful event.

### YYYY-MM-DD HH:MM TZ — Concise factual event

- Event type: observation | hypothesis | decision | action | outcome | communication
- Elapsed time from impact start:
- Owner:
- State: proposed | accepted | in progress | completed | superseded
- Source:
- Evidence links:
- What happened:
- Why it mattered:
- Expected next signal:
- Open question:

## Suggested chronology

- [ ] Trigger or earliest supported impact
- [ ] Detection signal or customer report
- [ ] Incident declaration and initial scope
- [ ] Major investigation findings
- [ ] Decisions that changed response direction
- [ ] Mitigation attempts and observed outcomes
- [ ] Scope or severity changes
- [ ] Stakeholder and customer updates
- [ ] Recovery signal and verification
- [ ] Closure decision and remaining risk

## Review checks

- [ ] Event time and record time are not conflated.
- [ ] Estimated times are labeled as estimates.
- [ ] Conclusions retain the evidence available at that moment.
- [ ] Superseded hypotheses remain visible rather than rewritten with hindsight.
- [ ] Actions have owners and outcomes.
- [ ] Customer-impact changes are represented in the chronology.
