Incident ID: INCIDENT-___ Date: YYYY-MM-DD Severity: [Critical / High / Medium / Low] Status: [Draft / Published] Authors: [Names] Reviewers: [Names] Last Updated: YYYY-MM-DD Related Runbook: [link]
[2–3 sentences: what happened, user impact, resolution]
| Metric | Value |
|---|---|
| Detection time (MTTD) | |
| Response time | |
| Recovery time (MTTR) | |
| Total downtime | |
| Data loss (RPO) | |
| Affected components | |
| Affected users |
| Time | Event |
|---|---|
| HH:MM | Incident detected |
| HH:MM | Team assembled |
| HH:MM | Mitigation started |
| HH:MM | Service restored |
| HH:MM | Monitoring confirmed stable |
[Technical root cause — blameless]
- [Factor 1]
- [Item]
- [Item]
| ID | Action | Owner | Priority | Due Date | Tracking Issue | Status |
|---|---|---|---|---|---|---|
| AI-001 | P0/P1/P2 | YYYY-MM-DD | #___ | Open |
- [Runbook name] — [what to change]
[Blameless takeaways]
- Internal review complete
- Sensitive details redacted (if customer-facing)
- Action items filed as GitHub issues
- Runbooks updated (if applicable)
- Added to
docs/incidents/index - Stakeholders notified (#yieldvault-incidents)