# Incident evidence log

Blank working document. Replace placeholders with your own evidence; an empty field is unknown, not a passing result.

Owner: [fill in]
Source revision: [fill in]
Environment: [fill in]
Evidence date: [fill in]

## Scope

Incident window and time zone: ___
Environment/service: ___
Customer-visible symptom: ___
Permitted event sources: ___
Sensitive fields removed: ___

## Timeline

| Timestamp | Observed event | Evidence reference | Related deployment |
| --- | --- | --- | --- |
| ___ | ___ | ___ | ___ |

## Hypotheses

Hypothesis: ___
Supporting evidence: ___
Contradictory evidence: ___
Discriminating test: ___
Reproduction unavailable because: ___

## Recovery

Proposed minimal change: ___
Validation command and preserved exit: ___
Recovery signal and observation window: ___
Rollback trigger/owner: ___
Current state: investigation only

## Boundaries

- Choose a host for each stage and verify its tool mapping. Pass evidence explicitly between stages; the listed resources do not automatically configure or invoke one another.

- Configure Sentry access and the definition’s tool mapping separately. Record adapter and self-hosted feature limits before treating an event set as complete.

- Do not resolve issues, change alerts, edit production or publish incident data during the evidence-gathering pass.

Workflow: https://undominated.ai/workflows/#investigate-an-incident

Original worksheet: MIT. Linked resources retain their own licences and setup requirements.
