Hand over an incident and record recovery
Give the next operator enough context to continue safely.
Access needed: Operator responsible for the incident.
- State the affected site and environment, when the problem started, and which users or operations are affected.
- Record the last known working revision and recent changes.
- List checks performed, their results, and any temporary configuration or paused jobs.
- Attach relevant redacted errors and identifiers, with links to controlled logs rather than copied secrets.
- Name the current owner, the next action, and the condition for escalation or recovery.
- After service returns, verify the original workflow, remove temporary changes, and record the recovery point and outstanding work.
Keep a timeline so another operator does not repeat a destructive or already failed action. Do not label an incident resolved merely because a process restarted; confirm the user-facing operation and delayed background work.