Cadence
Four meetings, one window, no invented hours
Incident visibility reporting follows a fixed cadence so the chronology does not wander. Related memos and monthly briefings reuse pieces of the same sequence.
1. Window lock
A thirty-minute call names the first timestamp a record can defend, the last timestamp after collection stopped, and the display time zone. If the coordinator only has a hallway memory for the start, we wait for a ticket or an export row.
2. Source inventory
Every file that arrives gets a line: name, time range inside the file, and whether a filter was applied before export. Missing collectors become the first draft of the coverage-gap page, not a problem to solve by guessing.
3. Draft read
The coordinator marks factual errors only. Requests to add an actor name without a row in the inventory are declined in writing on the draft.
4. Walkthrough
Ninety minutes, on paper in Jackson when travel works, otherwise by phone at +17705041075. We read the chronology aloud and stop on every coverage gap. The local tracking utility may hold the same files the coordinator used; it is not a live feed into this meeting.
When the question is smaller than a full window, skip to anomaly detection reviews. When the incident is already closed, see after-action narratives.