Notebook and laptop during a working discussion

Cadence

Four meetings, one window, no invented hours

Incident visibility reporting follows a fixed cadence so the chronology does not wander. Related memos and monthly briefings reuse pieces of the same sequence.

1. Window lock

A thirty-minute call names the first timestamp a record can defend, the last timestamp after collection stopped, and the display time zone. If the coordinator only has a hallway memory for the start, we wait for a ticket or an export row.

2. Source inventory

Every file that arrives gets a line: name, time range inside the file, and whether a filter was applied before export. Missing collectors become the first draft of the coverage-gap page, not a problem to solve by guessing.

3. Draft read

The coordinator marks factual errors only. Requests to add an actor name without a row in the inventory are declined in writing on the draft.

4. Walkthrough

Ninety minutes, on paper in Jackson when travel works, otherwise by phone at +17705041075. We read the chronology aloud and stop on every coverage gap. The local tracking utility may hold the same files the coordinator used; it is not a live feed into this meeting.

When the question is smaller than a full window, skip to anomaly detection reviews. When the incident is already closed, see after-action narratives.