Reference · The incident case
The incident case
A case is the one record an incident leaves behind, on the hosted app and on the desktop app alike. It has one identity, seven sections in one order, seven statuses with a fixed set of moves between them, and a rule for who may make each move. The vocabulary is the shared contract's, so both apps say the same thing.
Working an incident? Start with incident response, then use this contract when you need the exact case fields, sections, and allowed status moves.
See it in motion
Identity
A case belongs to one team and one repository. It carries a class (production, performance, security or cost), a severity (critical, high, medium or low), a title, the time it was opened, first seen and last seen, and a deduplication key built from the source's stable identity for the problem, so a second sighting of the same problem lands on the same case rather than opening another. A source-supplied session reference is reported context until it is verified; a collaborator's role is not proof of causation.
The seven sections
- Overview
- The problem, its impact, the facts, the hypotheses, and the confirmed cause when a person has confirmed one.
- Evidence
- The timeline and the source records, each with the source's health at the moment of the sighting.
- Attribution
- The deployment, the commit, the changed code, the contributors, the session and its turns; the confidence and the gaps on every edge.
- Security
- The versioned classification, the affected assets, the exploit evidence or its recorded absence, the containment options.
- Cost
- Measured charges and recorded usage, kept apart from estimates; unknown is not zero.
- Fix
- The proposed remedy, the exact-scope approval, the verification receipts, the deployment.
- Prevention
- The reviewed lesson, the executable guard, delivery and recurrence results, and the outcome of the newest published prevention package.
The order is fixed on both apps. A section with nothing recorded says so in words rather than hiding the row; a row that could not be read says it could not be read, which is a different fact from empty.
A case opens as a dialog over the page you were on. One row of controls lists the seven sections, then any inspector that page has evidence for. Each one has its own address, so a link opens the case on that section and the browser's Back returns to the section before. Escape or Close returns you to the list, with focus on the row that opened the case.
Statuses and moves
| From | May move to |
|---|---|
| open | acknowledged, investigating, contained, resolved, false_positive, duplicate |
| acknowledged | investigating, contained, resolved, false_positive, duplicate |
| investigating | contained, resolved, false_positive, duplicate |
| contained | investigating, resolved, false_positive |
| resolved | investigating |
| false_positive | open |
| duplicate | open |
Resolved, false positive and duplicate close a case. A new sighting after a close is a recurrence decision, never an automatic reopen: a matching signature and scope reopen the case into investigating with the earlier resolution kept on the record; a sighting in scope with another signature links a new case; anything else is no match, with the evidence listed. The same status is not a move.
Who may move one
Any member of the team reads a case within their repository scope. A status move, a finding's confirmation, a verification check, a cost receipt entered by hand, a lesson's review and a recurrence decision are an owner's or an admin's; the case detail shows those forms only to a person who may use them. A person confirms a cause; a model may draft a hypothesis and never confirm one. Two confirmed causes that conflict are a conflict, and no lesson is admitted over it.
Where to read on
Which sources open a case and how their health is reported: supported adapters and capture and troubleshooting. The cost section's rules: cost receipts and approvals. The prevention section: lessons and recurrence and the package workflow. The same case on the desktop app: the local companion.
Last updated