Incident response
A preservation-first workflow to detect, classify, contain, recover, communicate and learn from incidents.
How to interpret this document
This content describes technical and methodological behavior that is implemented or explicitly planned in the product. When a control depends on configuration, a provider, a secret, a contract or legal approval, that dependency must remain visible.
Detect
Use alerts, observability, user reports and audit evidence to identify abnormal behavior and determine which systems may be involved.
Classify
Assess impact on authentication, confidentiality, integrity, availability, billing, integrations and measurement reliability.
Contain
Prefer disabling the affected workflow, integration or rollout state rather than deleting historical evidence. Launch Control can move the product back to hold.
Preserve evidence
AUD-2.0, identity events, billing reconciliation, telemetry and related records should be preserved. Legal hold can be applied when appropriate.
Recover
Restore a known-good checkpoint, correct data through auditable and idempotent operations and rerun readiness checks.
Communicate
Notification duties and timelines for customers, regulators and data subjects depend on law, contract and approved legal policy.
Learn
Record root cause, contributing factors, gaps, corrective actions, owner and a verification plan for the fix.