Skip to content

Populate every correlated incident with an operator-ready report #71

Description

@CodeBuildder

Problem

Correlated incidents expose only a title, four facts, lifecycle stages, and raw supporting evidence. The Argus and Phoenix records contain enough context for a proper report, but Sentinel neither derives nor renders one.

Scope

  • derive a deterministic report for every Argus + Phoenix correlation
  • include executive summary, detection, affected resource, impact, root cause, decision/containment, recovery, verification, governance, and provenance
  • render the report clearly above the resilience proof timeline
  • cover seeded and dynamic portable-demo incidents without inventing unavailable facts
  • preserve explicit simulator/replay/live provenance

Acceptance criteria

  • every correlated incident returned by /overview contains a report
  • missing source fields are represented honestly, not hallucinated
  • incident drawer is readable at recording resolution
  • backend tests and dashboard production build pass

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions