Problem
Correlated incidents expose only a title, four facts, lifecycle stages, and raw supporting evidence. The Argus and Phoenix records contain enough context for a proper report, but Sentinel neither derives nor renders one.
Scope
- derive a deterministic report for every Argus + Phoenix correlation
- include executive summary, detection, affected resource, impact, root cause, decision/containment, recovery, verification, governance, and provenance
- render the report clearly above the resilience proof timeline
- cover seeded and dynamic portable-demo incidents without inventing unavailable facts
- preserve explicit simulator/replay/live provenance
Acceptance criteria
- every correlated incident returned by
/overview contains a report
- missing source fields are represented honestly, not hallucinated
- incident drawer is readable at recording resolution
- backend tests and dashboard production build pass
Problem
Correlated incidents expose only a title, four facts, lifecycle stages, and raw supporting evidence. The Argus and Phoenix records contain enough context for a proper report, but Sentinel neither derives nor renders one.
Scope
Acceptance criteria
/overviewcontains a report