Skip to content

Populate every correlated incident with an operator-ready report #71

Description

@CodeBuildder

Problem

Correlated incidents expose only a title, four facts, lifecycle stages, and raw supporting evidence. The Argus and Phoenix records contain enough context for a proper report, but Sentinel neither derives nor renders one.

Scope

  • derive a deterministic report for every Argus + Phoenix correlation
  • include executive summary, detection, affected resource, impact, root cause, decision/containment, recovery, verification, governance, and provenance
  • render the report clearly above the resilience proof timeline
  • cover seeded and dynamic portable-demo incidents without inventing unavailable facts
  • preserve explicit simulator/replay/live provenance

Acceptance criteria

  • every correlated incident returned by /overview contains a report
  • missing source fields are represented honestly, not hallucinated
  • incident drawer is readable at recording resolution
  • backend tests and dashboard production build pass

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions