Build one fact base before writing three stories
Create a master index with incident ID, UTC timeline, affected hostname and path, request coverage, estimated and invoiced cost, customer impact, control decisions, recovery tests, owners, and open questions. Every conclusion in an audience brief should point to an indexed source.
Preserve originals read-only and hash exported files. Record collector, collection time, source system, timezone, query or export method, and retention date. A filename such as final-log.csv does not establish provenance.
Minimize before distributing
Exclude raw conversations, prompts, responses, API keys, unrelated visitors, and unrelated client records unless they are necessary and authorized for a specific claim. Prefer counts, request IDs, hashes, and redacted excerpts. The master index should record what was excluded and why.
Separate supported WordPress calls from outside or direct calls. If the evidence cannot establish coverage, label the boundary unknown. An insurer or client needs an honest scope more than a confident total that merges incomparable systems.
| Index item | Master fact base | Insurer/auditor view | Client view |
|---|---|---|---|
| UTC timeline | full event chain | control and notification milestones | customer-impact milestones |
| Financial impact | estimate, invoice, bridge | method and confirmed amount | contract-relevant summary |
| Request evidence | IDs and covered/outside state | sample plus provenance | aggregated and redacted |
| Control decision | options, approver, reason | policy compliance evidence | action and outcome |
| Sensitive data | location and restriction | minimum authorized subset | excluded unless necessary |
| Retention | owner and deletion date | legal/contract basis | stated commitment |
Issue role-specific views
An insurer may need chronology, claimed amount, mitigation, and policy notices. An auditor may need control design, approval, test, and exception evidence. A client may need service impact, affected scope, recovery, and contractual actions. Use the same facts but not the same indiscriminate archive.
Give each view a purpose, recipient, approval, version, redaction log, and secure transfer method. If a reviewer asks for additional data, add it through a recorded change rather than sending an untracked attachment.
Distinguish estimates from settled facts
Label local estimated cost, provider finalized usage, invoice amount, credits, tax, and internal labor separately. Include the calculation and rate source for estimates. Replace or bridge them when the invoice arrives; do not silently revise a previously issued report.
Likewise distinguish suspected cause, supported contributing factor, and confirmed root cause. Include contradictory evidence and remaining uncertainty. A defensible pack shows how the conclusion was reached, not merely the conclusion.
Close the pack's own lifecycle
Record final approvals, recipients, transfer receipts, follow-up requests, litigation or contractual holds, ordinary retention, and deletion date. Remove working copies when no longer required and retain the index or proof of deletion according to policy.
The pack is complete when a reviewer can trace every material statement to minimized evidence, see coverage and uncertainty, and know when the data will be deleted. The privacy policy is the appropriate next page for published collection and retention commitments.
Use the incident evidence pack index from “Prepare an evidence pack for an insurer, auditor, or client after a cost incident” on a real first installation. Download AI Cost Circuit Breaker for free, begin in Monitoring, and move to enforcement only after the expected signals and rollback are verified.