Incident response
Start an incident for suspected unauthorized access, exposure of private information, broken check-in, event-wide availability failure, payment/reputation risk, or unsafe public content.
- Stabilize: stop the affected workflow where a safe UI control exists; do not disable security controls or alter logs.
- Capture: time, route, record IDs, screenshots without sensitive data, user-visible symptom, and who is affected.
- Escalate to the on-duty technical owner and event lead. Notify Communications for participant-facing messages.
- Contain and recover only through reviewed controls. Record every decision.
- Close after evidence shows the impact is understood and the owner approves the follow-up.
Never paste secrets, raw JWTs, email/phone lists, or bypass values into the incident record.
Severity and authority
Section titled “Severity and authority”The event lead coordinates participant impact; the technical owner controls system changes; Communications approves outward messaging. Anyone may report an incident, but only authorized owners may change access, publish content, deploy, alter provider settings, or modify data.
First 15 minutes
Section titled “First 15 minutes”- Open the official incident channel and name the incident commander, technical owner, and communications owner.
- State impact in plain language: who/what is affected, start time, whether it is ongoing, and the current safe workaround.
- Preserve route, sanitized error, request/record IDs, timestamp/timezone, and redacted screenshots.
- Contain through an existing approved UI control where possible. Do not rotate keys, disable RLS, change production data, or send a broad message without authority.
- Set the next update time even when there is no new finding.
Recovery and closeout
Section titled “Recovery and closeout”Choose the smallest reversible fix with the responsible owner. Validate in the target environment, then separately record source/configured, deployed, and live-observed evidence. After stabilization, document impact, timeline, decision maker, remedial work, and required communications. Security-sensitive facts remain in the authorized incident system, not in the general handbook.