Operations
Incident response
Follow the Incident response operator checklist with on-call. Never wipe databases during an incident.
- SEV1: authority exposure, revocation bypass, or live billing corruption.
- Preserve logs and commit SHAs; freeze live unlocks if authority is in doubt.
- Verify trust boundaries and deny unauthorised access while investigating.
- Write a timeline and update the runbook after action.