# Incident Status Update

Provide time-stamped verified facts, user impact, affected scope, mitigation, workarounds, ownership, safety guidance, and the next update time.

## Usage note

Publish only facts confirmed by the incident source of truth. Name uncertainty and provide the next update time even when no new resolution estimate is available.

## How to use this template

1. Connect to the incident source of truth and confirm owners, scope, impact, and timestamps.
2. Separate verified facts, working hypotheses, unknowns, and sensitive internal details.
3. Draft user impact, current mitigation, safe workaround, support, and next update time.
4. Coordinate channels, publish a timestamped entry, and correct changes transparently.
5. Close with restoration scope, remaining work, monitoring, user action, and follow-up owner.

## Blank template

### Incident control

- **Incident ID and title:** [Enter]
- **Incident commander:** [Enter]
- **Technical and communication owners:** [Enter]
- **Source of approved facts:** [Reference]
- **Start and detection time:** [Date/time/timezone]
- **Current severity:** [Enter]
- **Affected service/version:** [Enter]
- **Last verified:** [Timestamp/person]

### Update entry

- **Public timestamp:** [Date/time/timezone]
- **Current status:** [Investigating / Identified / Mitigating / Monitoring / Resolved]
- **User-visible impact:** [Describe]
- **Affected users/regions/features:** [Verified scope]
- **Unaffected functions:** [Only if verified]
- **What changed since prior update:** [Enter]
- **Confirmed cause:** [Enter or Still investigating]
- **Unknowns:** [List]

### Action and next update

- **Mitigation in progress:** [Describe]
- **Safe workaround:** [Tested steps or None]
- **Workaround risks/limits:** [Enter]
- **Support path:** [Enter]
- **User action required:** [Enter or None]
- **Resolution estimate:** [Enter with confidence or None]
- **Next update:** [Absolute time/timezone]
- **Approver:** [Name/role]

### Resolution and follow-up

- [ ] Restoration, recovery, backlog, and monitoring are distinguished.
- [ ] Cross-channel messages and support scripts agree.
- [ ] Scheduled alerts and reminders were stopped or updated.
- [ ] Account-specific help avoids public sensitive detail.
- **Resolution time and scope:** [Enter]
- **Remaining user impact:** [Enter or None]
- **Post-incident communication:** [Owner/status]
- **Correction or retrospective trigger:** [Enter]
