Agents & automationIncident reviewagent

Build an incident timeline without assigning blame

Orders logs and notes by time while preserving source and clock uncertainty.

Editorial illustration for Build an incident timeline without assigning blame
Editorial illustration for this prompt; the prompt itself does not generate this image.

Ready to use

Prompt

Using permitted [LOGS] and [NOTES], construct a timeline for [INCIDENT WINDOW]. Preserve original timestamps and timezones, annotate clock drift and distinguish observation from inference. For every event provide a source pointer and confidence. Mark gaps, contradictory reports and potential sensitive data for restricted handling. Do not alter logs, accuse a person, publish a report or recommend disciplinary action. Output a neutral timeline plus questions for the incident owner. Check whether two apparent events are duplicates and whether the chronology changes after timezone normalisation.