Agents & automationIncident reviewagent
Build an incident timeline without assigning blame
Orders logs and notes by time while preserving source and clock uncertainty.

Ready to use
Prompt
Using permitted [LOGS] and [NOTES], construct a timeline for [INCIDENT WINDOW]. Preserve original timestamps and timezones, annotate clock drift and distinguish observation from inference. For every event provide a source pointer and confidence. Mark gaps, contradictory reports and potential sensitive data for restricted handling. Do not alter logs, accuse a person, publish a report or recommend disciplinary action. Output a neutral timeline plus questions for the incident owner. Check whether two apparent events are duplicates and whether the chronology changes after timezone normalisation.