The incident commander holds the overall state of an incident and structures the response — assigning who changes the system, who communicates, who plans — without doing the technical work themselves.
| time | source | event |
|---|---|---|
| 12:03:00 | log | tickcap: last message on the quote channels |
| 12:03:05 | alert | data age above 5 s: page |
| 12:03:30 | alert | data age above 30 s: page |
| 12:03:56 | alert | burn rate: page |
| 12:04:00 | alert | data age above 60 s: page |
| 12:24:00 | log | tickcap: quote channels resume |
| 12:24:00 | log | rtrisk: data age back under 5 s |
firm.observe.timeline. Time to detect: 56 seconds under the burn-rate rule; time to restore: 21 minutes.