Obligation Receipts is not deployed, but confidential-evidence exposure, credential exposure, a false pass, or a disabled security gate can still be an incident.
- Stop the affected workflow and preserve non-sensitive diagnostic facts.
- If a credential may be exposed, rotate it, revoke the old value, and inspect issuer audit logs before considering repository-history cleanup.
- If confidential evidence was processed contrary to policy, isolate the workspace, stop copying it, identify every storage location, and obtain legal/privacy advice before deletion could destroy required evidence.
- Correct the control and add a regression test.
- Record confirmed incidents under
docs/incidents/YYYY-MM-DD-<slug>.mdwith severity, UTC timeline, impact, detection, systemic root cause, actions, owners, and due dates.
Never include credentials, confidential contracts, personal data, or raw evidence in an issue or postmortem.