Severity ladder, label conventions (incident, sev1–sev4), and the postmortem artifact
format are owned by the portfolio INCIDENT-RESPONSE-STANDARD.md.
This directory holds this repo's committed postmortems.
- Sev1 — any cross-tenant data access; credential-vault exposure; mass send of unapproved email.
- Sev2 — alert/digest pipeline silently down for affected users beyond one cycle; budget caps failing open.
- Sev3 — single-user delivery failure with a workaround; adapter breakage covered by healing.
- Sev4 — cosmetic or documentation-only defects discovered post-release.
Secret-leak events follow the standard's runbook (rotate → revoke → history-scrub decision → postmortem) without exception.