What to do now
Reconstruct the affected population by defining the suspect time, versions, properties, action classes, and trigger conditions, then unioning candidate identities from every independent source. Deduplicate by business action, compare expected transitions with observed records, label confirmed, possible, excluded, and unknown outcomes, and retain unresolved gaps in the closeout.
Key takeaways
- Missing logs increase the candidate set; they do not prove no action occurred.
- Reconcile business actions across systems, not raw log-line counts.
- State confidence and unknowns explicitly.
Define a conservative incident boundary
Record first known bad and last known good events, deployment and configuration changes, model/provider versions, prompt and tool versions, affected tenants or properties, action classes, queues, credentials, timezones, and logging failures. Expand the time window for delayed jobs and retries.
Preserve available logs and snapshots before normal retention or remediation changes them. Apply the organization’s privacy and security controls to sensitive incident data.
Union independent candidate sources
No source is presumed complete.
| Source | What it can prove | Typical blind spot | Join key |
|---|---|---|---|
| Workflow/orchestrator | Attempt and state transition | Dropped telemetry or bypass | Business action ID |
| Model/provider | Request/version/response where retained | No downstream execution proof | Request/correlation ID |
| System of record | Created or changed property record | Failed/no-op attempts | Object and action IDs |
| External provider | Message, payment, or dispatch outcome | Internal proposal context | Provider and idempotency IDs |
| Approval/human record | Decision and evidence version | Automated bypass or post-approval drift | Approval/action ID |
| Notifications/support | Observed recipient or user effect | Incomplete and unstructured | Recipient, property, time |
Assign evidence-based population states
Use confirmed affected, confirmed unaffected, possible affected, duplicate representation, and unknown. Record why each exclusion is justified; absence from a broken log is not exclusion evidence.
NIST log and AI risk-management guidance supports robust logging, monitoring, incident response, and recovery. It does not define these property-management disposition labels. Closeout should carry remaining unknowns, compensating review, and logging remediation.
Operational checklist
Mark your progress, then save a working copy. Selections reset when you leave this page. A checked box is not an approval or evidence of completion.
☐
Incident boundary and versions fixed
☐
Logging gaps preserved
☐
Independent sources inventoried
☐
Business-action join strategy documented
☐
Duplicates collapsed without deleting lineage
☐
Exclusions supported affirmatively
☐
Unknowns and compensating review retained
0 of 7 marked
Edge cases
- Clock drift changes apparent order: preserve source times and normalize with uncertainty.
- One external effect lacks an internal request: include it as possible affected until explained.
- Retries share a business action but have several provider IDs: keep one action with all attempts.
Sources and references
Follow each source to check the underlying claim. Access checks and professional review are different steps.
1. Primary source · National Institute of Standards and Technology
SP 800-92: Guide to Computer Security Log ManagementLog management includes configuring sources, analysis, response, storage, access control, and representative testing. The federal guidance is used as a control reference, not a certification.
Source checked 2026-09-18
Automated source-access check: 2026-09-18.
2. Primary source · National Institute of Standards and Technology
AI Risk Management Framework CoreThe voluntary AI RMF addresses governance, measurement, monitoring, incident response, recovery, and change management. It does not prescribe a property-management workflow.
Source checked 2026-09-18
Automated source-access check: 2026-09-18.
Continue the workflow
AI workflow incident closeout for property operationsWebhook replay reconciliation for property workflowsReview AI workflow failure modes before launchRevision history
2026-09-18
Initial Phase 4 operational article with a distinct evidence artifact, failure states, source limits, and AI-assisted technical review.