Skip to content
SALARAProof Space

PROOF SPACE

Experience Organizational Intelligence

See how SALARA turns a policy document into activated Organizational Intelligence, then ask a question and Replay the evidence behind the answer.

  • Policy document source
  • Activated intelligence only
  • Deterministic Runtime
  • Replayable evidence

What you are doing

  1. Choose a documentStart from an activated policy source.
  2. Inspect the contentReview the governed statements SALARA compiled.
  3. Ask a questionReceive a deterministic answer and open Replay.

Policy document experiences

Choose a document

Each available document is backed by activated Organizational Intelligence.

Document content

What SALARA activated

These approved statements are the content Runtime can use. Answers stay inside this activated boundary.

IT Operations · Activated document

Escalation and Incident Response Guide

58 approved statements · DOC-OPS-0003 · SRC-5991452A065397B573265DC07B98
  1. - Every exception must be recorded in the incident record.

    ASSERT-009CCCFE7EFBBA10FC30A9084F1D20BF · v1
  2. - A Severity 1 incident requires executive notification within one hour.

    ASSERT-00F9D0E142887E750630A646873D7C78 · v1
  3. - Corrective actions are tracked to closure by the Field Operations Director.

    ASSERT-016C60CC6D4F576AE5A2DC03186C9D93 · v1
  4. - Severity 1 is an incident causing complete loss of a customer-facing service.

    ASSERT-108600BB54591621FD592DA5FBC66AB9 · v1
  5. - An incident affecting more than one hundred customers is classified as Severity 1.

    ASSERT-122AB786C509BF5FD278E6850A9E5207 · v1
  6. - Severity 2 escalation to the executive team requires Field Operations Director approval.

    ASSERT-13394C7A08DBC8ED9D509B9E9DEA53FB · v1
  7. - Evidence must be preserved before any remediation that alters system state.

    ASSERT-1A7F8B2B76A828234DE26D7443BC4227 · v1
  8. - Evidence is any record supporting later reconstruction of the incident.

    ASSERT-281B3B015C424D990BA59F35AA12B19A · v1
  9. - A Severity 1 incident involving customer data requires notification to the CISO.

    ASSERT-317BEB5B472D1202080D538B8C53FF34 · v1
  10. - A Severity 1 incident requires a post-incident review.

    ASSERT-35CBD578B90144A3A0F121BFCBF379EF · v1
  11. - A Severity 1 response must continue uninterrupted until service is restored.

    ASSERT-3E25451EEA3FD410AD1F58C5E371A085 · v1
  12. - Information Security owns evidence handling for a security incident.

    ASSERT-406ED7717DF586090DDA7870E3179962 · v1
  13. - Every responder must preserve logs relevant to an active incident.

    ASSERT-441C1BA3AA70E9EDD3B6FCF6110ED532 · v1
  14. - The incident commander may authorize an emergency change during a Severity 1 incident.

    ASSERT-4D2BD971CDA24A2944239DB053A8DB96 · v1
  15. - Severity is assigned by the on-call operations lead at declaration.

    ASSERT-4EF31471F2226F31453C97A4DEA959EA · v1
  16. - The Field Operations Director owns this standard.

    ASSERT-547B9D8FEA152932096E3BB424871906 · v1
  17. - An exception to a response window requires Field Operations Director approval.

    ASSERT-55AE9E837E640EDB4928EEBFD3FEFC3A · v1
  18. - This standard applies to every operational incident affecting a Compass One service.

    ASSERT-56102F42528320EC13DA201E387500C9 · v1
  19. - Severity 3 is an incident with limited impact on a single customer.

    ASSERT-562E30E5FB7C9B61E77F3D9B87943AFC · v1
  20. - The Technical Support Director owns customer notification.

    ASSERT-57E8EBF53538B6FF810BB0DE7C7CB41C · v1
  21. - External communication requires approval from the VP Customer Experience.

    ASSERT-63AF62119BF4AFF93E11C70F2D8C7616 · v1
  22. - A Severity 1 incident lasting beyond four hours requires continuity plan activation.

    ASSERT-6F2C153C2F40AA7F364F96544908D3F1 · v1
  23. - The incident commander is the individual accountable for coordinating the response.

    ASSERT-718FE4FF93E141946F3456A5F0D06A54 · v1
  24. - Any responder may raise the severity of an active incident.

    ASSERT-7B15DABF710EFB9C295D39785336BC8F · v1
  25. - A Severity 1 incident requires acknowledgement within fifteen minutes.

    ASSERT-7BB7D0C5B43D5499BE70B77753A6C4D6 · v1
  26. - A safety event involving injury is classified as Severity 1.

    ASSERT-7DA6B6140A5B8266B38484B34C54F441 · v1
  27. - An incident with an available workaround is classified as Severity 2.

    ASSERT-7ECDCE5F58E3B40F27B2F03AC30C9C28 · v1
  28. - Security incident reporting is stated in DOC-SEC-0002.

    ASSERT-80DBEE60AB5D23A8025CD442CB7CC8E6 · v1
  29. - Deletion of incident evidence during an active investigation is prohibited.

    ASSERT-8F63ED7F34F21EBBC16365C953AEAED2 · v1
  30. - A Severity 3 incident requires acknowledgement within one business day.

    ASSERT-9192EB6A4156D52F67844C6E4A1B5148 · v1
  31. - A Severity 1 incident requires a status update every thirty minutes.

    ASSERT-94DCA5A9FDCC99823BEEC81BEB289ED4 · v1
  32. - A Severity 2 incident requires a status update every two hours.

    ASSERT-972DF6B48B8D2719D83FA2FC86CBFD39 · v1
  33. - A Severity 1 incident requires an assigned incident commander within thirty minutes.

    ASSERT-A488009EDC5AC9E375F4356598C0799A · v1
  34. - The incident commander has authority to escalate to any Compass One function.

    ASSERT-AC039A71B122CFD019CAF86FFB699392 · v1
  35. - A post-incident review must identify at least one corrective action.

    ASSERT-AD6F2F41ABBAEB4F28A6825AD2E77232 · v1
  36. - The post-incident review is owned by the incident commander.

    ASSERT-AFCF30A98819DEFAB25CED4D63EED443 · v1
  37. - The on-call operations lead must be notified first for every incident.

    ASSERT-AFF18211BFC0F522166281D83FA1D867 · v1
  38. - Executive notification is directed to the COO.

    ASSERT-B0416DE5D5B0F906B2491981B130CB7C · v1
  39. - An incident is an unplanned event that degrades a Compass One service.

    ASSERT-B43E5082CD26281C4CEF3EB9E9A11BC7 · v1
  40. - A planned maintenance event is not classified as an incident.

    ASSERT-B9EEE8E7EFC1A22559991446078C228B · v1
  41. - A Severity 2 incident requires acknowledgement within one hour.

    ASSERT-BC65947F7BF9F6DC9AC36EE25BE4EB09 · v1
  42. - The incident commander owns all internal incident communication.

    ASSERT-BCAE82F6D59EF3210F3D634B7CA3AAAB · v1
  43. - Severity may be raised at any point during an active response.

    ASSERT-C41FD18B8DB7CB098054F72162180EB6 · v1
  44. - Customer escalation routing is stated in DOC-CUS-0001.

    ASSERT-C4B3FB58C7EF4DC9B13081D5330E35A6 · v1
  45. - A Severity 2 incident requires a review when customer impact exceeds two hours.

    ASSERT-C60235CFF2B3B62A4A35CBB40736AC16 · v1
  46. - A Severity 2 incident requires executive notification when unresolved after four hours.

    ASSERT-D23DED5AC53A34C1B18A5109EE7C0A6C · v1
  47. - A security incident is handled through DOC-SEC-0002 rather than this standard.

    ASSERT-D3F6A2844544944ECE793193646DC77A · v1
  48. - Incident evidence is retained for twenty four months.

    ASSERT-D6DA2F0339BB8171EAEA9518FA02B86B · v1
  49. - Continuity activation requires notification to the COO.

    ASSERT-D7D237A54D98307562CC38B66B1E5774 · v1
  50. - Customer notification for a Severity 1 incident is issued within four hours.

    ASSERT-D7FA281061C5AD57C40A565FE6E50637 · v1
  51. - Speculation about cause is prohibited in customer communication.

    ASSERT-DD9EA3F38CC38810FD23417198448A9F · v1
  52. - The incident commander is accountable for the coordinated response.

    ASSERT-DE8C84CF08DF663782538BF57164E95D · v1
  53. - The post-incident review must be completed within five business days.

    ASSERT-DF72E66D2B030AE3E1B65DCC9A54F36D · v1
  54. - Severity 2 is an incident causing partial degradation of a customer-facing service.

    ASSERT-E383F37F84FA18404253D0AAC7112684 · v1
  55. - An incident involving loss of customer data is classified as Severity 1.

    ASSERT-E74CCF2E6AE43587D04855C51A8365B5 · v1
  56. - The continuity plan is activated by the Field Operations Director.

    ASSERT-E8CEB59AD57A7EF6203CFFBAD79A4F6F · v1
  57. - Information handling requirements are stated in DOC-SEC-0005.

    ASSERT-ECA548EFD92A31CDAF4802FB8C19B82F · v1
  58. - The on-call operations lead is accountable for initial severity assignment.

    ASSERT-F91ACAABDBD2C5477134A3866E52E470 · v1

From the activated intelligence

Suggested questions

These examples are derived deterministically from approved Assertions in the active compiled artifact.

Activated-OI question

What does the policy say about - Every exception must be recorded in the incident record?

Ask this question
Activated-OI question

What does the policy say about - A Severity 1 incident requires executive notification within one hour?

Ask this question
Activated-OI question

What does the policy say about - Corrective actions are tracked to closure by the Field Operations Director?

Ask this question
Activated-OI question

What does the policy say about - Severity 1 is an incident causing complete loss of a customer-facing service?

Ask this question
Activated-OI question

What does the policy say about - An incident affecting more than one hundred customers is classified as Severity 1?

Ask this question
Activated-OI question

What does the policy say about - Severity 2 escalation to the executive team requires Field Operations Director approval?

Ask this question

One discipline, four ways to explore

Learn. Understand. Experience. Explore.

Handbook
Learn the discipline.
Guide
Understand the concepts.
Proof Space
Experience Organizational Intelligence.
Research Library
Explore the supporting evidence.