Post-incident review
Understand what an AI system did during an incident.
Review agent actions, retrieved content, tool calls and security controls to establish what is known about an incident and what remains unresolved.
What you receive
What the engagement covers.
- Technical reconstruction
- Artifact-quality review
- Timeline and system-state notes
- Control and logging gaps
- Customer, counsel, or executive readout support
01
Review focus
- Agent actions, tool calls, retrieval paths, prompts, outputs, approvals, logs, and configuration state.
- Security controls, identity posture, access changes, audit logs, and remediation steps.
- What is known, what is uncertain, and what additional materials would be needed.
Limits
Scope and limitations.
- The review is technical and scoped; it does not replace legal advice or managed incident response.
Next step