Blog
If they have to open Slack, the packet is not done
Chat threads and Drive links are not a tabletop record. What has to live in the file so an assessor can sample the exercise without you.
March 2027. The assessor asks for the September tabletop. You send three things: the calendar invite for 30 September 2026, a Slack link to #inc-tabletop-sep-30, and a Drive folder called IR TTX notes. The channel is archived. The folder 404s because the facilitator left in November. Marcus T, who remembers what Priya decided about prod-db-01, is on leave. That is not a sampling problem. That is a packet that never existed.
A weak packet is a pointer:
Ran IR tabletop 30 Sep 2026. Notes in Slack. Recording in Drive. Team performed well. Gaps TBD.
A strong packet is a file that can leave the room:
2026-09-30, 90 minutes, remote. Scenario: EDR flagged encryption on prod-db-01 at 02:14. Present: Marcus T (incident commander), Priya S (on-call engineering), Sam O (comms). Legal unfilled, no cover. +00:04 Priya isolated prod-db-01. +00:18 Sam held the customer draft pending legal. Plan names Legal as data-exposure owner within 1h; room reached 01:30 with the seat empty. Follow-up: Dana K names a Legal backup by 2026-10-14. Out of scope: no live restore, no customer send.
Both describe the same ninety minutes. Only the second can be sampled in March. The first costs you the exercise: you book another tabletop to produce evidence of the one you already ran, and the findings from September are gone.
Pointers are not the record
A Zoom recording is ninety minutes of people talking. An assessor will not watch it. A Slack export is four hundred messages including the lunch thread. A link to section 4.2 of the IR plan is not a quote of the step the room missed. If the packet needs a fact, the fact has to be in the packet.
The test is simple. Save the HTML, or print it. Hand it to someone who was not there. If they have to ask you what happened, it is not done.
What has to live in the file
Five things. If one is missing, the reader reconstructs, and reconstruction is where "the team performed well" comes from.
- Date and duration as calendar facts. 2026-09-30, 90 minutes. A quarter is not a date.
- A scenario that names a system. Encryption on prod-db-01, not a security incident.
- Attendance by name and role, absences included. Legal unfilled is a finding. "The security team attended" is not attendance. The invite-list post is how to write the roster; this is how to keep it in the file.
- Timed decisions with owners. Who isolated prod-db-01, at what elapsed time, against which facts.
- Gaps with an owner and a due date, plus what was out of scope. The plan-says post is the shape of a gap. Scope that names the restore you did not run stops the file being read as a recovery record.
That is the field list in our free evidence template. Fill it once and download a formatted record. It sits with three other formats in the template library. A sample packet shows the finished artifact with the same seats and the same host.
Write it before the room dissolves
Anything written up from memory after the session closed cannot reconstruct who said what, who stayed silent on an inject, or how long a decision actually took. Those are measured while the room is running, or they are gone. The free template says that on the artifact, because a self-reported write-up is still a reconstruction. Write the five things anyway: a reconstructed file with dates and owners still beats a Slack pointer. Capture during the session if you can, so the silences stay.
Do not paste the chat log into the packet to make up the difference. Do not attach the recording and call it the record. Do not write that the control is satisfied. The file reports facts about an exercise. The person who samples it decides what those facts are worth.
Where the file lives after the day
When a questionnaire asks whether you test incident response, the answer is a pointer to this file, with the date it ran. That is what the free evidence index is for: artifact, what it is offered toward, how old it is, who owns it. Listing the packet there says it exists. It does not say the question is closed.
Keep the tabletop record in the tabletop format. A post-incident review is a different document, with different fields, in the same library. Mixing them is how a decision exercise gets read as a live incident.
Bottom line: put the exercise in a file that can leave the room. If they have to open Slack, you do not have a packet yet.