Skip to content
Buy an exerciseBuy

Free, no signup

The records, and how to write them.

Four formats for the documents people are asked to produce and rarely taught to write. Every field explains what it is for, shows a strong and a weak version, and says what the weak one costs you when somebody reads it. Fill one in and download it.

These run entirely in your browser. Nothing is uploaded, there is no account, and no model is called, which is why there is nothing to sign up for.

The library

Pick the record you owe.

Tabletop evidence pack
Write up an incident response tabletop: attendance including empty seats, a timed decision log, and gaps with owners.
Post-incident review
Write up a real incident: timeline, contributing factors, the notification decision, and action items with owners.
Recovery test record
Record a restore or failover: target against measured RTO and RPO, how you verified the data, and where the runbook was wrong.
Evidence index
The register that turns a three-week questionnaire into a lookup: artifact, what it evidences, how old it is, and who owns it.

Why these are not just headings

The format is the easy half.

Anyone can get a list of section titles for any of these in about ten seconds. What is harder to come by is knowing which sections a reader actually weighs, and which habits quietly make a record worth less: a single root cause, a restore verified by an exit code, an undated index, a gap phrased as a feeling. Those are the parts written out here.

Everything produced is marked as self-reported, because it is. Where a document genuinely cannot show something, each template says so rather than leaving you to find out from somebody else.

Open source

Take them.

All four are on GitHub as plain Markdown, MIT licensed, prose included. Adapt the wording for your own handbook, translate them, or paste a field's guidance into a review comment. If a field's guidance is wrong, or you have hit a failure mode that is not covered, the issue tracker is the right place for it.

The one you cannot write from memory

A record of the exercise itself.

Attributed decisions and how long each one took are measured while the room is running or not at all. ControlDrill facilitates the exercise on your own systems and incident response plan, and the record is already written when you finish. Running one is not by itself the control, and your auditor decides what it is worth.