Documentation

Operator runbooks

Where operational runbooks live and the incident process for suspected raw-data egress.

Runbook index

Operational runbooks live in the repository under docs/runbooks/. Each runbook lists its trigger, the containment steps, evidence handling and the follow-up regression test.

Suspected raw-data egress (critical)

Any sign that raw production data reached the control plane is treated as a critical incident:

  1. Contain — revoke the affected agents and disable the offending message type at ingress.
  2. Preserve evidence without spreading it — never paste values into tickets, chat or email.
  3. Assess scope — tenants, fields, time window and every sink (database, logs, traces, backups).
  4. Purge — and record each deletion as an audit event.
  5. Notify — a human decision; the runbook never auto-notifies.
  6. Fix at the root — add a failing regression test, then the fix, then a canary to the end-to-end suite.

Lead data (website forms)

Contact and demo requests submitted through the public website are handled by the leads service. Retention and deletion are described in the website privacy notice.

← All documentation