# AI agent incident-response worksheet

Praesidia · Version 1.0 · Updated 2026-10-03

Use this for an incident or a tabletop exercise. Record verified observations
separately from hypotheses. Keep sensitive evidence in your approved evidence
store and link to it here; do not paste secrets or personal data into the
worksheet. Adapt response and notification steps to your organization's process.

## Incident record

- Incident reference / exercise name: [fill in]
- Declared at (UTC): [fill in]
- Incident lead and backup: [fill in]
- Security / engineering / business contacts: [fill in]
- Severity and rationale: [fill in]
- Status: [investigating / containing / recovering / closed]
- Next stakeholder update (UTC): [fill in]

## 1. What is known

- Detection source and first observation (UTC): [fill in]
- Affected AI systems, agents, identities and workflow runs: [fill in]
- Connected tools, MCP servers and downstream resources: [fill in]
- Confirmed actions and known outcomes: [fill in]
- Actions with unknown outcomes or incomplete evidence: [fill in]
- Suspected cause and evidence needed to test it: [fill in]
- Potential impact: [data / external messages / financial actions / service disruption / other]
- Confirmed impact and the evidence supporting it: [fill in]

## 2. Containment

| Action | Owner | Started (UTC) | Verified (UTC) | Evidence / remaining gap |
| --- | --- | --- | --- | --- |
| Suspend affected workflows or identities | [fill in] | [fill in] | [fill in] | [fill in] |
| Revoke affected credentials and scoped grants | [fill in] | [fill in] | [fill in] | [fill in] |
| Check held actions, approvals, queues and retry paths | [fill in] | [fill in] | [fill in] | [fill in] |
| Restrict affected tool or resource access | [fill in] | [fill in] | [fill in] | [fill in] |
| Coordinate with downstream service owners | [fill in] | [fill in] | [fill in] | [fill in] |

- How did we verify that new affected actions cannot execute? [fill in]
- Which in-flight actions cannot be recalled? [fill in]
- Did the agent bypass the governed path? [confirmed / ruled out / unknown; evidence]

## 3. Preserve evidence and reconstruct the timeline

- Evidence store, custodian and access restrictions: [fill in]
- Audit exports, trace references, model / prompt / tool versions and configuration snapshot: [fill in]
- Integrity checks and any missing records: [fill in]
- Timestamp uncertainty or clock skew: [fill in]

| Time (UTC) | Observed event / action | Caller and target | Known outcome | Evidence reference | Confidence / gaps |
| --- | --- | --- | --- | --- | --- |
| [fill in] | [fill in] | [fill in] | [fill in] | [fill in] | [fill in] |

## 4. Impact and communication

- Affected resources, people, customers or business processes: [fill in]
- Scope of confirmed access and remaining uncertainty: [fill in]
- Stakeholders notified, by whom and when: [fill in]
- Privacy / legal reviewer for applicable notification obligations: [fill in]
- Current update: [verified facts / containment status / unknowns / next update time]
- External communication owner and approval record: [fill in]

## 5. Recovery decision

- Root cause and contributing conditions: [fill in]
- Fixes and compensating controls applied: [fill in]
- Regression tests and controlled replay results: [fill in]
- Credential rotation and permission review complete: [yes / no / not applicable; evidence]
- Conditions required before reenablement: [fill in]
- Recovery owner and explicit approval: [fill in]
- Monitoring window and rollback / suspension criteria: [fill in]
- Known unresolved actions and their owners: [fill in]

## 6. Follow-up review

| Improvement | Owner | Due date | Completion evidence |
| --- | --- | --- | --- |
| [fill in] | [fill in] | [fill in] | [fill in] |

- Review meeting and accountable owner: [fill in]
- What detection, enforcement or evidence gap should be tested next? [fill in]
- Runbook / alert / policy updates: [fill in]
- Next tabletop exercise: [fill in]

## Reading

- Readiness guide: https://praesidia.ai/blog/ai-incident-readiness-checklist
- More templates: https://praesidia.ai/tools

You may copy, edit and share this template within or outside your organization.
