# AI Incident Evidence Bundle — Template

Fill this in *instead of* pasting raw logs into an AI assistant. The goal is a
small, correlated, secret-free bundle: enough for good analysis, nothing more.

## Incident
- **Summary (one line):** e.g. "checkout API returning 500s"
- **Detected at (UTC):**
- **Time window shared (UTC):** from ______ to ______  ← keep this tight (minutes, not hours)
- **What changed recently:** deploy / config / traffic / infra?

## Environment (versions, not hostnames)
- **Stack:** Linux distro + version / Docker version / OpenStack release / etc.
- **Component:** which service is failing
- **Where it runs:** managed / self-hosted / k8s / VM (no real hostnames needed)

## Evidence (redacted)
> Keep timestamps, request IDs, status codes, and error strings. Remove secrets by
> deleting their structure. Pseudonymize hosts/IPs/users/customers with consistent
> placeholders (`IP_1` is always the same host) so relationships survive.

```
<paste the minimized, redacted evidence here>
```

## Placeholder legend (keep this LOCAL — do not send it to the provider)
| Placeholder | Real value (local only) |
|---|---|
| IP_1 | |
| DB_HOST_1 | |
| CUST_1 | |

## What I'm asking the assistant
- **Question:** e.g. "Given this evidence, what's the most likely root cause and the next safe diagnostic step?"
- **Constraints:** "Suggest read-only checks first. Flag anything destructive."

## Before I paste — final checks
- [ ] No credentials, tokens, keys, or connection strings (structure removed, not masked).
- [ ] No real hostnames, internal IPs, subnets, emails, or customer identifiers.
- [ ] Time window is as small as still-useful.
- [ ] The placeholder legend stays on my machine.
