Write down the hour somebody first knew, keep the facts, effects and remedial action beside it, and leave what is notifiable to the named lead who decides it.
An incident opens, and the hour somebody first knew is recorded before anything else about it is.
02
A clock starts on a state of mind, not an event: Article 33 runs from having become aware.
Reason
03
An hour fixed in a meeting leaves no system record, so whatever evidences it is gathered and held.
04
A breach sits below the notification threshold, and Article 33(5) still requires it documented.
05
A deadline passes, and Article 33(1) reads where feasible, so a late notice carries its reasons.
Decide
06
A high-risk breach reaches Article 34, which carries no seventy-two-hour clock of its own.
07
A determination of materiality is made, and Item 1.05 runs four business days from that, not discovery.
Out
08
An exercise is run, and ISO 22301 keeps clause 8.5 and clause 8.6 apart, voluntary though it is.
09
Execute write actions only inside the approval boundaries agreed during implementation.
→Product statement
Recording, evidencing and clock-keeping belong to the agent. Deciding a breach is notifiable, and notifying anybody, belongs to a named human.
Example workflow
One incident, first hour to filed record
AgentHuman
1Incident openedAlert, ticket, call bridge, supplier notice or somebody saying it out loud
2Awareness evidencedThe messages, pages, bridge joins and tickets that show when somebody first knew, each with its hour
3Record assembledThe facts, the effects, the remedial action and the candidate awareness hour
4Controls appliedSource-hour checks, regime-scope checks, gap checks and awareness confidence
No human action required
Stages 1 to 4 run unaided, and nothing is notified at any of them — the agent is recording, and the lead lane opens at the awareness gate.
5DecisionSplits at the awareness gate
Hour well evidenced
Goes to the named incident lead.
Anything thin
Adds a legal counsel read first.
Lead review
The incident is held with its facts, its evidenced hours and what the record still lacks.
Confirm hour · Add evidence · Send to legal review
Confirmed — by the incident lead▼
6Incident and continuity records updatedOnly where write access and records policy allow it
7Outcome evaluatedHour accuracy, evidence currency, lead corrections and what review found
Corrections
Each incident-lead correction is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Confirming the hour the company became aware.
Deciding that a breach is notifiable.
Notifying a supervisory authority or anybody else.
Determining whether an incident is material.
Automation boundaryAgent acts unaided
✓Collect what shows the hour somebody first knew.
✓Document any breach with its facts, effects and remedial action.
✓Keep the exercise programme and the evidence it left.
✓Show which clock each regime would run from, and from what moment.
Nothing is notified except by a named human, inside the boundaries agreed at implementation.
Judging whether an exercise proved the plan.
Telling a regulator what a timeline means.
Signing a filing that carries a manual signature.
Changes to the classes, the clocks or the contacts.
Example output
One incident record, annotated
This serves an operations team whose notification would name a contact point under Article 33(3)(b) and sign nothing; below is one incident as the agent leaves it.
Incident record · single eventIllustrative example
Incident
Recorded as
Class
Evidence of record
Confidence
Held for
Unauthorised access, one system
Documented, hour evidenced
Personal data breach
Bridge log, 14 August 2026
Held unnotified
The named incident lead
As receivedAssembled from the alert log and the bridge record on file, and it asserts nothing beyond them.
What the record holdsAlert logBridge recordRemedial action
Why no notification hereDeciding a breach is notifiable is a judgement a named lead makes.
ActionConfirm hourAdd evidenceSend to legal review
What the score decidesBelow the configured threshold the incident gets a legal read before the lead sees it.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every incidentFrom the hour it became known
03Evidence
Where the record sits
Banking owns DORA for financial entities, telecom owns the NIS2 Article 23 clocks and admin owns workplace injuries; this is an ordinary company keeping its own record of when it knew.
01Approved path
The clock starts when you knew
Nothing in the stack holds the moment somebody first knew, because it happens in a meeting, on a call, or in the head of the person who noticed.
02Human review
What was checked, and not found
Checked in the current text: CIRCIA has no final rule, and 6 U.S.C. 681b(a)(7) defers even its preservation duty, so nothing there binds today; the Cyber Resilience Act reaches manufacturers from 11 September 2026, not the companies using their products.
04Build an evidence trail
The incident, the hour it became known and the person who knew stay together.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Detection and alertingSIEM · EDR · monitoring Paging and on-call records
Incident and service managementServiceNow · Jira Service Management PagerDuty · Opsgenie · xMatters
A class-level awareness-timing figure can read clean while third-party and supplier incidents carry most of the corrections. Nestack reports the correction rate by incident class, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Third-party and supplier incidents
11.3%
3.7×
Review
Incidents first raised verbally
8.1%
2.6×
Review
Weekend and out-of-hours onsets
5.1%
1.7×
Watch
Routine single-system alerts
2.5%
0.8×
Normal
Bar: correction-rate lift vs. routine-alert baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
What an unrecorded hour costs
The cycle ends when the hour nobody recorded is a regression case. That suite is what the next timeline assembled is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Correction rate rises on third-party and supplier incidents.
02Diagnose
The hour somebody first said out loud that this looked bad, which no system recorded, is worked backwards until one cause is left standing.
03Improve
Changes ship numbered, with the timelines that drove them filed underneath.
04Verify
Nothing ships while one timeline case is still failing.
05Learn
One case joins the suite, one line joins the notification rules.
Learn → DetectThe return edge. The next timeline is measured against a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, incident recording, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Incident-classification and automation-boundary work.
02Alerting, ticketing and bridge sources.
03Awareness-evidence and clock-derivation mapping.
04Incident and evidence ingestion.
05Hour, source and record binding.
06Awareness scoring and review routing.
07Lead confirmation workflow.
08Service-management integration.
09Awareness and timeline cases.
10Guardrails and notification controls.
11Timeline-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne class, one siteProductionProduction incident workflowAdvancedMultiple sites / regimes
Introduced at Pilot
Incident recording to your classes✓✓✓
Named lead confirmation✓✓✓
Dependency-mapping baseline✓✓✓
Introduced at Production
Reporting by incident class—✓✓
Lead review workflow in your systems—✓✓
Approved write-back—✓✓
Alerting-and-paging integration—✓✓
Introduced at Advanced
Multi-regime record sets——✓
Cross-site evidence packs——✓
Large incident volumes——✓
Multi-regime notification controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, incident volume, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your live incident classes and the rule each is scoped to→Class capture and clock derivationWeek 1
02Representative alerts, bridges and exercise reports→Evidence binding, hour logic and the record baselineWeek 2
03Your escalation path and the leads it names→Class mapping, clock derivation and the automation boundaryWeek 1
04Access to relevant APIs, feeds or exports→Alerting, ticketing and bridge-record assessment, then integration setupWeek 2
05Timelines you would not want reconstructed→Awareness cases and the evaluation roundWeek 4
06What no timeline may conclude→Awareness scoring, review routing, guardrails and release controlsWeek 3
07A named incident lead who confirms the hour→Release to the named lead, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
Where the bands overlap, the phases overlap; the fifth week is a measurement and not a compromise.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Class discovery, clock derivation and the automation boundaryW2Source integration and the incident-record baselineW3Evidence binding, awareness logic and release controlsW4Evaluation suite, awareness cases and failure-mode testingW5Service-management integration, pilot incidents and targeted correctionsW6One exercise cycle run under the continuity lead, then Agent Care handover
Reading the bandEach bar covers only the weeks its own work is named for, and week five is shared by design.
At the end of W6When the timeline record validates, Agent Care assumes the agent.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Operations AI agent
Build an incident response agent around the hour nobody wrote down.
Show us one incident from last year and the hour you first knew of it. Every clock here starts on a state of mind — reasonably believes, becoming aware, having become aware, a materiality determination — never on the event. The general US duty is state law, not federal.