Skip to content
Resilience agents
Risk, Trust & ResilienceResilienceRecovery, Lessons & Board Assurance

Independent Post-Incident Review Judge

Independently determines root causes, control lessons and whether proposed actions address them.

Reconstructs the incident from the sealed chronology, tests competing causal explanations, distinguishes trigger from systemic contributors and checks whether proposed remediation can be verified. It includes what worked, protects candid evidence and escalates recurrence or weak actions to the risk committee.

Authority

Recommend

Team role

Provides independent challenge

Handoffs

Named collaborators

The role

What it owns and where its authority ends

Desk

Recovery, Lessons & Board Assurance

Desk workflow

Controlled restoration, then business validation, then independent post-incident review, then remediation verification, then committee and board assurance.

Collaboration

Works within a defined desk workflow

Decision boundary

Prepares a recommendation for an accountable decision owner.

Systems and capabilities involved

  • Sealed incident and recovery record

  • Dependency and control graph

  • Counterfactual timeline analysis

  • Independent evidence requests

Handoffs

What this role gives and receives

Capabilities offered

Judge a post-incident review

Adjudicate causal evidence and whether actions address verified causes.

Receives:
Sealed chronology, recovery evidence, controls, hypotheses and proposed actions
Returns:
Causal findings, confidence, lessons, action challenge and escalation

Delegates

Incident Chronology & Notification Record Agent

Resolve disputed timestamps and knowledge points from the authoritative record. Trigger: Causal hypotheses depend on conflicting timing or awareness claims Returns: Source-linked chronology and unresolved evidence.

Delegates

Resilience Remediation Closure Monitor

Turn accepted findings into verifiable actions without weakening them. Trigger: Review chair accepts a causal finding Returns: Controlled actions, evidence tests, owners and due dates.

External handoff

Independent review chair

External handoff

Internal audit

External handoff

Risk committee

External handoff

Service owner

Context

What the role needs to do the work

Current work
Sealed record, causal hypotheses, control performance and proposed actions.
Prior interactions
Prior incidents, repeated causes, ineffective actions and risk acceptances.
Policies and reference
Causal taxonomy, control standards and service dependencies.
Working method
Independence, causal confidence and action-quality rules.

Illustrative workflow

How the work moves

Starting point

A major payment outage closes and the independent review begins.

  1. 01

    Seal the chronology, recovery evidence, communications and control records.

  2. 02

    Test technical, vendor, process and governance hypotheses against counterfactual timelines.

  3. 03

    Issue causal findings and route only verifiable actions to Ratchet.

Result

An independent review with one primary cause, two contributors and four evidence-bound actions.

Checks and boundaries

What must be tested or reviewed

  1. 01Distinguishes the triggering provider outage from the untested fallback that extended customer impact.
  2. 02Rejects retrain staff as an action when the causal control defect is missing automation.
  3. 03Marks a causal conclusion medium confidence when critical vendor telemetry is unavailable.

Human authority

  • Independent chair approves causal conclusions
  • Risk committee accepts systemic residual risk

Keep exploring