Closing, and accounting for it
Closure, in two steps
Winding down, then final closure. The latter freezes the log, runs a full integrity check and triggers the assembly of the crisis file.
The crisis file
A complete, self-contained export:
- the whole log, with the canonical payload of each event — the one the database actually hashed;
- the hash chain and the head hash;
- the incident log, decisions, actions, situation reports;
- document references and their checksums.
This file can be verified without Kastell. That is the whole point: see Verifying without trusting us.
The after-action review
Twelve indicators computed from the log, not declared: time from declaration to first situation report, average arbitration time, call-out response rate, actions closed on time, applications left unchecked.
What you gave up on counts as much as the rest: dropped actions stay in the log with the reason they were dropped.
Long afterwards
Rewinding stays usable years after closure, on an archived crisis, without degradation — that is what projection snapshots are for.
And the head hash of the log is what you hand to a third party: it fits on one line, and it commits everything before it.