Skip to main content

Running the crisis

The shell

Three fixed zones, and they never move: a status bar at the top, a navigation rail on the left, a context panel on the right. The scene changes in the middle.

The status bar carries what you must see without looking for it: severity, time since declaration (H+04:12), title, who is online, and the nearest regulatory deadline.

Two panels survive navigation: the floating video call and the rewind slider. Changing screen does not drop the call.

Two shortcuts: ⌘K to search, ⌘J to log an entry. Logging must stay one gesture, including from the keyboard.

What you do there

The incident log. One-click entry from any context, with a link to whatever prompted it. An entry is corrected without being erased: the original stays, with a pointer to its correction.

Decisions and actions. A decision without an action is an intention. An action without an owner will not be done — the product refuses it. Actions are followed as a list or on a board whose columns are the states; moving a card writes an event to the log.

Cell rooms. One thread per cell, with attachments that go into the document store — a conversation keeps the thread, the store keeps the files.

Video built in, with recording and retention. The recording indicator is permanent: you are told before joining, not after.

Whiteboards, with snapshots filed into the dossier.

Documents: quota, antivirus scanning, SHA-256 and MD5 checksums, time-limited revocable shares.

Call-out across channels, with automatic reminders and escalation to the deputy. A crisis team has nobody whose job is to watch a response table.

Continuity: "what is still running?"

The question the executive committee asks every two hours.

This is not monitoring: nobody probes the IS, somebody looks and declares. Hence the author of each check, and above all its age — "normal, checked six hours ago" is not "normal". With no check, the state is unknown, never normal.

Deadlines: "who to notify, and by when?"

Each stakeholder carries their deadline and the text that grounds it. Without that reference, nobody will know in six months why the countdown existed.

The most misunderstood point

A regulatory deadline runs from when you became aware of the facts, not from when the crisis was opened in the tool. The two almost always differ — sometimes by days.

Kastell starts from the declaration for want of anything better, says so plainly, and lets you date the discovery. That act moves every deadline at once: it requires a reason and is written to the log.

A passed deadline is shown as negative rather than disappearing. Better to notify late than not at all — and to say so in the notification.

External monitoring

What is being said outside: RSS and Atom feeds — press, CERT advisories, leak sites — Bluesky, Mastodon, or any HTTP provider.

The collected feed does not enter the log. Only a signal someone keeps is written, into the incident log, with its source and its original publication time.