Skip to main content

Evidence-bound drafts: the incident story, notices and emails

How the incident story, insurer notice, NIS2 early warning, staff note and customer email are drafted from your records, and why nothing is ever sent.

Written for the business owner9 min readUpdated

After an incident, the hard part is often not the fix but the writing: the insurer wants a notice today, NIS2 may want an early warning within 24 hours, your staff are asking what happened, and customers may need an email. Qorionix drafts each of these from what it recorded — the containment plan, its receipts, the report that started it and the NIS2 register — so you start from an accurate draft instead of a blank page.

Where to find them

  • On a containment plan, in the Story and drafts section below the steps.
  • On a NIS2 incident, through Story and drafts in the incident's row.
  • The incident response plan, written before anything happens, has its own page: see Your incident response plan.

On the left is the timeline: every recorded event in order — the employee report, the plan proposed, approved and run, each step done or undone, each NIS2 stage filed. It comes straight from the receipts and is never written by AI. On the right are the drafts you can create for that incident.

The drafts available after an incident, and the plans that include them.
DraftWhat it is forPlans
Incident storyWhat happened, in order, and what was done. For your own records and for anyone who asks.Protect, Complete
Note to staffA short, calm message for your team.Protect, Complete
Close-out email to customersA message to customers with no claim the records cannot support.Protect, Complete
Notice to the insurerA first notice for your cyber insurer.Complete, or the Compliance Autopilot add-on
NIS2 early warningThe values the Article 23 early warning asks for, ready to copy into your authority's form.Complete, or the Compliance Autopilot add-on

A draft your plan does not include is simply not offered. See Plans and what each includes.

How a draft is checked before you see it

Drafting from records only helps if the draft cannot invent things. Each draft is written from a fact set: typed values the platform recorded, such as times, step results and the plan status. Alert titles and descriptions are left out entirely, because an attacker can write those. Then every paragraph Sentinel-Q writes has to pass these checks:

  • Every name, date, number, address and host in it is in the fact set. A paragraph that mentions anything else is thrown away.
  • It contains no link at all. A draft is pasted into an email to an insurer or a customer, and a link there is exactly what a phishing attack would want to plant.
  • It makes no reassurance the records cannot support, such as no customer data was accessed or the incident is fully resolved. The records never prove a negative, so the draft may not claim one.
  • It cites the facts it relies on, and each citation must be a real entry in the fact set.
  • It contains no text that tries to instruct the AI.

A section that fails any check is replaced by the platform's own wording for that section, and the draft says so. If a recorded label itself — a device name, for example — contains text aimed at the AI, the whole draft is written by the platform with no AI involved, and a warning explains why. On plans without AI, or when your monthly drafting allowance is used up, the platform's wording is used throughout. See Grounding: why a confident answer can be refused for the same principle applied to investigations.

What the labels on a draft mean

Written by AI / Written by the platform / Edited by a person
Shown under each paragraph, so you always know where a sentence came from.
Commitment, not measured
A promise, such as we will send an update when the review is finished. Nothing measures whether you keep it.
Records hash
In the footer: a fingerprint of the fact set the draft was written from. Two drafts from the same records carry the same hash, and a draft written after new events carries a different one.
Draft, not reviewed
Nobody has put their name to it yet.

Reviewing a draft

  1. Read it against the timeline

    The timeline on the left is the source of truth. If the draft and the timeline disagree, trust the timeline and redraft.

  2. Choose Mark as reviewed

    Enter your name. This records who reviewed the draft and when. It still sends nothing.

  3. Copy it and send it yourself

    Copy includes the section titles, labels commitments as such, and ends with the records hash, so the recipient can be told which records it was written from.

Drafting again after more events have been recorded produces a new draft from the newer records; the old one stays as it was. Reviewing or drafting needs the permission of the thing the draft is about: response:containment for a containment plan, compliance:breaches for a NIS2 incident.

What to read next

  1. Your incident response plan — the plan written before an incident, with measured controls.
  2. "I think I clicked something": the employee report button — the report that often starts the story.
  3. The EU AI Act and your system card — how AI-written content is disclosed.

Was this article wrong?

If a procedure here does not match what you see, or a limit we described has changed, tell us and we will fix the page. Email us about this article, or see how to get help if you need an answer rather than a correction.

Everything in compliance evidence