Evidence-first incident review

The incident is over.
The truth isn’t ready.

OnRecord turns fragmented Slack conversations into a source-linked postmortem your team can verify, revise, and stand behind.

Source linkedHuman approvedHistory preserved
OR
INC-DEMO-1042EU checkout outage
Needs review
SUPPORTED FINDING

An unauthorized WAF rule blocked checkout requests at the edge.

3 sourcesDirectly observed
OPEN QUESTION

How was the authenticated session acquired?

Slack conversationsEvidence graphApproved record

The dangerous part isn’t the blank page

It’s the confident sentence nobody can defend.

During an incident, observations sit beside guesses. Decisions are buried between status updates. Contradictions arrive out of order.

A conventional AI summary smooths that mess into fluent prose. OnRecord does the opposite: it preserves the seams, so a reviewer can see why every conclusion exists.

The actual review workspace

This is product code, not a product rendering.

The window beside this copy loads the same React application used by the authenticated review console. The public demo swaps only the API boundary for validated synthetic state.

Real console components Synthetic evidence External effects blocked
Use the actual interface
ORProduction review UI · synthetic API
Open interactive product

90-second product walkthrough

Watch one incident travel from Slack to an approved Confluence record.

Recorded in a connected test environment with synthetic incident data. Processing and review sequences are visibly accelerated; the approval and publication path is real.

Connected test environment01:30 · Slack to Confluence
Slack intakeAWS evidence pipelineHuman reviewApproved publication

From signal to record

A disciplined path through messy evidence.

No autonomous diagnosis. No one-prompt postmortem. No silent upgrade from “maybe” to “fact”.

01

Scope the incident

Choose the exact Slack channels, time window, threads, and reviewer. Nothing is searched in the background.

02

Build the evidence graph

Messages become cited timeline events, claims, contradictions, and questions—not a loose prompt transcript.

03

Review every conclusion

Keep, edit, exclude, or reclassify each statement while the source evidence stays beside it.

04

Approve one record

Only a human-approved immutable revision can be published to Confluence or Notion.

Show the work

Four product boundaries.
Each one is inspectable.

“Implemented” means code and tests exist. It does not mean a customer environment has already been provisioned.

01

Slack intake

Scope what the system is allowed to see.

A signed Slack shortcut opens a bounded scoping flow: time window, one primary public channel, up to four additional public channels, optional thread anchors, and a named reviewer.

Implemented · requires connected Slack
02

Evidence pipeline

Create the record before writing the story.

Collection is checkpointed. Analysis persists cited timeline events, claims, contradictions, questions, source coverage, model metadata, and token usage before report generation begins.

Implemented · synthetic demo data
03

Human review

Use the same interface reviewers use.

The public demo is a production build of the real review console—not a marketing recreation. Only its API boundary is replaced with validated, in-memory synthetic incident data.

Live in this demo
04

Controlled publication

Publish exactly what was approved.

Approval locks one immutable revision and queues retry-safe publication through configured Confluence or Notion adapters, followed by a final Slack notification.

Implemented · external effects disabled here

Capability ledger

What exists, what runs here, and what comes next.

Verify the review experience
Customer setup

Implemented paths that still require a provisioned customer environment.

  • Slack app installation and approved workspace scopes
  • AWS, PostgreSQL, Cognito, networking, and runtime secrets
  • A destination Confluence space or private Notion data source
  • Operational ownership for retention, alarms, and deployment promotion
Future work

Explicit roadmap—not represented as available product functionality.

  • Slack OAuth installation and token lifecycle management
  • GitHub App evidence collection
  • Enforced retention-deletion jobs
  • Action-item creation and semantic quality benchmarking

Capability status reflects the repository as of July 2026. The public demo never connects to customer systems or publishes externally.

Live system journey

Watch one event become an approved record.

The moving packet follows the implemented production path. It pauses at the human gate because infrastructure can prepare a record, but it cannot approve one.

Tracing event · incident.review.requestedSynthetic animation
01 · Intake

Accept the event durably

Slack official logo

Slack event

Raw signed HTTP request

Amazon API Gateway official architecture icon

API Gateway

Public webhook boundary

AWS Lambda official architecture icon

Ingress Lambda

HMAC + replay verification

Amazon SQS official architecture icon

SQS FIFO

Durable, deduplicated command

AWS Lambda official architecture icon

Worker Lambda

Idempotent incident start

AWS Step Functions official architecture icon

Step Functions

Deterministic orchestration

02 · Evidence pipeline

Collect, structure, and draft

AWS Lambda official architecture icon

Collector Lambda

Bounded Slack history pages

Slack official logo

Slack Web API

Approved channels + threads

PostgreSQL logo

Evidence store

Atomic PostgreSQL checkpoints

AWS Lambda official architecture icon

Analysis Lambda

OpenAI structured extraction

AWS Lambda official architecture icon

Report Lambda

Source-linked draft + validation

AWS Lambda official architecture icon

Notify Lambda

Content-free review-ready link

03 · Human gate + publication

Review, approve, then publish

Amazon S3 official architecture iconAmazon CloudFront official architecture icon

Review console

S3 origin through CloudFront

Amazon Cognito official architecture icon

Amazon Cognito

Authorization code + PKCE

AWS Lambda official architecture icon

Review API Lambda

JWT + membership authorization

PostgreSQL logo

Approved revision

PostgreSQL transaction + outbox

Amazon EventBridge official architecture icon

EventBridge

Bounded publication schedule

AWS Lambda official architecture icon

Publisher Lambda

Leased, retry-safe side effects

Confluence logoNotion logoSlack official logo

Final destinations

Confluence or Notion + Slack

External boundary AWS runtime Durable record Human authority

Secrets Manager supplies scoped runtime credentials to the relevant Lambdas and is intentionally shown outside the event path: secrets configure execution; incident payloads do not travel through it.

The implementation stack

Technology chosen for durable evidence, not demo theatre.

These technologies are present in the repository. Customer infrastructure still requires explicit provisioning.

01

Experience

  • React logoReact 19
  • TypeScript logoTypeScript
  • TanStack logoTanStack Query
  • Radix UI logoRadix UI
  • Amazon Cognito official architecture iconAmazon Cognito
02

Evidence + AI

  • OpenAI BlossomOpenAI Responses API
  • Zod logoZod schemas
  • PostgreSQL logoPostgreSQL
  • AWS Secrets Manager official architecture iconAWS Secrets Manager
03

Workflow

  • Amazon API Gateway official architecture iconAPI Gateway
  • AWS Lambda official architecture iconAWS Lambda
  • Amazon SQS official architecture iconSQS FIFO + DLQ
  • AWS Step Functions official architecture iconStep Functions
  • Amazon EventBridge official architecture iconEventBridge
04

Delivery + release

  • Amazon S3 official architecture iconAmazon S3
  • Amazon CloudFront official architecture iconCloudFront
  • Terraform logoTerraform
  • GitHub Actions logoGitHub Actions
  • Confluence logoConfluence
  • Notion logoNotion

Brand marks identify the technologies used; they do not imply vendor endorsement. AWS service artwork is from the current AWS-approved architecture icon set.

Trust is a product behaviour

The model drafts.
It does not decide.

01

Evidence before prose

The draft is generated from structured, cited claims—not directly from raw conversation.

02

Uncertainty stays visible

Hypotheses, disputes, partial coverage, and unanswered questions cannot be polished away.

03

Approval means something

The model cannot confirm a cause, approve a revision, or create an external effect.

Built with tenant-scoped authorization, immutable revisions, bounded model access, retry-safe publication, and source-content-free operational logs.

Human approval required

Synthetic incident. Production interface.

See what changes when every conclusion has to show its work.

Review the evidence, challenge the draft, and put one revision on the record.

Enter the demo