06: Incident Response, Warranty Evidence, and Financial Recovery
Contain the business impact, preserve evidence, and restore only the affected service after verification.
1. Objective and Ownership
At $50,000 in daily spend, uncontrolled exposure can grow while teams debate whether a problem belongs to a supplier, network operator, platform, or buyer. Assign ownership before an incident occurs.
The Incident Commander coordinates decisions. Ad Operations controls campaign exposure. Security handles compromise. Measurement handles event integrity. Finance authorizes credits or refunds. One communicator maintains the client timeline.
2. Prerequisites and Severity Model

| Severity | Example | Initial action |
|---|---|---|
| SEV-1 | Unauthorized access, cross-client data exposure, uncontrolled spend | Immediate containment and executive escalation |
| SEV-2 | Material delivery outage, purchase-event corruption, widespread access failure | Freeze affected changes and assign technical owners |
| SEV-3 | Isolated initial defect or incomplete handover | Quarantine the item and preserve the claim deadline |
Maintain contacts, asset ownership, relevant warranty terms, escalation routes, known-good configurations, and independent access to incident records.
Example internal targets are acknowledgment within 10 minutes and updates every 30 minutes for SEV-1. These become customer commitments only after staffing, monitoring, and contractual approval support them.
3. Execution Procedure
- **Open a single incident record.** Assign incident ID, severity, discovery time, owner, affected tenants, and next update time.
- **Contain the smallest safe scope.** Pause affected spending or exports, revoke exposed credentials, or isolate the defective asset. Expand containment when cross-tenant impact is plausible.
- **Preserve evidence.** Capture timestamps, identifiers, error messages, change history, and redacted state snapshots. Use access-controlled retention; integrity hashes alone do not make evidence tamper-proof.
- **Classify the fault.** Separate initial specification mismatch, access compromise, network failure, platform restriction, payment issue, and measurement defect.
- **Protect contractual deadlines.** File a complete warranty claim promptly where applicable. An internal ticket does not automatically extend a supplier's deadline.
- **Approve remediation.** Select repair, permitted replacement, credit, or refund according to the evidence and governing terms. Record who bears responsibility.
- **Validate recovery.** Repeat the failed acceptance or operational test. Begin with a limited authorized workload before restoring full exposure.
- **Reconcile the outcome.** Link replacement assets, accounting entries, restored permissions, and the final client communication to the original incident.
4. Validation and Release Gates

Separate technical restoration from financial closure. A replacement may work while a credit remains unresolved; a refund does not prove credentials or permissions have been revoked.
For the proposed NoLimit Shopping Proprietary Ledger, make each approved refund operation idempotent. Repeating the same authorized request must not create another credit. Retain the original transaction and post a linked reversal or adjustment instead of deleting history.
Validate tenant scope, permissions, data integrity, and relevant financial balances before closure. Financial actions require the authority specified by the agency's approval policy.
5. Incident Response and Rollback
If remediation fails, return to containment and update the hypothesis. Do not repeatedly replace assets while the underlying configuration or authorization issue remains unresolved.
Never restore compromised credentials from a snapshot. Restore reviewed configuration and issue fresh credentials through supported processes. For suspected personal-data exposure, involve the privacy owner immediately to determine applicable assessment and notification obligations.
Client updates should state confirmed impact, current containment, unresolved questions, responsible owner, and next update time. Avoid unsupported recovery estimates.
6. KPIs and Operating Cadence

Track detection time, acknowledgment time, containment time, restoration time, repeat incidents, claim completion before expiry, and financial reconciliation time.
Run a monthly tabletop exercise covering access compromise, event duplication, payment failure, and supplier nonresponse. Complete a post-incident review with corrective actions, named owners, and due dates. The required output is a closed incident record supported by recovery evidence and reconciled financial actions.



