Boardroom Answers · People & Operations · Operational Excellence
Every vendor is transparent until something breaks. When you have a bad incident, what do I actually see, and when?
The question a Chief Customer Officer (CCustO) asks.
The short answer
Public status page across seven subsystems, a six-stage incident lifecycle where post-review is mandatory, and machine-tracked notification deadlines. The machinery is real; the track record is honestly zero because customers are.
The full executive answer
You see it where everyone sees it: the public status page, which covers seven subsystems — the web application, public API, AI generation, knowledge retrieval, webhooks, billing, and authentication — with the current state of each and the incident's update trail. Our incident model runs a disclosed lifecycle: open, investigating, contained, resolved, post-review, closed — and post-review is a formal stage, not an optional courtesy, so a resolved incident is not done until the review is.
Two design details show the intent. First, the status vocabulary is honest by construction — degraded, partial outage, major outage, maintenance — with roll-up logic that computes the overall banner from the worst component; there is no hand-set "all systems operational" override. Second, the incident model tracks jurisdiction notification deadlines with statuses like pending, imminent and overdue — so if an incident ever touches regulated notification duties, the countdown is machine-tracked rather than dependent on someone remembering.
What I will not claim: a track record. We have no public history of handling a major production incident with customers on the platform, because we are pre-launch — you are evaluating the machinery and the stated policy, not a portfolio of past incidents. The machinery is built and demonstrable; the reputation gets earned the only way it can be.
Grounded in: ITIL 4 incident management with mandatory post-incident review; the notification-deadline tracking mirrors regulatory breach-notification discipline (GDPR-style clocks).
The natural next questions
Related governed answers
- You are one person. When you are asleep and my board portal is down at 2am the night before an AGM, who answers the phone?
- Define your SLA precisely. What is committed, what is measured, what do I get when you miss, and how would I even know you missed?
- Talk me through your escalation matrix. A user hits a bug, it is not an outage but it is blocking their board meeting prep — what is the path and the clock?
Want this answered live, on your data?