Evidence Preservation

Snapshots before clean-up.

Overview

Evidence preservation captures system state before mitigation cleans it up. Logs roll over, dashboards reset, configs change as part of the fix. Without explicit preservation, the postmortem reconstructs the incident from memory and Slack scrolls. With it, the postmortem works from the actual data.

The approach

Three habits make evidence preservation reliable rather than wishful: automate the snapshot capture, document the checklist for on-callers, and review during postmortems whether the right evidence was captured.

Why this compounds

Each preserved snapshot makes the next postmortem better. The team’s investigation capability deepens; cross-incident analysis becomes possible because the data exists; legal and compliance reviews work from real evidence rather than reconstructed memory.