{"name":"CapitalGuard Blank AI Agent Incident Response Register","version":"1.0.0","updatedAt":"2026-07-30","canonical":"https://capitalguard.io/guides/ai-agent-security-incident-response-checklist","purpose":"A blank template for documenting an AI-agent security incident, containment, evidence, credential revocation, scope, recovery, monitoring, and residual risk.","limitations":["This register does not itself contain an incident, revoke access, restore systems, or prove that every event was observed.","It is not legal, privacy, compliance, notification, forensic, insurance, or emergency incident-response advice.","Completed records can contain sensitive security, personnel, customer, and architecture metadata and should remain in an authorized private system."],"workflow":[{"id":"stop","label":"Stop","title":"Stop new agent actions without destroying evidence","action":"Name one incident coordinator, record the detection time, pause new agent tasks and schedules, and use an approved containment control when continued tool use could cause harm. Do not delete chats, rewrite repository history, or reset affected systems merely to make the incident look clean."},{"id":"preserve","label":"Preserve","title":"Preserve the smallest useful evidence set","action":"Record agent, session, model, repository, tool, connector, account, and environment references. Export available traces, audit events, diffs, commits, approvals, provider event IDs, and timestamps before retention windows expire. Keep secrets and personal data out of the response register."},{"id":"revoke","label":"Revoke","title":"Revoke authority and rotate exposed credentials","action":"Disable affected tokens, keys, sessions, connectors, app grants, and service accounts at their issuing providers. Rotate a potentially exposed secret before considering repository-history cleanup, and verify each replacement automation uses the new credential with the minimum required scope."},{"id":"scope","label":"Scope","title":"Determine what the agent reached and changed","action":"Build a timeline of files read or changed, commands and tool calls, external destinations, accounts, data types, users, and business processes in scope. Separate confirmed evidence from assumptions, identify required internal escalation, and obtain qualified legal, privacy, or incident-response advice when needed."},{"id":"recover","label":"Recover","title":"Restore a known-good boundary and monitor it","action":"Restore approved configuration and code, reissue only the access still needed, test the agent in a constrained environment, and monitor the affected repositories, accounts, connectors, and credentials for a defined period. Record residual risks, lessons, owners, and follow-up deadlines before closure."}],"fields":[{"key":"incident_id","label":"Incident ID","purpose":"A non-sensitive internal reference for the incident."},{"key":"detected_at","label":"Detected time","purpose":"When suspicious behavior or exposure was first identified."},{"key":"coordinator","label":"Incident coordinator","purpose":"The person accountable for decisions, evidence, and handoffs."},{"key":"initial_severity","label":"Initial severity","purpose":"The organization's provisional severity and the reason for it."},{"key":"environment","label":"Environment","purpose":"Development, test, staging, production, personal, or other boundary."},{"key":"agent_system","label":"Agent system","purpose":"The agent product, workflow, harness, or automation in scope."},{"key":"agent_session_references","label":"Agent session references","purpose":"Privacy-reduced run, trace, conversation, job, or session identifiers."},{"key":"trigger","label":"Detection trigger","purpose":"The alert, report, observation, or control that started the response."},{"key":"observed_behavior","label":"Observed behavior","purpose":"Facts observed without inferred motive or unsupported conclusions."},{"key":"affected_repositories","label":"Affected repositories","purpose":"Authorized repository references and branches potentially in scope."},{"key":"affected_accounts_and_services","label":"Affected accounts and services","purpose":"Identity, cloud, source-control, SaaS, and local accounts in scope."},{"key":"tool_calls_and_actions","label":"Tool calls and actions","purpose":"Commands, writes, deployments, messages, purchases, or external calls observed."},{"key":"data_types_in_scope","label":"Data types in scope","purpose":"Source code, credentials, customer data, personal data, or business records involved."},{"key":"containment_started_at","label":"Containment start time","purpose":"When the first approved action limited further agent activity."},{"key":"agent_and_job_status","label":"Agent and job status","purpose":"Paused, stopped, isolated, still running, or unknown, with the responsible owner."},{"key":"credentials_revoked_or_rotated","label":"Credentials revoked or rotated","purpose":"Provider-side credential references and completion status, never secret values."},{"key":"connectors_and_sessions_revoked","label":"Connectors and sessions revoked","purpose":"Application grants, connectors, sessions, devices, or service accounts disabled."},{"key":"evidence_locations","label":"Evidence locations","purpose":"Authorized private locations for traces, logs, diffs, exports, and provider records."},{"key":"evidence_privacy_class","label":"Evidence privacy class","purpose":"The handling category applied to the incident evidence."},{"key":"timeline","label":"Timeline","purpose":"Ordered confirmed events, decisions, actions, and owners."},{"key":"impact_assessment","label":"Impact assessment","purpose":"Confirmed and possible technical, data, customer, financial, and operational impact."},{"key":"notification_owner","label":"Notification owner","purpose":"The qualified owner deciding internal, customer, regulator, insurer, or authority notices."},{"key":"recovery_baseline","label":"Recovery baseline","purpose":"The known-good code, configuration, policy, and access state selected for recovery."},{"key":"validation_tests","label":"Validation tests","purpose":"Tests used to confirm containment, credential replacement, and constrained operation."},{"key":"monitoring_window","label":"Monitoring window","purpose":"The defined period, signals, and owner for heightened monitoring."},{"key":"residual_risk_and_actions","label":"Residual risk and actions","purpose":"Unresolved questions, accepted risks, follow-up owners, and deadlines."},{"key":"closed_at","label":"Closed time","purpose":"When the incident coordinator completed the response record."},{"key":"approver","label":"Approver","purpose":"The person who reviewed closure evidence and accepted remaining risk."}],"blankRecord":{"incident_id":"","detected_at":"","coordinator":"","initial_severity":"","environment":"","agent_system":"","agent_session_references":"","trigger":"","observed_behavior":"","affected_repositories":"","affected_accounts_and_services":"","tool_calls_and_actions":"","data_types_in_scope":"","containment_started_at":"","agent_and_job_status":"","credentials_revoked_or_rotated":"","connectors_and_sessions_revoked":"","evidence_locations":"","evidence_privacy_class":"","timeline":"","impact_assessment":"","notification_owner":"","recovery_baseline":"","validation_tests":"","monitoring_window":"","residual_risk_and_actions":"","closed_at":"","approver":""},"primarySources":[{"publisher":"NIST","control":"SP 800-61 Rev. 3 incident response","documentedBoundary":"NIST integrates incident response across cybersecurity risk management and the Detect, Respond, and Recover functions. The publication is organization-wide guidance, not an AI-agent product test, certification, or substitute for a response plan tailored to the organization.","url":"https://csrc.nist.gov/pubs/sp/800/61/r3/final","checkedAt":"2026-07-30"},{"publisher":"NIST","control":"AI RMF Manage function","documentedBoundary":"The AI RMF calls for documented response and recovery, the ability to disengage or deactivate AI systems, post-deployment monitoring, incident communication, and tracked recovery. It is voluntary, use-case agnostic guidance and does not certify this checklist.","url":"https://airc.nist.gov/airmf-resources/airmf/5-sec-core/","checkedAt":"2026-07-30"},{"publisher":"CISA","control":"Cybersecurity Incident and Vulnerability Response Playbooks","documentedBoundary":"The CISA playbooks cover detection and analysis, coordination, evidence collection, containment, eradication, recovery, and post-incident work. They were written for U.S. federal civilian agencies; their agency reporting steps are not general requirements for every organization.","url":"https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf","checkedAt":"2026-07-30"},{"publisher":"OpenAI","control":"Agents SDK tracing","documentedBoundary":"The Agents SDK can trace generations, tool calls, handoffs, guardrails, and custom events, but tracing can be disabled and is unavailable under Zero Data Retention. Trace inputs and outputs can contain sensitive data, so an absent or privacy-reduced trace is not proof that an action did not occur.","url":"https://openai.github.io/openai-agents-python/tracing/","checkedAt":"2026-07-30"},{"publisher":"GitHub","control":"Review and export an organization audit log","documentedBoundary":"GitHub organization audit logs identify recorded actors, actions, and times and can be searched or exported as JSON or CSV. The documented web view covers events from the last 180 days and export limits apply; the log is not a complete record of activity outside GitHub.","url":"https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization","checkedAt":"2026-07-30"},{"publisher":"GitHub","control":"Respond to sensitive data in repository history","documentedBoundary":"GitHub says to revoke or rotate an exposed password, token, or credential before considering history rewriting. Rewriting history has coordination and recontamination risks, and removing repository history does not prove that local or downstream copies were deleted.","url":"https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/removing-sensitive-data-from-a-repository","checkedAt":"2026-07-30"},{"publisher":"Microsoft","control":"Revoke Microsoft Entra user access","documentedBoundary":"Microsoft documents disabling an account, revoking refresh tokens, and disabling registered devices, while warning that access-token expiry and application-issued sessions affect revocation timing. An application must revoke sessions issued under its own authorization policy.","url":"https://learn.microsoft.com/en-us/entra/identity/users/users-revoke-access","checkedAt":"2026-07-30"}]}