LedgerLens Policy-sealed incident commander for DataHub
SEV-1
ACTIVE COMMAND INC-2042
ELAPSED · REPLAY 00:07:42
RUNTIME MODE FIXTURE / REPLAY
Fixture replay · tools held · live receipts separately labeled

PUBLIC DEMO · SAFE REPLAY · PLAIN ENGLISH

DataHub grounds the plan. Deterministic policy seals exactly what may run.

Agentic loop: sense with DataHub tools → LLM plans allowlisted tool calls → non-model gate seals the exact plan → adapters run → receipt back to DataHub. AI proposes; AI does not authorize.

scroll to walk the pipeline

INCIDENT TRIGGER · SOURCE ASSERTION

Revenue dashboard freshness breach after payments model deploy

payments_daily exceeded its recorded 15 minute freshness SLO. 23 minutes observed against 15 minutes.

SERVICEpayments-analytics OWNEROn-call data platform DETECTED2026-07-31T03:06:18Z STATUScoordinating

01 · DATAHUB CONTEXT

Grounded entity & blast radius

grounded
PRIMARY ENTITY analytics.payments_daily urn:li:dataset:(urn:li:dataPlatform:snowflake,analytics.payments_daily,PROD)
Owner
Data Platform
Domain
Revenue Intelligence
Tier
Tier 1
Platform
Snowflake
8 recorded downstream assets
3 Tier 1 dependencies
AUTHORIZATION BOUNDARY bounded metadata-derived, not causal proof
Asset Type Criticality Relationship
finance.revenue_executive Dashboard Tier 1 1 hop downstream
risk.payment_anomaly_features Feature table Tier 1 2 hops downstream
growth.checkout_health Dashboard Tier 1 2 hops downstream
finance.daily_close_packet Report Tier 2 3 hops downstream

02 · PLANNER OUTPUT

Bounded response plan

PLAN FINGERPRINT 20f3ace20273830b
OBJECTIVE Coordinate bounded response work without asserting unproven causality.
Collaboration fanout and metadata write-back only
  1. 01
    Open an auditable incident work item reversible

    Preserve owner, evidence pointers, and remediation checklist.

    github.issue.create → data-platform/operations
  2. 02
    Notify the bounded incident channel reversible

    Publish the known facts, unknowns, and current authorization scope.

    slack.message.post → #inc-data-platform
  3. 03
    Attach provenance context to the active page reversible

    Give the on-call responder DataHub entity and blast-radius pointers.

    pagerduty.incident.note → PD-INC-PAYMENTS-778
  4. 04
    Create the follow-up recovery task reversible

    Track freshness recovery and post-incident verification separately.

    jira.issue.create → DATAOPS
  5. 05
    Write the bounded response receipt to DataHub reversible

    Keep the entity, action receipts, unknowns, and next owner together.

    datahub.incident.writeback → analytics.payments_daily
EXECUTION BOUNDARY No production rollback or incident resolution is authorized by this plan.

DISAGREE WITH THIS PLAN?

Pick a smaller alternate — same safety lock, new seal

You are not stuck on deny. Swap the AI draft for a human template (or keep the full fanout). Any prior authorization is wiped; the new plan must pass the same deterministic gate before anything runs.

05 · ACTION FANOUT

Provider execution receipts

4 / 4 receipted
succeeded

GitHub

Create incident issue data-platform/operations

Deterministic fixture action recorded.

fixture://github/issues/481
succeeded

Slack

Post bounded incident brief #inc-data-platform

Deterministic fixture action recorded.

fixture://slack/messages/1712.4401
succeeded

PagerDuty

Append incident note PD-INC-PAYMENTS-778

Deterministic fixture action recorded.

fixture://pagerduty/incidents/778/notes/4
succeeded

Jira

Create recovery task DATAOPS

Deterministic fixture action recorded.

fixture://jira/issues/DATAOPS-219

06 · DATAHUB WRITE-BACK

Incident coordination receipt

recorded
ENTITY analytics.payments_daily

Fixture receipt only. No DataHub request or external mutation occurred.

fixture://datahub/writeback/inc-2042/receipt-5f2d
Operation
DataHub incident receipt UPSERT
Aspect
datasetProperties.customProperties
Recorded
2026-07-31T03:14:00Z

07 · INHERITED MEMORY

What the next agent receives

ready
NEXT AGENT Recovery verifier

Bounded collaboration fanout completed in replay; production recovery and root cause remain unverified.

Known facts

  • 4 fixture provider action(s) returned receipts.
  • A fixture DataHub write-back receipt was recorded.
  • No production rollback or incident resolution was authorized.

Still unknown

  • Root cause is not established.
  • End-user impact is not established.
  • Freshness recovery has not been observed.

Next safe actions

  1. Observe a new freshness check before claiming recovery.
  2. Compare deploy and query evidence before assigning cause.
  3. Resolve the incident only through the host system's live policy.
MEMORY RECEIPT fixture://ledgerlens/memory/inc-2042/handoff-1

CLAIM BOUNDARY · ALWAYS ON

Operational metadata, planner proposals, and receipts are not proof of causality.

LedgerLens separates source assertions, DataHub metadata, deterministic policy decisions, AI advisory output, executed action receipts, and unknowns.