When something breaks, one timeline.
Declare an incident, grade it, assemble the response, and keep every status change, note, and decision on one append-only record.

Open
Declare with a title, a severity from SEV1 to SEV4, a commander, and responders. Everyone named is told, and the clock starts.
Mitigated
Impact contained. The status change requires a note, so the timeline says what was done, not just when.
Resolved
Root cause addressed. Link the change that caused it and the change that fixed it; both records now point at each other.
Closed
Post-incident review: what happened, the root cause, and action items that spawn real cards on real boards.
Severity that means something
Four levels, each with a stated meaning, so a SEV1 at 3 a.m. and a SEV4 on Friday afternoon get the response they deserve.
One timeline, append-only
Status changes, severity changes, comments, and links interleave on one record. Nothing on it can be edited or deleted.
Commander and responders
One person owns the response; responders are added and notified as the picture changes. Every addition is on the timeline.
Honest timestamps
Detected, mitigated, resolved, and closed are stamped when the milestone is reached, and they drive MTTM and MTTR in Analytics.
The change that caused it
An incident links to the change request behind it. That link is what makes the change failure rate a measurement instead of a guess.
Wired into the board
Link a board card for the follow-up work. The card shows the incident's severity and status, and links straight back.
Loud where it counts
The module badge shows how many incidents are active, and responders and commanders get email on the changes that matter.
Run the next incident on the record.
The timeline is the record: what was decided, by whom, and when. Roost is in beta and invite-only.