Incident Monitor Setup Checklist
Use this checklist when setting up Incident Monitor intake, destination routing, security posture, and production governance evidence.
Current GitHub setup
Section titled “Current GitHub setup”- Enable Incident Monitor in
Settings -> Incident Monitor. - Set the GitHub repo in
owner/repoformat. - Select an MCP server with GitHub list, get, create, and comment capabilities.
- Keep
require_approval_for_new_issuesaligned with team policy. - Run status/readiness and confirm GitHub read/write capabilities are available.
- Submit a manual report or external log fixture.
- Create or refresh the triage run.
- Preview or publish only after the draft has enough evidence.
- Confirm the post receipt includes the destination ID, external URL, and evidence digest.
External source setup
Section titled “External source setup”- Add
monitored_projectswith stableproject_id,repo, andworkspace_root. - Add
log_sourceswith stablesource_idvalues. - Set
source_kind, route tags, tenant/workspace IDs, and schema version where known. - Fill
data_readinessfor production sources: owner, system of record, classification, allowed use, lineage/source of truth, freshness SLA, last observation, expected schema version, schema drift status, quality notes, and legal basis or authorization marker. - Set
redaction_profileandretention_profileon projects or source bindings before production routing. - Set
allowed_destination_idsanddefault_destination_idsfor any source that must be constrained. - Create scoped intake keys only for report-only external systems.
- Confirm scoped keys cannot publish, mutate routes/destinations, call tools, or inspect files.
Destination-router setup
Section titled “Destination-router setup”- Define destinations explicitly when moving beyond the legacy fallback.
- Add routes only when default destinations are insufficient.
- Use route preview to confirm matches, readiness, approval, and blocked reasons.
- Enable Linear, webhook, telemetry, memory, and MCP destinations only after their readiness and receipt behavior match deployment policy.
- Treat generic MCP destinations as high risk until
allow_publish, server/tool allowlists, payload mapping, approval policy, and redaction are reviewed. - Preserve
legacy-githubbehavior for old configs.
Security posture preparation
Section titled “Security posture preparation”- Inventory agents, workflows, tools, sources, destinations, approvals, and tenant/workspace context.
- Add deterministic checks before adding controlled probes.
- Make probes authorized, bounded, and dry-run or sandboxed where possible.
- Export evidence to a customer-owned audit destination when assessing Tandem itself.
Production governance preparation
Section titled “Production governance preparation”- Generate deployment cards for Tandem self-monitoring, monitored sources, high-authority agents, and externally mutating workflows.
- Fill owner, accountable team, intended purpose, data classification, approval protocol, escalation protocol, and review cadence metadata.
- Review source-readiness findings from status, route preview, posture checks, assessment reports, and deployment cards.
- Confirm reports, receipts, and protected audit evidence have a customer-owned retention/export policy before production use.
- Map posture findings to customer policy and assign owners before enabling high-risk external destinations.
- Use Production Governance for the full operating-model checklist.