The runbook is a written answer to what happens when something goes wrong, prepared while nothing is going wrong. It covers the first sixty minutes step by step: who is called, what gets contained first, what is preserved before anything is changed, and how affected users are told.
Why it is a control
A generic runbook is useless at two in the morning. The runbook control satisfies Articles 33 and 34 of the GDPR, the breach notification duties, and is checked by the cross-check signal. It passes when the document names your actual components: your auth provider and how to force every session out, your database and how to revoke access, your payment processor and its security contact, the exact steps to rotate each key you hold, and the 72-hour clock. A runbook that could belong to any app fails.
During an incident
An incident in progress is a flag on the ledger, not a number. While a critical or high incident is open, or a leaked key has not been rotated, the flag shows on your dashboard and on any share link. The public page shows nothing about it, because the public page shows only what is proven.
Offline access
If you install VibeLock to your home screen, incident pages you have opened are cached and stay readable without a connection. The one moment you need this document is a moment when other things may also be broken. Open the runbook once after you write it.
Breach notification
Where you have a notification obligation, the runbook records the clock. Under GDPR that is 72 hours from becoming aware of a personal data breach, and the deadline runs from awareness, not from confirmation or from the end of your investigation.
The runbook is not legal advice about whether a given event is notifiable. That determination needs a lawyer, and the runbook tells you to call one.