IOSOR Learn

Failover incident export at 02:00

One night file for failover: switch events, debit ids, and terminal statuses on a single timeline finance and ops can share without brand leaks.

A failover night without a shared file is two stories: ops remembers the switch; finance sees burn and guesses. The 02:00 incident export is one timeline — switch events, debit ids, terminal statuses — so postmortem and close share a clock.

IOSOR is white-label prepaid. USD 20 funds the pilot floor; soft review near USD 1,000/month turns a missing night file into chat archaeology. Path: Primary rail fails: ordered backup without double-debit. Gates: Failover gates before any Live badge. Mid-flight: Partial failover send without double charge. Runbook: Failover ops runbook at live volume. Tags: Failover ledger tags finance can reconcile.

One night file, one incident timeline

Cut UTC at 02:00 and emit one CSV/JSON for the incident window — not three silos. Rows: hold, accept, switch, settle/release, terminal status. Ops and finance open the same artifact; neither invents a second clock.

Timeline: which intents switched, when primary failed, which opaque rail fulfilled, whether money settled once, what buyers saw as terminal truth. Chat is not the system of record.

Fields that must appear at 02:00

Field Why
Incident / window id Bound the night
Intent / idempotency key Same unit across rails
Debit or release id Money truth once
Opaque rail tag Fulfilling path — brand-safe
Switch event + timestamp Primary → backup (or restore)
Terminal status Delivered, failed, released, needs attention
Corridor / channel Mix without brand columns

Missing debit ids force invented joins. Missing switch events force narration. Missing opaque tags leak brands or leave hops unexplained. Hold-fails still belong via Hold fail auto-refund and status truth — releases are rows.

Who consumes the export (ops vs finance)

Ops: pager hand-off, rail-order audit, “did we invent Delivered?” Finance: reconcile burn vs settled units on the same artifact — no upstream portals. Product may sample white-label copy; nobody gets a brand column.

Latency and DLR lag are timestamps and pending rows, not second debits. Lag vs hop: DLR, latency, and failover. Money: Prepaid hold before first debit.

Distinct from wallet month-end export

Wallet month-end export at 02:00 closes the calendar money story (holds, debits, refunds, channel mix). This page is the incident timeline for failover nights — switches and terminals tied to debit ids. Month-end can be green while the 02:00 failover file is missing; do not ship one and claim the other.

Buyer checklist for incident export

  1. One 02:00 file covers switch + debit ids + terminal statuses?
  2. Opaque rail tags present — no upstream brands?

Start with IOSOR

Force a failover before midnight UTC. Next morning open the 02:00 file: one incident id, start and stop, every switched intent, one debit each, opaque tags, terminal status. A missing switched intent means the export is broken — not that ops will remember. This is the night clock, not a timeout rule, not a tenant webhook, and not a Live badge.

IOSOR takeaway

02:00 is the incident clock. If the night cannot be rebuilt from the file, AM and finance cannot close.

Do: read the 02:00 file after every drill and every real night. Don’t: paste chat logs into the invoice pack, or reuse the wallet month-end export as the incident file.

Was this guide helpful?

Related guides