Every SOC ends up with the same problem: incident documentation is scattered across chat threads, shared docs, and whatever ticketing tool the org happened to buy. By the time a report is due, half the timeline has to be reconstructed from memory.
IRDoc started as an internal tool to fix that for one team. It's now becoming something we think other teams could use too.
What it does differently
- Timeline-first. The incident timeline is the primary record, not an afterthought bolted onto a ticket.
- Local AI. Report drafting runs against a local Ollama instance -- no incident data leaves your network.
- SharePoint sync. Management gets a live document instead of a stale export.
Where it's headed
The alpha is public now, self-hosted via Docker Compose. If that's useful to your team, try the live demo or grab the code on GitHub.
We'll use this space to write about IR practice, what we're building, and why -- not a marketing feed, just the actual log.