How to Build an Incident Timeline in the First 24 Hours
A practical eight-step method for investigators who need to preserve facts, separate evidence from interpretation, and create a decision-ready incident timeline before memory and operational pressure reshape the story.

Key takeaways
- 01An incident timeline is a decision record, not a polished story written after the investigation is complete.
- 02The first version should preserve what was known, what changed, and what remains uncertain without forcing early conclusions.
- 03Separate observed facts, reported statements, system records, and interpretations so later reviewers can test the reasoning.
- 04Use the timeline to identify control changes, handovers, alarms, approvals, and missed escalation points before asking why the event occurred.
- 05A strong 24-hour timeline ends with named evidence gaps, interim controls, and questions that the next investigation phase must answer.
After an incident, the first version of the story often arrives before the first piece of reliable evidence. A supervisor remembers the last task, a witness remembers the loudest moment, and an operations manager wants to know whether production can restart. If the investigator writes a confident narrative too soon, those pressures can become the investigation.
A timeline creates a better starting point. It records what happened in sequence, which conditions were changing, what people knew at each point, and where the evidence is still incomplete. The method below is designed for the first 24 hours, when the scene, system records, shift handovers, and human recollection can change quickly.
James Reason's work on organizational accidents supports this discipline because an event rarely has one visible cause. The timeline should therefore move beyond the final action and examine the conditions that shaped decisions. Andreza Araujo's experience across more than 25 years of executive EHS work and more than 250 cultural transformation projects reinforces the same practical test: an investigation is useful only when its evidence changes what leaders decide to protect.
What should an investigator prepare before building the timeline?
Prepare a working table with at least five columns: time, event or condition, evidence source, confidence, and open question. Add a sixth column for control relevance when the event involves a critical barrier, isolation, supervision, access, equipment condition, or emergency response.
Do not begin by writing a paragraph called “what happened.” Begin with a blank sequence that can accept contradictions. A useful timeline is allowed to look incomplete because uncertainty is a finding in the first phase, not a writing defect.
Step 1: Set the investigation boundary
Define the event, the people exposed, the work area, and the period that may have influenced the outcome. Include the immediate response, but do not silently expand the scope to every historical weakness at the site.
Write the boundary as a decision statement. For example, the investigation may cover task preparation, equipment isolation, work execution, alarm response, and first notification from the last verified safe condition until the scene was secured.
Verify the boundary with the incident owner and the person responsible for preserving evidence. The boundary is usable when another investigator can explain what belongs in the timeline and what belongs in a separate review.
A common error is to define the event only by the injury or damage. That approach starts too late, because the conditions that made the final action possible may have changed during planning, handover, or authorization.
Step 2: Mark the last known safe condition
Identify the last point at which the relevant task, equipment, or work area was verified to be within the agreed control conditions. The point may come from a field check, an isolation record, a permit, a control-room log, or a supervisor's direct observation.
Record the evidence source and its timestamp rather than relying on a general statement such as “the job started normally.” If the source is a person, preserve the person's wording separately from the investigator's interpretation.
Verification is complete when the team can state what was safe, who checked it, and which conditions were expected to remain stable. If any of those elements are missing, flag the gap instead of filling it with confidence.
Investigators often start with the first abnormal event because it feels more relevant. The last known safe condition is more valuable, since it gives the review a reference point for identifying when the control state changed.
Step 3: Freeze and label available evidence
Preserve physical conditions, access records, alarms, camera footage, permits, isolation documents, equipment histories, radio traffic, digital messages, and relevant shift information. The purpose is not to collect everything. It is to protect the evidence that can confirm or challenge each timeline entry.
Assign an evidence identifier to every item and record who collected it, when it was collected, where it came from, and whether the original remains available. Keep photographs and screenshots linked to the condition they document, because an image without location or time context can be misread.
Verify that critical system data has been exported or placed under retention before routine systems overwrite it. A missing log should be recorded as missing, with the reason and likely effect on the timeline.
Do not edit a source file to make its time format match the rest of the table. Record the original time zone or clock reference and explain any conversion in a note.
Step 4: Build the first sequence from records
Enter the earliest reliable records before interviewing people. Use permits, control-room entries, access data, work orders, inspection records, alarm logs, and communication records to create an evidence-led spine.
Each entry should answer what changed or what decision became possible at that moment. “Worker entered area” is less useful than “access record shows entry after the isolation verification was signed,” provided the record actually supports that statement.
Verify the sequence by checking whether adjacent entries can coexist. A permit closure cannot precede the recorded handover that authorized the work, and an alarm response cannot be credited before the alarm appears in the system record.
A common error is to place every available record into the timeline. Relevance matters. A record belongs when it helps explain exposure, control performance, decision authority, communication, or response.
Step 5: Interview people against the sequence
Use the provisional sequence to guide interviews without treating it as settled truth. Ask each person what they saw, heard, did, understood, and expected at specific points in time. Then ask what information was unavailable when the decision was made.
Separate direct observation from later explanation. A witness may accurately remember a valve position while offering an assumption about why it was open. Both statements can be recorded, but they should not occupy the same evidence category.
Verify material statements against records and other accounts. When accounts differ, preserve the difference and identify the evidence that could resolve it. The goal is not to produce identical memories; it is to locate the condition that needs testing.
Do not conduct the interview as a search for a person to blame. Reason's distinction between immediate actions and latent conditions helps investigators ask how the work was designed, supervised, and supported without excusing unsafe decisions.
Step 6: Add control and decision changes
Overlay the sequence with the controls that should have been present and the controls that were actually available. Mark changes in isolation status, staffing, equipment condition, work scope, supervision, access, weather, workload, and simultaneous work.
For each change, name the decision owner and the verification method. A control that existed on paper but was not checked in the field should appear as a changed or unverified condition, not as a completed control.
Verify the overlay with the control owner and with someone who performed the work. Their perspectives should clarify what the control looked like in practice, while the evidence source determines what can be stated as fact.
The common error is to treat a deviation as an isolated moment. A deviation becomes more important when it changes the next person's options, weakens a handover, or makes the original method impossible to follow.
Step 7: Mark uncertainty without hiding it
Use clear labels such as confirmed, reported, inferred, disputed, and not yet verified. These labels keep the timeline honest while the investigation is still developing.
Write open questions next to the relevant entry rather than collecting them in a final appendix. If the timeline says that a safeguard was unavailable, the adjacent question should identify how that fact will be verified and who owns the follow-up.
Verification is complete when another reviewer can distinguish evidence from interpretation without asking the original investigator to translate the table. This is especially important when leaders need to decide whether to restart work or extend an interim control.
Do not remove a disputed entry simply because it is inconvenient. A contradiction can reveal a weak handover, an unreliable instrument, or a gap in the organization's shared understanding of the work.
Step 8: Convert the timeline into decisions for the next phase
End the first 24-hour review with three outputs: interim controls, evidence gaps, and investigation questions. Interim controls protect people while the analysis continues. Evidence gaps show what may limit the conclusion. Investigation questions direct the next interviews, technical checks, and management review.
Assign an owner and due time to each output, with escalation criteria when the evidence cannot be obtained or the condition remains uncontrolled. The investigation report should change the work, not merely document that a meeting occurred.
Verify the handoff with the person who controls restart, the affected supervisor, and the investigator who will continue the review. Each person should understand which facts are confirmed, which assumptions are prohibited, and which condition would stop the next phase.
A common error is to close the timeline when the table is complete. The timeline is complete enough for the first decision when it makes uncertainty visible and directs action. It is not complete because every question has been answered.
How should leaders review an early incident timeline?
Leaders should ask whether the sequence exposes a change in control conditions before asking which individual action appears closest to the outcome. They should also ask whether the organization had a practical way to detect the change, escalate it, and restore the intended barrier.
A useful review compares the timeline with the control system that leaders believe exists. If the record shows that a permit, alarm, handover, or supervision check did not influence the work as expected, the decision is not to improve the narrative. The decision is to examine the control.
That distinction is consistent with Andreza Araujo's practical approach in Safety Culture: From Theory to Practice, where culture is tested through decisions and repeated work conditions rather than declared values alone. The difference between facts, interpretations, and assumptions should remain visible throughout the review.
FAQ
What is an incident timeline?
An incident timeline is a chronological record of relevant conditions, actions, decisions, alarms, communications, and control changes before, during, and after an event. It should show the source of each entry and identify uncertainty instead of presenting assumptions as facts.
Why should investigators build the timeline in the first 24 hours?
Early work helps preserve system records, physical conditions, shift information, and fresh recollections before the scene changes or people unconsciously fill gaps. The first timeline is provisional, but it gives leaders a disciplined basis for interim controls and evidence collection.
Should an incident timeline include root causes?
It should not turn root-cause opinions into facts. The timeline can show conditions and decisions that require analysis, while a separate evaluation identifies active and latent failures, contributing factors, and corrective actions.
Who should review an incident timeline?
The investigator should review it with people who understand the work, the affected supervisor, and the control owners whose decisions appear in the sequence. Their role is to challenge omissions and clarify evidence, not to negotiate a preferred narrative.
In the first 24 hours, the strongest incident timeline is not the one with the most entries. It is the one that preserves the sequence, separates evidence from interpretation, shows where controls changed, and gives leaders a defensible basis for protecting the next shift.
For more practical guidance, explore the English safety article library. Safety is about coming home, and a disciplined investigation helps leaders protect the conditions that make that possible.
Frequently asked questions
What is an incident timeline?
Why should investigators build the timeline in the first 24 hours?
Should an incident timeline include root causes?
Who should review an incident timeline?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.