H3AD-REF / SOC OPS / SHIFT HANDOVER TEMPLATE

Shift Handover.
Context Doesn't Survive A Bad Handover.

A structured template for what a SOC shift handover should cover, and why each field matters. A 24/7 SOC runs on what makes it across the shift boundary: an open investigation, a "watch this" item, an escalation that hasn't been answered yet. A rushed or verbal-only handover is one of the most common ways that context gets lost between analysts who rarely overlap in person. For how pending escalations logged here map to response-time expectations, see the Escalation Matrix.

The Handover Template

Fill this in at the end of every shift, before the incoming analyst logs on. Every field exists because something was lost when it wasn't captured.

Open Work

1. Open Incidents / Tickets
├── Ticket ID: [ INC-XXXX ]
├── Current status: [ triage / contained / eradication / monitoring ]
├── Next action: [ what the incoming analyst does first ]
└── Owner after handover: [ name ]
    // one block per open ticket — don't collapse multiple incidents into a single line

2. Active Investigations, Not Yet Ticketed
├── What's being looked at: [ alert / anomaly / user report ]
├── Why it's being looked at: [ trigger, initial reasoning ]
└── What's inconclusive: [ the specific unanswered question, not "still checking" ]
    // this is the category most likely to get dropped — nothing forces anyone to track it

3. Watch Items
├── What's flagged: [ metric spike / suspicious-but-unconfirmed pattern ]
├── Condition that would escalate it: [ e.g. "second occurrence = open a ticket" ]
└── Not yet an incident — say so explicitly, don't let it read like one
    // a watch item with no defined trigger just sits there until someone finally asks if it's still a thing

4. Pending Escalations
├── Escalated to: [ team / individual / vendor ]
├── Escalated at: [ timestamp ]
└── Response received: [ yes / no — if no, this is still the incoming shift's problem ]
    // an unacknowledged escalation isn't "handled" just because it was sent

Environmental & Time-Sensitive Notes

Context that isn't a ticket or an investigation, but changes how the incoming analyst should interpret what they see.

Environment, Deadlines & Status

5. Environmental Notes
├── Active maintenance windows: [ system, start/end time ]
├── Known false-positive sources active right now: [ rule/source + why it's noisy today ]
└── Tooling or detection outages during the shift: [ what's down, since when, coverage gap it creates ]
    // the incoming analyst needs this before they burn an hour chasing something already known

6. Time-Sensitive Items For Incoming Shift
├── Scheduled calls: [ who, what time, what it's about ]
├── Expected callbacks: [ stakeholder, what they were asked, when they said they'd respond ]
└── Deadlines: [ what's due, when, consequence of missing it ]
    // these are the items where a missed handover has a visible external consequence, not just an internal one

7. Shift Summary Status
└── State it explicitly: "Nothing to report" or "See items above" — never leave this blank
    // a blank handover is indistinguishable from a rushed one; an explicit "nothing to report" is a status, silence is not

Handover Discipline

The template only works if it's used with intent. The habits below are what separate a handover that actually transfers context from one that just looks like it did.

DISCIPLINE

Verbal Handover Alone Isn't Enough

A conversation ends when the conversation ends
A spoken handover carries tone and nuance, but it leaves nothing the next shift — or a third shift two days later, reviewing what happened — can reference back to. A written artifact, filled in and time-stamped, is what survives past the five minutes after the outgoing analyst logs off.
DISCIPLINE

Confirm Understanding, Not Just Delivery

Telling someone isn't the same as them knowing
The outgoing analyst's job isn't done when the items are read out loud — it's done when the incoming analyst can restate the open items back, unprompted. A quick "what's your understanding of INC-1042" catches gaps a one-way readout won't.
DISCIPLINE

"Nothing To Report" Is Still A Status

Silence and a quiet shift look identical until they don't
A blank handover field is ambiguous: did nothing happen, or did the handover get rushed and skipped? Explicitly stating "nothing to report" for a section removes that ambiguity and confirms the section was actually reviewed, not just left empty.
DISCIPLINE

How This Interacts With The Escalation Matrix

The handover records what's pending; the matrix decides what happens next
Pending escalations logged in this template should map to a severity in the Escalation Matrix. If an item has sat unacknowledged past the response window that severity defines, that's the trigger to re-escalate now, not wait for the next handover to raise it again.