Sample Security Decisions guide: Connect monitoring signals to evidence, ownership, and an actionable response process. Placeholder content for reviewing this series.
![[Sample] An alert has fired. Who can respond?](/_next/image?url=https%3A%2F%2Fwww.quillaudits.com%2Flanding%2Fwhy%2Fcard-image-3.1.png&w=1080&q=75)
SAMPLE CONTENT — Placeholder for reviewing this series. The incident example is hypothetical; response actions require protocol-specific authorization and assessment.
The decision
An alert has fired. Who can respond? Confirm the signal, identify the incident owner, and establish which authorized actions are actually available before executing a response.
When it arises
Monitoring reports an unusual transaction, permission change, or activity pattern affecting a live protocol.
Failure path
An alert reaches a shared channel but no responder owns triage. The team assumes a pause control exists. During escalation it discovers that the affected function cannot be paused, delaying an appropriate response.
What to verify
Record the chain, contract, transaction, and timestamp. Validate the signal against on-chain evidence. Identify the on-call owner and escalation path. Check whether pause, role revocation, configuration changes, or other controls exist, who can authorize them, and their expected side effects. Follow the agreed runbook rather than assuming every alert warrants the same action.
Evidence to request
Alert rule and payload, transaction traces where available, relevant state changes, responder contacts, authority inventory, tested runbook, proposed action calldata, and an incident timeline.
Scope and limits
An alert is a signal to investigate, not proof of an exploit. Response controls can have limited coverage, delays, and consequences for users. An audit does not replace an operational response plan.
Relevant example — hypothetical
A permission-change alert fires. The responder checks the transaction and discovers a scheduled governance change, then records why no emergency action is required.
Related reading
OpenZeppelin Monitor documentation: https://docs.openzeppelin.com/defender/module/monitor
QuillAudits research: https://www.quillaudits.com/research
Next step
Rehearse the escalation and authorized response paths in a safe environment, and update the runbook when deployed controls change.
Contents

From day-zero risk mapping to exchange-ready audits, QuillAudits helps projects grow with confidence. Smart contracts, dApps, infrastructure, compliance: secured end to end.