A handover is a document. If yours happens on a call, you have not handed over, you have felt better.
The person receiving it will read it at 03:40 with a pager going and one shoe on. They will not remember your Thursday afternoon voice, your caveats, or the bit where you said "oh and watch out for". Nine years ago I wrote this out as a plain text block that goes in the ticket, not a doc link, and I have changed it twice since.
ON-CALL HANDOVER
from: DW to: AF
window: 2026-06-18 08:00 UTC -> 2026-06-25 08:00 UTC
OPEN
INC-4471 gateway 5xx, sev3, currently mitigated by a rate limit of 40/s
on POST /v1/charges. The limit expires 2026-06-19 12:00 UTC.
Renew it or remove it. Do not let it lapse quietly.
WATCH
ledger replica lag touches 40s around 23:10 UTC, nightly since Tuesday.
Not paging, no alert covers it. Above 120s the payouts job reads stale
balances, which is a money bug and not a latency bug.
CHANGED
gateway 2026.6.17-2 rolled out Wed 17th. First full week on it.
work_mem 64MB -> 192MB on the reporting replica (me, Tue 16th, no ticket).
SUPPRESSED
DiskWillFillIn4h on ledger-3, muted until 2026-06-19 06:00 UTC, OPS-2210.
The mute expires on its own. Do not extend it without reading the ticket.
EXPECTED
PSP maintenance Sat 2026-06-20 16:00-18:00 UTC. Declines will rise.
Merchants in JP will notice first. Support already has the wording.
BROKEN GLASS
Deploying without the gateway: runbook OPS/break-glass, credential in
vault at ops/bg/deploy. I tested it Mon 15th and it worked.
Escalation lives in the rota tool, not in this document.
The window has both ends written into it, in UTC. Not "this week". Two of us were in different countries during the same handover once and both of us were certain we knew when it finished.
OPEN is one line per thing, and every mitigation carries an expiry in the text. A rate limit with no stated end date becomes permanent architecture inside a month. If you cannot say when a mitigation should come off, you are handing over a decision and pretending it is a state.
WATCH is observation and never prediction: what I saw, when, how often, and the number that would make it matter. That last clause does the work. "Above 120s the payouts job reads stale balances" is what turns a graph into an action. Without it, the receiver has to reconstruct my reasoning from scratch at 03:40, which is the one thing a person in that state cannot do.
CHANGED includes the thing with no ticket. Especially the thing with no ticket. Nobody goes looking for a config change from six days ago if there is no record that it happened, and writing "work_mem 64 to 192, me, Tuesday, no ticket" costs me nothing and saves the next person twenty minutes of disbelief.
SUPPRESSED has caught more real problems than any other field in here. Every mute gets an expiry and a ticket. If it has neither, it comes off before I hand over. A muted alert is an alert somebody made a decision about, and if nobody can name the decision then the mute is a lie we are both maintaining.
EXPECTED is other people's calendars that are going to look like our incidents. PSP maintenance, a merchant's sale, a partner rotating a certificate. On a bad week half the pages are somebody else's plan.
BROKEN GLASS is the path that works when the normal path is the broken thing, with the credential location written down. This section exists because of @grep/postmortem-forty-three-minutes-of-502s, where five of the forty three minutes went on working out who was able to deploy while the deploy tool itself was returning 502. It also says I tested it. Untested break glass is decoration.
"Risk for the coming week" was a horoscope. It was wrong most weeks, and being wrong was the smaller problem. It anchored whoever read it on the subsystem I happened to be anxious about on a Thursday, so a real signal somewhere else got a second look instead of a first. WATCH replaced it, and WATCH only holds things that have already happened.
"How was your week" I added myself in 2019, because a manager asked for a wellbeing signal and this looked like a cheap place to put one. It became a field where twelve people in a row wrote "fine". It was theatre, and it sat in the top third of a screen that a tired person was reading for facts. Wellbeing is a real problem and this is not the instrument for it. That field was bullshit and it was mine.
Both surviving rules are really one rule. Everything temporary in the document has a date attached, and nothing in the document is a forecast. Keep it under four hundred words. Longer than that and you are writing a status report for your own comfort, and the person with one shoe on will skim it and miss the rate limit.