Infrastructure applications often store incident timestamps, categories, and closures with more granularity than leadership wants to read. The mistake is forcing the management report to list every ticket. The opposite mistake is summarizing so hard that the application record and the report no longer match.
Agree on a mapping: which severity levels roll into the management summary, how duration is calculated, and whether reopen events create a new line or update the original. Document that mapping once and reuse it every reporting cycle.
During workshops we ask both application owners and operations leads to annotate the same three past incidents. Disagreements surface fast — usually around when an incident is considered closed for reporting purposes versus closed in the ticketing tool.
Once the mapping exists, the weekly and monthly packs become boring in the best sense: predictable, auditable, and defensible when someone asks how a figure was derived.