What broke
Site P2's TLS certificate was managed by an internal tool, but nobody owned the renewal step. Registrar R1 emailed a 30-day reminder to a forwarding alias that auto-binned mail into a quarantine folder. The certificate expired on a Tuesday afternoon and stayed expired for four hours.
How it was fixed
Configured automatic renewal through Registrar R1, added a "cert expiring in 21 days" alert into the team channel, and assigned a primary owner for renewals — manual fallback now lives in a runbook with a named on-call, not an alias.
Monitoring rule that would have caught it
Alert on cert expiry at the 30, 14, 7, 3, and 1-day marks. If your cert issuer has automatic renewal, monitor that it actually fired — most "expiry" incidents are really "auto-renew failed silently" incidents in disguise.