Incident started_at is an isoformat() string (incident_correlator.py, routers/incidents.py), not a Firestore timestamp like calls. The range bounds were Dates, which Firestore compares by type, so any date range returned zero incidents. Bounds are now UTC ISO strings in the same "+00:00" shape, which order lexicographically by time. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>