Incident Response Runbook

Detection, triage, mitigation, communication, escalation, and recovery proof

Incident Response Runbook Detection, triage, mitigation, communication, escalation, and recovery proof 01 / Signals 02 / Incident Command 03 / Service Mitigation 04 / Recovery Evidence 05 / Stakeholder Communication EX / Escalation + Rollback Detect Triage + mitigate Verify + close Incident command If impact persists SLO Alert · burn rate · Signals › Detect SLO Alert burn rate Page On-call · acknowledge · Incident Command › Incident command › Detect Page On-call acknowledge Triage · scope impact · Incident Command › Incident command › Triage + mitigate Triage scope impact Declare · assign commander · Incident Command › Incident command › Triage + mitigate · SEV-1/2 Declare assign commander SEV-1/2 Contain · stop growth · Service Mitigation › Triage + mitigate Contain stop growth Recover · restore · Service Mitigation › Verify + close Recover restore Verify · SLO + traces · Recovery Evidence › Verify + close · 15 min stable Verify SLO + traces 15 min stable Resolve · final update · Stakeholder Communication › Verify + close Resolve final update Status Update · impact + ETA · Stakeholder Communication › Triage + mitigate Status Update impact + ETA Escalate · specialist · Escalation + Rollback › If impact persists › Triage + mitigate Escalate specialist Rollback · last good · Escalation + Rollback › If impact persists › Verify + close Rollback last good page Legend User UI Agent logic Policy Tool action Context / trace

Ownership First

  • • A page is not an incident until someone owns command
  • • Severity and scope are explicit before mitigation spreads
  • • Escalation names the missing expertise

Recovery Is Evidence

  • • Mitigation can reduce impact without proving recovery
  • • SLOs and traces must stay healthy for a fixed window
  • • The final update follows verification, not optimism

Communication Contract

  • • Stakeholders receive impact, action, and next update time
  • • Rollback remains visible as a deliberate response
  • • Every branch has an owner and observable exit