What problem does it solve?
Incident-response helps teams triage and mitigate production incidents quickly by coordinating severity, roles, mitigation levers, and communication cadence—while explicitly preventing premature root-cause hunting during the first hour.
Core Features & Use Cases
- Severity triage matrix: Classifies incidents (Sev 1–Sev 4) based on user impact, scale, and security/data risk, and sets the right comms cadence.
- Role assignment for clarity: Defines an incident commander, a technical responder, and a comms lead to prevent decision paralysis and context-switching.
- Mitigation-first workflow (60-minute playbook): Runs an ordered sequence—stop the bleeding, preserve evidence, then hand off to root-cause analysis after mitigation.
- Evidence preservation guidance: Captures logs, dashboards, deploy info, and crash artifacts before mitigation removes the failure state.
- Comms templates and hygiene: Provides internal/external update cadences, impact-led messaging, status page templates, and incident channel organization rules.
- Special incident handling: Adjusts steps for data loss/corruption, security incidents, and overlapping incidents.
Quick Start
Use the incident-response skill when the user reports production is down or a Sev 1/Sev 2 alert, and ask it to structure the next 10 minutes as a severity triage with roles, immediate mitigation lever, evidence to preserve, and comms cadence.