ops-escalation-runbook

Provide escalation and containment steps for severe AEGIS findings.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/RideMatch1/a.e.g.i.s --skill ops-escalation-runbook
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ops-escalation-runbook
Source: https://github.com/RideMatch1/a.e.g.i.s/tree/main/packages/skills/skills/ops/aegis-native/escalation-runbook
Command: npx skills add https://github.com/RideMatch1/a.e.g.i.s --skill ops-escalation-runbook

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill provides an escalation and containment framework for severe AEGIS findings.

Core Features & Use Cases

  • Immediate containment steps and escalation decision thresholds to prevent further impact.
  • Structured communications templates and notification triggers for security, IT, legal, and executives.
  • Post-incident review structure and forensic tooling guidance to facilitate root-cause analysis and process improvements.

Quick Start

Invoke this runbook immediately when a high-severity AEGIS finding is detected to initiate containment, notification, and post-incident review.

Frequently Asked Questions about ops-escalation-runbook

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is an escalation runbook for severe security findings?

An escalation runbook for severe security findings defines immediate containment steps, stakeholder notification triggers, and post-incident forensic review structures to manage critical incidents. It provides structured, auditable guidance mapped to incident severity levels.

How do I initiate incident response containment after a high-severity alert?

To initiate incident response containment after a high-severity alert, invoke the escalation runbook immediately. It establishes decision thresholds for immediate containment to prevent further impact and triggers structured communications for security, IT, legal, and executive stakeholders.

When do I need to trigger legal and compliance notifications during a security incident?

You need to trigger legal and compliance notifications during a security incident when severe findings meet defined escalation thresholds. The runbook specifies notification triggers and provides communication templates to alert legal and executive teams for compliance adherence.

What steps are involved in a post-incident forensic review?

A post-incident forensic review involves analyzing root causes using provided forensic tooling guidance, evaluating the incident response process, and implementing improvements. The runbook defines this review structure to facilitate thorough post-incident analysis and process enhancements.

Can this incident response playbook map to different security incident severity levels?

Yes, this incident response playbook maps directly to different security incident severity levels. It provides ready-to-run playbooks that align containment actions, communications, and escalation thresholds with the specific severity of the detected finding.