wr-itil:manage-incident

Declare, triage, mitigate, and close incidents with an evidence-first workflow.

4|1|Updated Apr 7, 2026
One-click install
npx skills add https://github.com/windyroad/agent-plugins --skill wr-itil-manage-incident
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: wr-itil:manage-incident
Source: https://github.com/windyroad/agent-plugins/tree/main/packages/itil/skills/manage-incident
Command: npx skills add https://github.com/windyroad/agent-plugins --skill wr-itil-manage-incident

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Declare, triage, mitigate, and close incidents using an evidence-first workflow. The primary goal is to restore service quickly, then hand off to manage-problem for root-cause work.

Core Features & Use Cases

  • Declare, Update, Mitigate, Restore, Close, List, and Link incidents to manage lifecycles end-to-end.
  • Enforce an evidence-first workflow with sections for Observations, Hypotheses (with evidence), and Mitigation attempts.
  • Automatically hand off to wr-itil:manage-problem once service is restored for persistent root-cause work.

Quick Start

Declare a new incident by providing a title or symptoms to start investigation.

Frequently Asked Questions about wr-itil:manage-incident

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I manage an IT incident lifecycle from declaration to service restoration?

You can manage the entire incident lifecycle by declaring, triaging, mitigating, and closing incidents using a structured workflow. This approach enforces documenting observations, hypotheses, and mitigation attempts to restore service quickly.

What is an evidence-first approach for incident management?

An evidence-first incident management approach requires documenting observations, forming hypotheses with supporting evidence, and recording mitigation attempts. This structured workflow ensures service restoration is driven by verified facts rather than assumptions.

How do I link a resolved incident to a root-cause problem workflow?

Once service is restored, you can link the incident and automatically hand off to a manage-problem workflow for persistent root-cause analysis. This ensures incidents are properly migrated for deeper investigation after mitigation.

Can I update and track multiple mitigation attempts during incident response?

Yes, you can update incidents and track mitigation attempts throughout the response process. The structured incident document supports adding observations and hypotheses with evidence to evaluate each mitigation step effectively.

When should I close an incident in IT operations?

You should close an incident once service restoration is confirmed and documented. The evidence-first workflow requires capturing observations and mitigation attempts before closing, ensuring the incident lifecycle is fully resolved before handoff.

Does this incident response workflow support listing and tracking active incidents?

Yes, the incident management workflow supports listing active incidents alongside declaring, updating, and mitigating them. You can track the end-to-end lifecycle of IT operations incidents from declaration through closure.