Turns incident work, roles, and countermeasures into a tangible result by documenting the incident, describing impact and timeline, and sharing learnings.
Core question: Which system conditions and decision points made the incident possible, and which concrete measures prevent recurrence?
Operating practiceMethod form: Operating practice. Describes how this method is used in practice.MediumComplexity: medium. Estimates preparation, facilitation effort, and method confidence needed.Workshop + asyncFormat: workshop or async. Shows whether the method works in a workshop, asynchronously, or both.
30-90 min
3-12
Run sheet · visual · session plan
Details
DevOpsCategory: DevOps. Describes the method's domain of use.
Turns incident work, roles, and countermeasures into a tangible result by declaring an incident, assigning commander and roles, and closing and reviewing the incident.
Core question: Who is in each role, which effect should be checked next, and when is the next stakeholder update due?
Operating practiceMethod form: Operating practice. Describes how this method is used in practice.MediumComplexity: medium. Estimates preparation, facilitation effort, and method confidence needed.Workshop + asyncFormat: workshop or async. Shows whether the method works in a workshop, asynchronously, or both.
As needed
4-15
Run sheet · visual · session plan
Details
OperationsCategory: Operations. Describes the method's domain of use.
Turns workflows, data, causes, and improvements into a tangible result by defining a scenario, writing steps, and testing and updating.
Core question: Which steps does a trained person execute in which order to handle the trigger safely without having to improvise?
Operating practiceMethod form: Operating practice. Describes how this method is used in practice.LowComplexity: low. Estimates preparation, facilitation effort, and method confidence needed.AsyncFormat: async. Shows whether the method works in a workshop, asynchronously, or both.