Incident Triage Runbook
When to use
A production incident is reported and must be classified and routed. Routine requests do not belong here.
Steps
- Gather the symptom, blast radius, and first-observed time.
- Classify severity using
references/severity-matrix.md. - Page the owning on-call team for that service.
- Open the incident channel and post the initial summary.
Failure handling
- If the owning team cannot be determined, ALWAYS escalate to the incident commander rota.
- NEVER close an incident without a documented resolution.
Example
A report arrives: "Checkout is returning 500s for ~30% of users." Classify against the severity matrix (high blast radius → Sev2), page the checkout on-call, and open the incident channel with the summary.