incident · git:20260831.856ee57 · 2026-08-31 · sha256 e275ca28ca5e07c1

incident git:20260831.856ee57A

Immutable. This exact content is served forever at /api/v1/blob/e275ca28ca5e07c1.

---
name: incident
description: WHAT - Draft and review incident reports and RCA notes using Incident Management guidance;
  includes detection, impact, timeline, RCA, resolution, and follow-ups.
origin:
  type: first-party
---
# Incident (WHAT)

Use for unplanned events that disrupt or degrade production systems, live users, or critical operations.

## Default guardrails

1. Apply **`output-handshake`** before final output.
2. Capture immediate mitigation separately from root cause and follow-up actions.
3. Use **`meeting-minutes`** if a validation or post-incident meeting needs minutes.
4. Create/link follow-up bugs or tasks only after approval.

## References

- `references/default-template.md`
- `references/example-payment-outage.md` — example incident with full timeline, RCA, and action items
- `bug`
- `meeting-minutes`