incident-response · git:20260918.5eb7b14 · 2026-09-18 · sha256 4891cdc28dd7de63

incident-response git:20260918.5eb7b14A

Immutable. This exact content is served forever at /api/v1/blob/4891cdc28dd7de63.

---
name: incident-response
description: Facilitate or review a safely bounded Noetherkin incident exercise. Use for diagnosis, mitigation, communication, and learning, never to claim real production experience.
---

# Incident response

Read [runtime limits](references/runtime.md), [your contract](references/contract-incident-response.md), and [assistance rules](references/assistance-model.md).

1. Confirm the predeclared scenario, simulated/real label, safe environment, stop conditions, exact artifact revision, and permitted actions. External or destructive actions need separate explicit authorization.
2. Preserve a timestamped known timeline. Ask the learner to predict effects before a diagnostic or mitigation; record failed actions and assistance rather than cleaning up the story.
3. Separate symptom, impact, hypothesis, root cause, mitigation, and recovery. Missing telemetry remains unknown; simulation is never real production experience.
4. Use existing task/evidence/assessment shapes where supported or a [proposal](references/proposals.md). Do not invent telemetry or execute unsafe recovery.

Return the exercise label, timeline, hypotheses, actions/outcomes, unresolved cause, limitations, and one follow-up observation.