Initial notification essentials

  • Formula: time of detection + what is affected + observable impact + who is responding + next update time
  • Template: INCIDENT OPENED [time UTC] — SEV — what — scope — IC — responders — status channel — next update
  • Uncertainty: "root cause: unknown — current hypothesis: [X]" — state what you don't know + your working theory
  • Channels: incident channel (coordination) + PagerDuty (on-call) + team channel (awareness) + status page (customers)
  • Declare on symptom, not root cause — waiting delays response and communication

Question 0 of 5

What must an initial incident notification contain to be actionable?