Build the first incident brief while responders work
A timestamped internal brief tracks confirmed impact, evidence, hypotheses, owners, and next update time.
The problem
Responders repeatedly answer status questions while facts, hypotheses, and actions mix together.
What you get
A working system with the steps, tools, checkpoints, and expected return made explicit.
- Setup
- 120 minutes
- Back each week
- 5 hours
- Difficulty
- agentic
Expected return
The working case
A planning estimate, not a guaranteed result. Measure the first four weeks against your own baseline.
240
hours returned per year
At 5 hours/week across 48 working weeks.
1
week to earn back setup
Compare the setup estimate with the weekly time returned.
Operating contract
Input
The source material, constraints, and examples a human would need to do this work well.
Checkpoint
A person reviews judgment calls, sensitive content, unfamiliar tools, and irreversible actions.
Success signal
Track time returned, corrections required, and exceptions. Keep it only if the measured result compounds.
Before you start
- ·A named incident commander
- ·An approved source-of-truth and review template
The steps
- 01
Name incident commander as the accountable owner and define the decision this workflow is allowed to support.
- 02
Collect alerts, logs, status updates, and responder notes; preserve source links, timestamps, and access controls before any synthesis.
- 03
Produce a live incident coordination brief using the approved template. Do not publish externally or declare root cause before confirmation.
Copy this prompt
Create a live incident coordination brief from the supplied evidence. Separate facts, assumptions, and missing inputs. Cite every material claim. Do not publish externally or declare root cause before confirmation. Evidence: [approved inputs]
- 04
incident commander reviews the draft, records the decision or next action, and corrects the source system before distribution.
What it runs on
Where this goes wrong
- Do not let the model act beyond do not publish externally or declare root cause before confirmation.
- Keep sensitive fields out of unapproved tools and retain a human-readable evidence trail.
Definition of done
Run it for four weeks. Then make it earn its place.
- □ Baseline the manual time before launch.
- □ Keep a human approval step for consequential output.
- □ Record corrections and exceptions, not just successes.
- □ Expand, revise, or retire it after the first review.
Build the system around it
Related workflows
If this one stops working, tell us. Three reports in a month and it leaves the library until a person has looked at it again.