| name | incident-response-desk |
| description | create connector-grounded incident response, bug triage, severity classification, root cause analysis, hotfix handoff, follow-up issue, post-incident review, and production-support artifacts from incidents, alerts, logs, metrics, traces, recent deploys, github issues, pull requests, ci evidence, runbooks, and stakeholder updates. use when Gemini needs to triage a production failure, summarize an incident, draft an rca, plan a hotfix, map remediation work, or prepare downstream handoff notes for implementation-handoff-desk, ci-failure-desk, deployment-desk, observability-readiness-desk, release-operations-desk, verification-desk, or docs-traceability-desk workflows. |
Incident Response Desk
Suite workflow mode
This desk is part of the SDLC Command Desk workflow suite. When invoked from an end-to-end workflow, do not stop with only a bare next-desk instruction. Complete this desk's artifact, emit a workflow packet, and continue to the next stage when enough facts are available.
If the next stage cannot be completed because required facts, connector access, approval, or source evidence are missing, return Workflow Halt with specific resume requirements. Use references/suite-workflow-contract.md for the packet, continuation, and halt format.
Use this skill to create incident-response and production-support artifacts that are grounded in connector evidence. The skill owns triage, severity, impact, timeline, root cause, mitigation, hotfix planning, and follow-up work. It does not invent telemetry, deploy state, customer impact, ownership, or remediation proof.
Operating workflow
Outcome. The artifact the situation calls for: an incident triage brief and action plan for a live incident or active degradation; an RCA or post-incident review for a resolved incident; a bug triage and reproduction plan for a bug report or regression; a hotfix handoff for implementation-handoff-desk; or remediation issues and verification gates for follow-up work.
Grounding. Run connector preflight before producing operational claims. GitHub carries issues, PRs, recent commits, release tags, CI/checks, changed files, and hotfix branches. Observability sources, when available, carry alerts, dashboards, logs, metrics, traces, and SLO/SLA status. Deployment and release docs carry recent deploys, feature flags, rollback plans, and release notes. Incident and communication sources carry status page notes, paging context, and stakeholder decisions. Product and docs sources carry runbooks, support docs, architecture docs, and known-issues docs.