| name | incident-response-engineering |
| description | Run and improve technical incident response through severity, command structure, evidence preservation, hypothesis tracking, mitigation, recovery, and follow-up. |
Incident Response Engineering
Use when this procedure is the primary professional method needed for the assignment.
Procedure
- Confirm the decision or outcome this work must support, its scope, owner, constraints, and definition of success.
- Establish the evidence baseline using alerts, logs, traces, deploy history, user impact, mitigation attempts, and decision timestamps. Do not fill material gaps with assumptions when they can change the result.
- Establish impact and incident roles, preserve an evidence timeline, separate mitigation from root-cause work, and validate full recovery before closure.
- Exercise realistic edge, failure, transition, or exception cases that could invalidate the result; record unresolved uncertainty explicitly.
- Validate the output against the original outcome and any neighboring professional contracts so this skill does not silently absorb another specialist's authority.
- Record the resulting artifact, measurements, decisions, provenance, and handoff information needed for another owner to reproduce or continue the work.
Quality gate
Recovery is proven, the timeline is defensible, and follow-up work has owners and acceptance evidence.