AI Incident Workshop and Runbook
A facilitated incident tabletop for one named AI or automation workflow, followed by a customized operational response runbook.
What you receive
- One sixty-minute preparation call and review of up to ten supplied operational artifacts
- One remote workshop of up to four hours for up to eight participants
- One agreed incident scenario with up to three detection, escalation, containment, recovery, or communication injects
- Decision log, observed gaps, risk-ranked actions, and a customized runbook delivered within two business days
Acceptance
Accepted when the agreed scenario is facilitated, the decision log and risk-ranked actions are delivered, and the runbook covers the named detection, escalation, containment, recovery, and communication steps.
Delivery
Confirm the named workflow, accountable owner, participant roles, date, and time zone before checkout. Includes a thirty-minute runbook handoff after delivery.
Best fit
A team wants to practice how it will detect, escalate, contain, recover, and communicate during a realistic AI or automation incident before the real event forces those decisions.
What we need
One named workflow and accountable owner, preferred date and time zone, participant roles, current architecture or workflow outline, known failure signals, escalation contacts, and recovery method where available.
Not included
- Live production changes, remediation, feature development, or on-call response
- Penetration testing, red-team activity, certification, legal advice, or clinical validation
- 24/7 coverage, guaranteed prevention, restoration, or business outcomes
- Travel, third-party costs, or more than eight participants unless added in writing
Start with a bounded decision.
Confirm the named workflow and workshop date before checkout. If the engagement is not a responsible fit after intake, NorthStar will decline and refund rather than invent scope.
Prices are USD. No revenue, uptime, restoration, security, compliance, or business-performance result is guaranteed. Work begins only after the named system, access boundary, schedule, response window, and accountable contact are confirmed in writing.