AI Incident Workshop and Runbook
A fixed-scope remote tabletop for one named AI or automation workflow. Your team rehearses detection, escalation, containment, recovery, evidence, and communication; NorthStar returns the decision record and a customized operator runbook.
The buying decision
Use this when a valuable AI workflow exists but the people responsible for it have not practiced a realistic failure together. The engagement buys a facilitated decision exercise and an operator-ready artifact—not certification, remediation, or an uptime promise.
Best internal owner
A CTO, VP Engineering, Head of AI, product leader, security leader, or operations owner who can name the workflow and invite the people authorized to stop and recover it.
What is delivered
- One 60-minute preparation call
- Review of up to 10 supplied operational artifacts
- One agreed scenario with up to 3 incident injects
- Facilitated decision and evidence log
- Observed gaps and risk-ranked actions
- Customized response runbook within 2 business days
- One 30-minute runbook handoff
Illustrative four-hour agenda
Sample scenario anatomy
Illustrative only: after a provider or configuration change, an AI workflow begins taking inconsistent customer-facing actions while its ordinary availability monitor remains green.
- Inject 1: a weak signal appears in a support channel.
- Inject 2: the workflow's external tool access becomes part of the suspected path.
- Inject 3: the provider is degraded while leadership needs an accurate update.
The paid scenario is tailored only from the buyer's named workflow and supplied operating context.
Runbook structure
- Scope, owners, backups, and escalation contacts
- Detection signals and declaration criteria
- Containment controls and approval boundaries
- Evidence sources and decision-log procedure
- Dependency and provider escalation paths
- Recovery, rollback, and validation sequence
- Internal and external communication roles
- Open actions with owner and priority
Illustrative decision log
| Moment | Observed evidence | Decision required | Accountable role | Exit check |
|---|---|---|---|---|
| T+12 | Customer report conflicts with normal availability signal | Declare, investigate, or continue monitoring | Incident owner | Named evidence source confirms scope |
| T+28 | External tool action is inside the suspected path | Pause tool use, switch to manual, or isolate one workflow | Technical owner | Risky action can no longer execute |
| T+64 | Provider degradation complicates recovery | Rollback, fail over, or remain safely paused | Recovery owner | Agreed validation checks pass |
This table demonstrates the artifact format; it is not a claim about a prior client incident or a prescription for a live emergency.
Buyer supplies
- One named workflow and accountable owner
- Preferred date and time zone
- Participant names or operational roles
- Architecture or workflow outline
- Known failure signals and recovery method
- Up to 10 relevant, non-secret artifacts
Do not send passwords, API keys, patient data, customer records, or confidential datasets in the first message.
Explicit exclusions
- Live production changes or remediation
- Feature development or on-call response
- Penetration testing or red-team activity
- Certification, legal advice, or clinical validation
- 24/7 coverage or guaranteed outcomes
- Travel, third-party costs, or more than 8 participants unless written into scope
Copy for an internal approval request
Confirm fit before payment.
Send the named workflow, accountable owner, participant roles, preferred date and time zone, current failure signals, and recovery method. NorthStar will confirm fit and scheduling before checkout; if the engagement is not responsible or operable, it will be declined rather than stretched into vague scope.