AI Incident Response Runbook Starter
Draft the minimum operator questions for one AI or automation workflow. Edit the boxes in this page, copy the result, or print it. This is a preparation template—not an incident response plan, audit, certification, or substitute for your authorized internal procedures.

1. Declaration and authority
Who can declare, pause, contain, and return this workflow to service?
2. Detection and evidence
What signals prove normal behavior is no longer trustworthy?
3. Containment and fallback
What bounded action stops harm while preserving evidence?
4. Dependencies and escalation
Which providers, models, data sources, queues, and people can block recovery?
5. Recovery and validation
What must be true before this workflow returns to service?
6. Communication
Who needs what facts, at what cadence, through which approved channel?
7. Decision log
Record evidence, authority, choice, and exit check. Blank rows are intentional.
| Time / zone | Observed evidence | Decision | Accountable role | Exit check |
|---|---|---|---|---|
8. Open actions
Convert gaps into owned, dated work rather than unbounded recommendations.
What the paid workshop adds
This starter exposes the questions. The fixed-scope workshop rehearses the decisions with the authorized team and returns a customized operator artifact.
- Preparation call and review of up to 10 supplied operational artifacts
- One facilitated tabletop of up to 4 hours for up to 8 participants
- One tailored scenario with up to 3 incident injects
- Decision log, observed gaps, risk-ranked actions, and customized runbook within 2 business days
No revenue, uptime, restoration, security, compliance, or business-performance result is guaranteed.