Prompt
What should I use for incident runbooks and handoffs?
Latest observation
Sep 30, 2026
OpenAI APIWeb search: off
For incident runbooks and handoffs, use a format that is:
- short enough to use under pressure
- structured enough to reduce ambiguity
- easy to update after incidents
A good default is:
1. Use a standard incident runbook template
Keep every runbook in the same structure. For example:
- Purpose / scope
- Symptoms / when to use this runbook
- Impact
- Immediate actions
- Investigation steps
- Mitigation / rollback
- Escalation contacts
- Handoff notes
- Post-incident follow-up
Store it in a tool the team already uses, like Markdown in Git, Notion, Confluence, or Google Docs—but ideally with version history and search.
2. Use an incident handoff template
Handoffs should be a concise status transfer, not a full report. Include:
- Incident name / ticket
- Current status
- What happened
- What’s been done
- What’s still unknown
- Current owner
- Next actions
- Risks / deadlines
- Relevant links, logs, dashboards, alerts
A common pattern is SITREP (situation report) or SBAR:
- Situation
- Background
- Assessment
- Recommendation
3. Keep it operational, not theoretical
A runbook should tell someone:
- what to check first
- how to confirm the issue
- what safe actions they can take
- when to escalate
Avoid long explanations; optimize for fast execution during an outage.
4. Use tooling that supports live collaboration
For active incidents, pair the runbook with:
- PagerDuty / Opsgenie / Jira incident ticket
- Slack / Teams incident channel
- Shared doc for timeline and handoff notes
5. If you want one recommendation
Use:
- Markdown runbooks in Git/Docs
- A one-page incident handoff template
- A live incident ticket/channel for coordination
If you want, I can give you:
- a copy-paste runbook template,
- a handoff template, or
- a best-practice incident process for your team.