# Incident response checklist

Use this as a shared response prompt, not as a substitute for your team's runbook. Assign one owner to every open item and record decisions in the incident timeline.

## Declare and establish control

- [ ] Create the incident record and immutable incident reference.
- [ ] Write a factual title that describes the observed problem.
- [ ] Record detection time and the earliest supported impact-start time separately.
- [ ] Set the initial severity with the evidence and assumptions behind it.
- [ ] Record affected services, regions, user journeys, and known customer impact.
- [ ] Mark important unknowns explicitly.
- [ ] Assign the incident lead, technical lead, and communications owner.
- [ ] Set the next internal and external update times.

## Investigate and mitigate

- [ ] Preserve the triggering alert and its source link.
- [ ] Attach relevant dashboards, logs, traces, deploys, screenshots, and tickets.
- [ ] Record each active hypothesis, owner, supporting evidence, and contradicting evidence.
- [ ] Give every action one owner and a clear state.
- [ ] For risky mitigations, record the expected result, rollback path, and validation signal.
- [ ] Add decisions to the timeline with the context available at the time.
- [ ] Reassess severity and customer impact when new evidence changes scope.

## Communicate

- [ ] Publish what is known, what is unknown, what is being done, and who owns the next action.
- [ ] State the next update time even when there is no material change.
- [ ] Keep customer-facing language separate from internal technical hypotheses.
- [ ] Notify security, privacy, legal, or executive owners when local policy requires it.

## Recover and close

- [ ] Confirm customer-facing recovery and internal service health.
- [ ] Watch recovery signals for the agreed stabilization window.
- [ ] Record who accepted the recovery evidence and when.
- [ ] Capture unresolved risks with owners and due dates.
- [ ] Schedule the postmortem and identify the review owner.
- [ ] Preserve the final timeline, impact assessment, evidence, decisions, and follow-up work.

## Final handoff

- Incident lead:
- Technical lead:
- Communications owner:
- Current status:
- Customer impact:
- Next action and owner:
- Next update time:
- Open risks:
- Postmortem date:
