Incident Response War Room
Structure an incident response while you stay in control. The Incident Commander runs the phases and keeps a timestamped timeline; the Triage Analyst sets severity and blast radius from evidence; the Containment Planner proposes each action with its risk and the exact way to undo it; the Comms Drafter writes internal, statuspage and customer updates. It proposes and documents - you approve and execute. Nothing is run, nothing is sent, no system is touched.
Overview
Structure an incident response while you stay in control. The Incident Commander runs the phases and keeps a timestamped timeline; the Triage Analyst sets severity and blast radius from evidence; the Containment Planner proposes each action with its risk and the exact way to undo it; the Comms Drafter writes internal, statuspage and customer updates. It proposes and documents - you approve and execute. Nothing is run, nothing is sent, no system is touched.
Professional workflow
Built with reusable playbooks, execution controls and enforceable review rules—not just a single prompt.
- 3 Playbooks
- Sequential workflow
- 7 Enforcement specs
- Human-gated
Participants
4Loop
9- 1
Verify inputs: the incident description, the evidence and the system context. Name what is missing and start the timestamped incident timeline.
Incident Commander — coordinator: runs the phases, gates every action - 2
Assign severity (SEV1–4) and blast radius from the evidence; map the affected users, systems and data before any action is planned.
Triage Analyst — sets severity (SEV1–4) and blast radius from evidence - 3
Propose prioritized contain and mitigate actions, each with its risk and the exact way you would roll it back; nothing is executed.
Containment Planner — proposes actions with rollback; never executes - 4
Human gate: present each containment action for your decision — approve, reject, or dismiss as not needed — with its risk and rollback, and record each decision on the timeline.
Incident Commander — coordinator: runs the phases, gates every action - 5
Draft internal, statuspage and customer updates matched to the severity; use holding lines where facts are unconfirmed. Nothing is sent.
Comms Drafter — drafts status and customer updates; never sends them - 6
Assemble the incident timeline from the evidence; cite each event to its source and mark every unknown as UNKNOWN, never guessed.
Incident Commander — coordinator: runs the phases, gates every action - 7
Facilitate a blameless postmortem: name causes and contributing factors, and turn them into owned, dated action items.
Incident Commander — coordinator: runs the phases, gates every action - 8
Final revalidation: triage evidenced, every containment action decided and recorded, comms drafted, timeline complete, postmortem done, no pending human decision.
Incident Commander — coordinator: runs the phases, gates every action - 9
Close and deliver in one named state - READY_FOR_HUMAN_REVIEW, BLOCKED_AWAITING_HUMAN_DECISION or FAILED_TRIAGE - with the full artifact set declared in the Loop specification.
Incident Commander — coordinator: runs the phases, gates every action
Tools
1Rules
16This is a single-pass response, not an autonomous loop. READY_FOR_HUMAN_REVIEW means the response package and documentation are complete - not that the live incident is resolved. It requires triage done, every containment action decided by you (approved, rejected or dismissed) and recorded, comms drafted, the timeline complete, and the postmortem done, with no pending human decision.
The War Room is not a monitoring system or a SOC, does not perform digital forensics (pair it with a forensics organization), and gives no legal or PR advice. It never executes actions, never sends communications, and never accesses systems on its own.
The Containment Planner hands off each action with its risk and its rollback. The Incident Commander accepts only actions that carry both; an action with no rollback is returned. Each action is then decided by you - approved, rejected, or dismissed as not needed. An action still awaiting your decision holds the package at BLOCKED_AWAITING_HUMAN_DECISION.
The team never acts on systems. It proposes containment, drafts communications and documents the timeline; you execute every action. No command is run, no configuration changed, no system touched by the organization.
If evidence is missing and only you can provide it, the package stops at BLOCKED_AWAITING_HUMAN_DECISION with the exact item named. If the evidence is contradictory and the incident cannot be triaged, it stops at FAILED_TRIAGE with the conflict named. Never a confident response over unknown facts.
You provide: the incident description, the evidence you have (logs, symptoms, known timeline) and the system context. The Incident Commander names what is missing and starts the timeline. The team never invents facts to fill a gap; the human executes every action.
READY_FOR_HUMAN_REVIEW succeeds only when triage is evidenced, every containment action is decided and recorded (not merely escalated), comms are drafted to the right severity, the timeline is complete with unknowns marked, and the postmortem has owned action items. A blocked or failed run succeeds only if each open item is named with impact.
The postmortem is blameless: it names causes, contributing factors and the timeline, never individuals. It produces owned, dated action items to prevent recurrence. It is a learning document, not an assignment of fault.
A returned containment action states why it was returned — a missing rollback, an unscoped risk, or a decision that is yours — and what is needed to clear it. 'Do something' without a risk and a rollback is not an actionable step.
The Triage Analyst hands off severity (SEV1–4) and blast radius with the reasoning and the affected users, systems and data. The Containment Planner accepts only a scoped triage; an unscoped severity is returned, not planned against.
Communications are drafts only. Internal notes, statuspage entries and customer updates are written for you to review and send. The team never sends a message, never posts a status, and never contacts a customer.
Every containment action is presented for your explicit decision - approve, reject, or dismiss as not needed - with its risk and rollback, and the decision is recorded on the timeline. Escalating an action for a decision is not the same as it being decided; an action still awaiting you blocks READY_FOR_HUMAN_REVIEW.
The Incident Commander hands off the approved severity and the confirmed facts. The Comms Drafter writes to that severity only; where facts are unconfirmed it writes holding lines, never states as settled what the timeline has not confirmed.
Output ships in exactly one labeled state: READY_FOR_HUMAN_REVIEW, BLOCKED_AWAITING_HUMAN_DECISION or FAILED_TRIAGE. The package is the artifact set declared in the Loop specification: incident summary, severity and rationale, evidence timeline, affected systems and users, containment options with risk and rollback, communication drafts, open questions and human approvals.
The team never invents context. An assumption may only be inferred from the evidence, is marked PROVISIONAL ASSUMPTION citing that evidence, joins the confirmation list, and is not closed until you validate it. A material assumption blocks READY_FOR_HUMAN_REVIEW.
Every event on the timeline cites the evidence behind it. What is not known is marked UNKNOWN, never guessed. The severity and the blast radius state the evidence they rest on, so a reader can see what is fact and what is still open.
Version history
2Professional V2: evidence-based triage, containment planning with risk and rollback, human approval gates, and communication drafts that are never sent.
Initial release
Reviews
0No reviews yet