
Incident Response Strategic Command
Coordinate incident response with strategic guidance and decision frameworks
What You Can Do
You get immediate structured incident assessment and response coordination. Claude analyzes incident severity, impact scope, and escalation requirements—then generates decision trees, stakeholder communication templates, and post-incident review guides. This skill accelerates your response from triage through resolution to after-action review.
Features
Assess severity, scope, and customer impact using structured decision matrices
Determine who to notify and when based on incident class and business impact
Build a chronological narrative of events and responder actions for clarity
Generate email and Slack messages tailored to different audiences
Structure blameless RCA with root cause analysis and preventive actions
Create actionable task lists for parallel workstreams during active response
Quantify customer-facing downtime, revenue impact, and data exposure
Monitor resolution steps and estimate recovery timeline
Example Output
Example 1: Database Failover Incident
Incident Assessment:
- Severity: P1 (customers unable to login)
- Scope: 45% of user base affected for 23 minutes
- Root Cause: Replica lag on failover cascade
- Status: Resolved at 2:47 PM UTC
Immediate Actions:
- ✓ Alert on-call SRE team (completed 2:12 PM)
- ✓ Notify customers via status page (completed 2:14 PM)
- ✓ Rollback replica config to stable state (completed 2:35 PM)
- → Schedule RCA for tomorrow 11 AM
Stakeholder Message Draft: To: Premium Customers | Subject: Incident Resolution Update "We experienced a 23-minute authentication outage from 2:12–2:35 PM UTC affecting ~45% of users. The issue has been resolved. We're conducting a thorough review and will share findings within 48 hours."
Example 2: Post-Incident Review Output
RCA Summary: Replica sync lag exceeded failover threshold during routine maintenance.
Preventive Actions:
- Implement pre-flight check for replica lag (owner: Infrastructure, due in 2 weeks)
- Add monitoring alert for lag >5s (owner: Platform, due in 1 week)
- Update runbook with manual recovery steps (owner: SRE, due in 3 days)
What's Included
- SKILL.md: Incident response prompts and decision frameworks
- Assessment templates: Severity classification matrix, impact estimation worksheet
- Communication templates: Customer notification, executive briefing, post-incident review
- Response checklists: Triage steps, escalation criteria, resolution tracking
- How-to guide: Step-by-step incident coordination workflow with real examples
Who It's For
- On-call incident commanders — Coordinate response and make real-time escalation calls
- SRE/platform engineering teams — Assess system impact and manage cross-team response
- Incident response coordinators — Document events and track resolution progress
- Engineering managers — Run post-incident reviews and identify systemic improvements
- Security teams — Respond to security incidents with structured assessment and containment steps
Best For
- Active incident triage — Quickly classify severity and determine escalation path
- Multi-team coordination — Manage response workstreams and stakeholder communication
- Communication under pressure — Generate customer and executive notifications during response
- Post-incident analysis — Facilitate blameless RCA and action item tracking
- Incident documentation — Build timeline and impact summary for compliance and learning







