Incident alertStarts from Webhook on incident.openedStart from an alert or one-click responder launch.
1Incident Investigator4Correlates current alerts, incidents, and deployment context.Uses4 toolswithORLong-context reasoning modelproduces Strict JSON preserving incidentId and rollbackDeploymentId with evidence and confidencefrom Incident brief
2Incident CommanderChooses the smallest evidence-supported mitigation.Usesno toolswithORConservative reasoning modelproduces Strict JSON with incidentId, rollbackDeploymentId, rollbackReason, and channelUpdatefrom Correlated incident evidence
3Mitigation Operator2Executes the exact rollback and acknowledgement after approval.Uses2 toolswithORStructured output modelproduces Strict JSON with channelUpdate and provider receiptsfrom Reviewed mitigation JSON
4Status Reporter1Posts the verified mitigation state to responders.Uses1 toolwithORConcise writing modelproduces Slack proof and Run Receiptfrom Mitigation receipts
Incident Response TeamDiagnose one active incident, execute only the approved mitigation, notify responders, and preserve a replayable receipt.ForLean engineering and on-call teams handling production incidents