Runbook: [Symptom name]
> Organize runbooks by **symptom** (what the responder sees), not only by component.
Runbook: [Symptom name]
Organize runbooks by symptom (what the responder sees), not only by component.
Summary
| Symptom | e.g. Elevated 5xx rate on export API |
| Severity | SEV-1 / SEV-2 / SEV-3 |
| Service(s) | |
| Dashboard | URL |
| Alert | Name / link |
Symptoms
- What alert fires?
- What do users see?
- What metrics move?
Probable causes
Diagnosis steps
- Check …
- Run … (
exact command) - Confirm …
Remediation
Cause 1
- Exact steps
- Exact commands
- How to verify recovery
Cause 2
…
Escalation
| If | Then contact |
|---|---|
| Runbook exhausted | |
| Data loss risk | |
| Security suspicion |
Post-incident
- Incident report filed under
docs/internal/retrospectives/ - Follow-up tickets created
- Runbook updated with what was missing
Last tested
| Date | Environment | Tester | Result |
|---|---|---|---|
| staging / game day |