Concept and mechanism
A coordinated response distinguishes overall control, technical work, and communication. The incident commander maintains incident state and assigns responsibilities; specialists investigate and execute actions within defined scope; communication keeps stakeholders informed. Role names and combinations vary. In a small event, one person may combine tasks if capacity permits; as workload grows, delegation becomes necessary. Being the most experienced specialist does not imply being the best person to coordinate and execute every repair simultaneously. If the coordinator is indispensable to technical resolution, explicitly transfer coordination before taking that work. The team should know who decides priorities and who executes each action.
Guided application
In a fictional incident, network and middleware teams propose changes to the same connection. Record dependencies and sequence to avoid conflicting changes. Independent investigations can run in parallel, but changes to shared state require coordination. Use a recognized channel and record accessible even when the failed service is unavailable. Escalate to the appropriate on-call role, stating impact, evidence, and the requested task; do not rely solely on a former colleague's personal contact. If the response grows too large, create workstreams with leads reporting to the same coordinator. Define update checkpoints and release participants who are no longer needed while preserving a way to recall them.
Two teams should not change the same connection destination without coordinating sequence.
Common pitfalls
Specialist as mandatory coordinator; uncoordinated changes; paging everyone; personal contact as coverage.
Related topics: Triage and impact · Diagnosis and mitigation · Communication and evidence
Distribute work while keeping authority, context, and changes visible.
Reference: Incident roles and scalable responsibility · Incident management practices 2026-09; scoped Google SRE, PagerDuty and Atlassian examples