Build a useful impact picture
In a fictional funds incident, service A reports eighty affected accounts and B fifty. Twenty appear in both. With the same identifier and period, the union contains 110 accounts rather than 130. If B counts sessions instead of accounts, a mapping is needed before calculating distinct people. Record unit, observation interval, source, and limitations beside the number. Add the affected capability: viewing a position, delivering a file, and validating an outcome are different commitments. At 15:42 the batch is stopped and validated delivery is due at 16:30. Since validation requires twelve minutes after processing, processing must finish by 16:18. There are 36 minutes from observation, but this margin does not prove that a recovery option fits. Request an estimate of the required stages and when the alternative must be decided. These numbers are exercise conditions and do not represent actual bank deadlines.
Divide analysis while retaining coordination
When twelve specialists discuss three hypotheses simultaneously, the call may stop producing clear decisions. A workstream needs a question, lead, participants, intervention boundaries, and checkpoint. Retain a shared view of impact and actions that may affect other workstreams. In this example, network wants to restart X while application collects volatile state from X. Collection is a read, but restart may destroy the observation. Both workstreams also reserved Sofia, who can perform only one exclusive task at a time. There are two different dependencies: X state and Sofia's capacity. Another specialist may resolve the second without resolving the first. Ask the leads for a sequence or alternative preserving the required outcome. Public PagerDuty guidance on complex incidents supports thinking about workstreams and coordination limits; that provider's team names and internal rules are not requirements of your employer. Keep the decision understandable to anyone joining midway through the response.
Confirm tasks and leadership capacity
“Rui compares configurations” is an assignment, not evidence of acceptance, start, or completion. Distinguish these states in the record and request a checkpoint with an outcome or blocker. If the 11:12 checkpoint is overdue at 11:13, establish state and decide support, extension, or an alternative. Do not turn an investigation extension into a recovery promise. If someone identifies data-loss risk, clarify the condition before executing an option popular on the call. An objection may matter without an exact probability. Do not force “yes” or “no” when one consumer is unknown: record uncertainty and the check that may reduce it. When the coordinator repeats requests and misses checkpoints, arrange coverage and handover. A director's arrival does not automatically transfer leadership. Shared state should continue identifying who coordinates, who decides within the local mandate, and who executes each intervention. Authority to coordinate does not itself grant every form of risk acceptance.
Run the model and explain its limits
Save the complete code below as incident-command.py and run python3 incident-command.py. Fourteen checks use fictional data to calculate impact union and time margin, detect declared shared resources, distinguish task states, and analyze handover gaps. A v7 acknowledgment does not cover an action started in v8. Even when fields match, the program checks neither human understanding nor channel availability. It also cannot discover omitted dependencies: an empty intersection means only no conflict in the supplied inputs. Change one action's resource and predict the output difference before running again. Then write a coordination note with impact, incompatible action, required capacity, and next checkpoint. At work, that note must be discussed with the responsible people within the applicable process. This exercise sends no messages, changes no infrastructure, and authorizes no production actions. Treat passing checks as evidence of the model rather than proof of a team's operational competence.
"""Original DR incident coordination model; supplied fictional observations only."""
import hashlib
import json
import platform
from pathlib import Path
from statistics import median
def union_impact(left, right, left_unit, right_unit):
if left_unit!= right_unit:
raise ValueError("Map units and identities before combining populations")
return len(set(left) | set(right))
def interference(actions):
conflicts = []
for i, first in enumerate(actions):
for second in actions[i + 1:]:
resources = sorted(set(first["resources"]) & set(second["resources"]))
people = sorted(set(first["exclusivePeople"]) & set(second["exclusivePeople"]))
if resources or people:
conflicts.append({"actions": [first["id"], second["id"]],
"resources": resources, "exclusivePeople": people})
return conflicts # Possible interference for review, not an execution scheduler.
def task_state(task):
if not task.get("accepted"):
return "assigned-unconfirmed"
if not task.get("started"):
return "accepted-not-started"
if not task.get("completed"):
return "in-progress"
return "completed-result-recorded" if task.get("result") else "completion-claimed-result-missing"
def handover_gaps(current_version, acknowledgment, required_actions):
gaps = []
if acknowledgment.get("version")!= current_version:
gaps.append("state-version")
if not acknowledgment.get("incomingOwner"):
gaps.append("incoming-owner")
missing = sorted(set(required_actions) - set(acknowledgment.get("actions", [])))
if missing:
gaps.append("uncovered-actions:" + ",".join(missing))
return gaps # Empty means only that these supplied fields match.
def reconcile(expected, received):
expected, received = set(expected), set(received)
return {"missing": sorted(expected - received),
"unexpected": sorted(received - expected)}
def run:
checks = []
def check(name, actual, expected):
if actual!= expected:
raise AssertionError((name, actual, expected))
checks.append({"name": name, "actual": actual, "passed": True})
a, b = list(range(1, 81)), list(range(61, 111))
check("overlapping_accounts_are_counted_once", union_impact(a, b, "account", "account"), 110)
try:
union_impact(a, b, "account", "session")
mismatch_rejected = False
except ValueError:
mismatch_rejected = True
check("different_units_require_mapping", mismatch_rejected, True)
observed, due, validation = 15 * 60 + 42, 16 * 60 + 30, 12
processing_due = due - validation
check("sequential_validation_reduces_margin", {"processingDue": f"{processing_due // 60:02}:{processing_due % 60:02}",
"minutesFromObservation": processing_due - observed}, {"processingDue": "16:18", "minutesFromObservation": 36})
actions = [{"id": "restart-X", "resources": ["X"], "exclusivePeople": ["Sofia"]},
{"id": "capture-X", "resources": ["X"], "exclusivePeople": ["Sofia"]}]
check("workstreams_share_target_and_person", interference(actions),
[{"actions": ["restart-X", "capture-X"], "resources": ["X"], "exclusivePeople": ["Sofia"]}])
separate = [actions[0], {"id": "prepare-Y", "resources": ["Y"], "exclusivePeople": ["Luis"]}]
check("no_declared_overlap_is_not_proven_independence", interference(separate), [])
check("task_states_do_not_collapse", [task_state(t) for t in [
{"owner": "Rui"}, {"accepted": True}, {"accepted": True, "started": True},
{"accepted": True, "started": True, "completed": True},
{"accepted": True, "started": True, "completed": True, "result": "comparison recorded"}]],
["assigned-unconfirmed", "accepted-not-started", "in-progress", "completion-claimed-result-missing", "completed-result-recorded"])
ack = {"version": 7, "incomingOwner": "Marta", "actions": ["compare"]}
check("old_acknowledgment_does_not_cover_changed_state", handover_gaps(8, ack, ["compare", "failover"]),
["state-version", "uncovered-actions:failover"])
current_ack = {"version": 8, "incomingOwner": "Marta", "actions": ["compare", "failover"]}
check("matching_fields_do_not_prove_human_understanding", handover_gaps(8, current_ack, ["compare", "failover"]), [])
action = {"approved": True, "executionConfirmed": False, "effectValidated": False}
check("approval_is_not_execution_or_effect", [action[k] for k in ["approved", "executionConfirmed", "effectValidated"]], [True, False, False])
check("equal_counts_can_hide_different_identities", reconcile(["A", "B", "C", "D"], ["A", "B", "C", "X"]), {"missing": ["D"], "unexpected": ["X"]})
check("partial_validation_keeps_residual_visible", len(reconcile(range(240), range(232))["missing"]), 8)
observation, change, received = 14 * 60 + 5, 14 * 60 + 12, 14 * 60 + 20
check("receipt_time_does_not_refresh_observation", {"observationPredatesChange": observation < change,
"receivedAfterChange": received > change, "observationAgeMinutes": received - observation},
{"observationPredatesChange": True, "receivedAfterChange": True, "observationAgeMinutes": 15})
before = [20, 25, 40, 70, 90]
after_exclusion = [20, 25, 40]
check("selection_changes_median_without_new_outcomes", [median(before), median(after_exclusion)], [40, 25])
criterion = {"backlogProcessed": True, "reconciliationAccepted": False}
check("recovery_claim_still_has_validation_gap", [k for k, v in criterion.items if not v], ["reconciliationAccepted"])
return {"scope": "Fictional set, arithmetic and record checks only. No real incident commanded, production authorization, channel availability, human handover comprehension or group exercise is established. Shared-resource checks detect only declared overlaps and do not prove safe concurrency.",
"python": platform.python_version, "scriptSha256": hashlib.sha256(Path(__file__).read_bytes).hexdigest,
"groups": len(checks), "checks": checks}
if __name__ == "__main__":
print(json.dumps(run, ensure_ascii=False, indent=2))Two workstreams share X and Sofia. Coordination identifies both constraints before promising timing; 110 distinct accounts and a 16:18 processing deadline provide decision context.
Common pitfalls
Adding different units; double-booking capacity; treating assignment as execution; resolving risk by popularity; transferring leadership without current state.
Related topics: Impact and priorities · Shift handover · Dependencies and capacity
Divide analysis work while keeping dependencies, capacity, and ownership of the next decision explicit.
Reference: Complex Incidents · Google SRE incident guidance; PagerDuty contextual incident model; NIST SP 800-61 Rev. 3 April 2025; editorial review 2026-10-01