← ITIL 4 CDS: create, deliver, and support services
08 / 9 · 60 MIN

Shift handover and APS autonomy

Demonstrate task-level capability, transfer responsibility and preserve time for validated recovery.

1. Task-level capability

For a fictional funds service, checking batch status does not demonstrate ability to recover it. Build a matrix of concrete tasks: recognize impact, interpret evidence, execute an authorized action, confirm the result and request support. For each person record observed skill, access, tooling and availability. If Rui restores A and Eva restores B, there are two people but no demonstrated substitute per service. Evaluate the rota against absence, version change and failure outside the successful path. A cell without evidence should remain unconfirmed; training attendance should not convert it into approval.

2. Transfer responsibility with acknowledgement

Handover has both information and responsibility. The record should state current impact, timestamped observations, actions and their outcomes, open hypotheses, constraints, next steps and ownership. The receiver confirms understanding and accepts the role. During an ongoing incident, communicate that change to participating teams. A read receipt does not prove acceptance. If the incoming team can only diagnose between 22:00 and 22:20, confirm restoration-capable support during that interval. Do not assume availability from someone who left the rota or solve the problem by sharing credentials.

3. Rehearse boundaries and exceptions

Prepare an exercise without real production: provide a synthetic record with an alert, a version and a stop condition. The person identifies the applicable procedure, explains the permitted action, recognizes when to stop and contacts agreed support. They then check the expected functional result. Record where help was needed and repeat that part with the corrected guide. A rehearsal should match the installed version: queueDepth may exist in the guide but be absent from the system. Validate the meaning and replacement metric rather than memorize an old name. Autonomy may include appropriate escalation; it does not require unlimited access.

4. Coordinate interventions and evidence

If two teams change the same configuration simultaneously, improvement or regression becomes difficult to attribute. Coordination should identify who acts, in what sequence, under which authorization and what observation confirms the effect. Keep a rejected hypothesis, temporary mitigation and confirmed cause distinct. In the reconciliation example, fewer HTTP errors are positive technical evidence; an unreconciled file leaves functional recovery unconfirmed. Communicate both states instead of reducing the situation to green or red. Investigation may continue after mitigation with defined ownership and next steps.

5. Reserve time for validation

Define the deadline by the required outcome. In this exercise, 18 minutes of restoration followed by 12 minutes of validation must finish by 02:00 UTC. The latest mathematical start is 01:30. At 01:25, ten more diagnostic minutes would shift the start to 01:35 and completion to 02:05. This calculation assumes fixed durations, no waiting and no buffer; real operations require evidence and contingency for those assumptions. Do not omit validation to make reporting fit the deadline. If the window is no longer feasible, communicate impact and obtain a decision from the appropriate authority without inventing approval.

6. Workshop and summary

In pairs, one person hands over a record with three hypotheses and the other takes the shift. The first hypothesis was rejected, the second mitigated and the third not tested. The incoming shift should explain what is known, what remains unconfirmed, who takes the next action and when a decision is needed. Swap roles and introduce a 20-minute access gap. The answer should propose explicitly accepted coverage and a short participant update. Summary: capability is task-specific; responsibility needs acceptance; evidence has different states; restoration and validation consume time. These exercises do not replace internal procedures or demonstrate a real team’s readiness.

Validated deadline: 03:00 UTC
Restoration: 16 min
Validation: 9 min
Latest start: 03:00 - 00:25 = 02:35 UTC
Diagnosis until 02:40 => completion at 03:05 UTC
IN PRACTICE

At 02:30 UTC, 16-minute restoration plus nine-minute validation must finish by 03:00. The decision can wait at most five minutes, with no extra buffer.

Common pitfalls

Confusing rota names with capability, reading with acceptance, fewer alerts with recovery and starting with finishing.

Related topics: Incident management · Capacity and knowledge

Take this idea with you

A handover is ready when responsibility is accepted and capability is demonstrated for the agreed scope.

Create account

Reference: SRE Workbook: On-Call · ITIL 4 CDS; observed syllabus v1.0 mirror, 2025 update comparison pending

ITIL® is a registered trademark of the PeopleCert group. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by PeopleCert. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.