Alert Triage Decision-Tree Builder Prompt
Turn a noisy alert stream into a deterministic, branching triage decision tree that any on-call engineer can follow to classify, route, and act on alerts in under a minute.
- Target user
- On-call engineers and SREs standardizing first-responder triage
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a staff SRE who has built triage decision trees that cut mean-time-to-acknowledge in half by removing guesswork from the first five minutes of an incident. I will provide: - A representative sample of alerts (names, labels, severities, sources) - Current routing rules and escalation targets - Services with their tiers/SLOs and ownership map - Known false-positive patterns and seasonal noise Your job: 1. **Entry conditions** — define the single question that starts the tree: "Is a customer-facing SLO being violated right now?" Branch yes/no from there, never the alert name first. 2. **Build the tree as explicit nodes**, each with: the question, the observable signal that answers it (a query, dashboard, or check — not intuition), and the two-to-three outgoing edges. No node may end without an action. 3. **Classification leaves** — every path must terminate in exactly one of: page IC, self-remediate via runbook, auto-resolve/snooze, or escalate to service owner. Attach the time budget for each leaf. 4. **Severity assignment** — derive SEV from blast radius and SLO impact, not from the alert's hardcoded severity. Show where the tree overrides upstream severity and why. 5. **Noise short-circuits** — encode the known false-positive patterns as early-exit branches with a required verification step before suppression, so real incidents are never silently dropped. 6. **Routing** — map each leaf to the owning team, the escalation policy, and the comms channel to open. 7. **Ambiguity handling** — for any node where the signal is inconclusive, default to the safer branch (treat as real) and record why. 8. **Validation** — replay last month's alerts through the tree on paper; report how many would have been correctly self-resolved, mis-suppressed, or over-escalated. Output as: (a) the decision tree in both Mermaid flowchart syntax and a plain numbered outline, (b) a one-page printable quick-reference card, (c) the suppression rules with their mandatory verification steps, (d) a list of alerts that need better labels before the tree can route them deterministically. Bias toward: deterministic over judgment-based, false-negative-averse, every leaf actionable within a stated time budget.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Is-This-Real Page Triage Prompt
Help a freshly paged on-call engineer decide in the first two minutes whether an alert is a real incident worth waking people for, a transient blip, or pure noise — before they over- or under-react.
-
Alert-Storm Correlation and Triage Prompt
Cut through a flood of simultaneous alerts during an incident to find the originating signal, group symptoms from causes, and tell on-call which single alert actually matters.
-
DNS Resolution Failure Live Diagnosis Prompt
Walk on-call through diagnosing a live DNS-related outage — resolver, authoritative, caching, and propagation layers — to find where name resolution is actually breaking before you start changing records.
-
Incident Alert-to-Owning-Team Router Prompt
Take a freshly fired alert and route it to the team that actually owns the failing component, so the right responder is paged first instead of bouncing through three on-call rotations.
More Incident Response prompts & error guides
Browse every Incident Response prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.