Incident Detection Source Effectiveness Review Prompt
Analyze where your incidents were first detected — alert, dashboard, synthetic, or angry customer — to measure how proactive your detection really is and shift more incidents to catch-it-first signals.
- Target user
- SRE and monitoring teams improving proactive detection
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are a monitoring lead who measures detection maturity by a brutal metric: what fraction of incidents you found before your customers did. I will provide: - A set of recent incidents with their first detection source (specific alert, dashboard, synthetic check, support ticket, customer report, social media, executive escalation) - The detection timestamp vs the actual incident-start timestamp where known - Current alerting rules and synthetic coverage - Severity per incident Run a detection source effectiveness review. Work through these steps: 1. **Classify detection sources** — bucket each incident as proactive (your monitoring caught it), reactive (a human or customer told you), or accidental (someone stumbled on it). Compute the proactive-detection rate overall and by severity. 2. **Measure detection lag** — for each incident, estimate the gap between incident start and detection, and which source detected it. Find the slowest-to-detect categories. 3. **Diagnose reactive detections** — for every customer-or-support-detected incident, identify why your monitoring missed it: no signal, threshold too loose, alert routed nowhere, signal existed but was buried in noise. 4. **Find the high-leverage signals** — which new or tuned alerts/synthetics would have flipped the most reactive incidents to proactive, weighted by severity and frequency. 5. **Check the noise trade-off** — ensure proposed detections will not drown on-call in false positives; estimate the precision of each. 6. **Set a target** — a realistic proactive-detection-rate goal and a quarterly plan to reach it. Output: (a) a detection-source breakdown with proactive rate by severity, (b) a detection-lag ranking, (c) the reactive-miss diagnosis per incident, (d) prioritized new/tuned signals with expected precision, (e) a target and quarterly improvement plan. Separate conclusions backed by the incident data from hypotheses needing more evidence.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Capacity Saturation Early-Warning Design Prompt
Design leading saturation alerts — for pools, queues, memory headroom, and resource trends — that fire while there is still time to act, so the team gets paged before a slow capacity creep becomes a 3am outage instead of after users already feel it.
-
Is-This-Real Page Triage Prompt
Help a freshly paged on-call engineer decide in the first two minutes whether an alert is a real incident worth waking people for, a transient blip, or pure noise — before they over- or under-react.
-
Alert-Storm Correlation and Triage Prompt
Cut through a flood of simultaneous alerts during an incident to find the originating signal, group symptoms from causes, and tell on-call which single alert actually matters.
-
Incident Drill Scoring Rubric Prompt
Build an objective scoring rubric to evaluate how a team performs during an incident drill or fire drill — detection, coordination, communication, and recovery — so you can track readiness improvement over time instead of relying on gut feel.
More Incident Response prompts & error guides
Browse every Incident Response prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.