Incident Severity Misclassification Audit Prompt
Audit closed incidents to find where severity was over- or under-assigned and tighten the classification process
- Target user
- incident program owners and SRE leads auditing severity assignment quality
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a seasoned incident program owner who knows that a chronically under-called severity means real customer pain gets a slow response, while chronic over-calling burns out responders and trains everyone to ignore the next SEV1. I will provide: - A set of closed incidents with their assigned severity, actual customer impact, duration, and responder count - The current severity classification criteria - Any escalation or downgrade events that occurred mid-incident Your job: 1. **Retrospective re-grading** — for each incident, assign the severity the impact data actually warranted, independent of what was originally called. 2. **Misclassification patterns** — identify systematic biases: which teams, services, or hours of day tend to under-call or over-call, and by how much. 3. **Cost of error** — for under-calls, estimate the delayed-response impact; for over-calls, estimate the wasted-mobilization and alert-fatigue cost. 4. **Root drivers** — diagnose why misclassification happens (ambiguous criteria, fear of waking people, optics pressure, missing impact data at declaration time). 5. **Criteria fixes** — propose specific changes to the severity rubric that would have corrected the most common errors. 6. **Process guardrails** — recommend a mid-incident re-evaluation checkpoint and who owns the re-grade. Output as: a per-incident re-grading table (assigned vs warranted, delta, driver) plus a prioritized list of criteria and process fixes. Re-grade against impact evidence, not hindsight bias — judge what was knowable at declaration time, not only what was known after resolution.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Firing Alert Severity & Escalation Decision Prompt
Given a firing alert and current impact signals, decide an appropriate severity level and whether to escalate or page additional responders, with explicit reasoning against your severity rubric — leaving the final call to a human.
-
Is-This-Real Page Triage Prompt
Help a freshly paged on-call engineer decide in the first two minutes whether an alert is a real incident worth waking people for, a transient blip, or pure noise — before they over- or under-react.
-
Escalation Policy Gap and Single-Point-of-Failure Analysis Prompt
Audit your existing escalation policies and on-call schedules to find coverage gaps, dead-ends, and single points of failure where a page could go unanswered during a real incident.
-
SEV Downgrade and Incident Closure Criteria Prompt
Build objective, signal-based criteria for when an active incident can be downgraded in severity and formally closed, so incidents end on evidence rather than optimism or fatigue.
More Incident Response prompts & error guides
Browse every Incident Response prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.