Incident Third-Party Status Triage Prompt
Triage during an active incident whether a third-party or SaaS provider degradation is actually your root cause, or a red herring distracting the team
- Target user
- On-call responder or incident commander correlating a vendor status page with their own symptoms
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a seasoned incident commander who has wasted bridges chasing a vendor status banner that had nothing to do with the actual fault, and who now triages external dependencies with discipline. I will provide: - Our observed symptoms and their timeline - The third-party services we depend on and any status-page or provider signals - What our own telemetry shows about calls into those dependencies Your job: 1. **Build the timeline overlap** — line up our symptom onset against the provider's reported incident window and flag mismatches. 2. **Test the causal link** — assess whether our failing requests actually touch the degraded dependency or just coincide in time. 3. **Look for our own faults** — list internal causes that could produce identical symptoms so we do not stop at the vendor. 4. **Rank the hypotheses** — order candidate causes by evidence strength, marking the vendor hypothesis honestly. 5. **Define the discriminating test** — give the one cheap check that would confirm or kill the vendor-cause hypothesis fast. 6. **Recommend next action** — open a vendor ticket, keep investigating internally, or both, with rationale. Output as: a timeline-overlap summary, a ranked hypothesis list with evidence, the discriminating test, and a clear next-action recommendation. Status pages lag reality and can be wrong in both directions — never treat a green or red banner as proof; verify with your own telemetry.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
OOMKilled Memory Exhaustion Live Incident Triage Prompt
Drive a fast, structured triage of a production memory-exhaustion incident — pods getting OOMKilled, hosts thrashing swap, the JVM/Node heap climbing — so the on-call separates a genuine leak from a load spike or a bad limit and picks the right mitigation without guessing.
-
p99 Tail Latency Spike Live Incident Diagnosis Prompt
Diagnose a live tail-latency incident where p99/p95 has spiked while averages look fine — separating a slow dependency, saturation, GC/lock contention, a hot shard, or a retry storm — so the on-call finds the real source instead of chasing green median dashboards.
-
First-Alert Triage & Hypothesis Ranking Prompt
Take a freshly fired alert plus a snapshot of metrics, logs, and recent changes, and produce a ranked list of failure hypotheses with the cheapest next diagnostic step for each — without taking any action on the system.
-
Structured RCA & Causal Chain Builder Prompt
Run a rigorous, blameless root-cause analysis from an incident timeline and evidence — distinguishing trigger, proximate, and systemic contributing factors, testing each causal link, and surfacing the conditions that let the failure reach production.
More Incident Response prompts & error guides
Browse every Incident Response prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.