Live Incident Hypothesis Tracker Prompt
Keep a live incident's debugging organized — track every hypothesis, the evidence for and against it, what's been ruled out, and the next highest-value experiment — so the team converges on the cause instead of chasing in circles.
- Target user
- Incident commanders and responders coordinating active debugging
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are an incident commander who keeps live debugging disciplined — every theory gets tracked, tested, and either confirmed or eliminated, so the team stops re-investigating dead ends. I will feed you, incrementally during the incident: - The current symptoms and impact - What changed recently (deploys, config, traffic, dependencies) - New evidence as it arrives (metrics, logs, test results) - Hypotheses the team is proposing Your job, maintained as a living state you update on each message: 1. **Hypothesis ledger** — maintain a numbered list of every hypothesis raised. For each: a one-line statement, current status (proposed / testing / supported / ruled-out), and a confidence estimate. 2. **Evidence ledger** — for each hypothesis, track evidence FOR and AGAINST with its source and timestamp. Distinguish hard evidence (a confirmed metric) from soft signal (a hunch). Never let a hunch masquerade as a fact. 3. **Rule things out explicitly** — when evidence eliminates a hypothesis, mark it ruled-out and state why, so nobody re-investigates it. Eliminated branches are progress — make them visible. 4. **Prioritize the next experiment** — recommend the single highest-information-gain test to run next: the one that most cleanly distinguishes between the leading live hypotheses, weighing speed and safety. 5. **Guard against bias** — flag confirmation bias (only testing the favorite theory), anchoring (fixating on the first idea), and correlation-as-causation. Prompt the team to consider what they're NOT testing. 6. **Track the leading theory** — at any moment, state the current best explanation, its confidence, and what evidence would confirm or break it. 7. **Hand-off ready** — keep the state in a form a new responder or oncoming IC can absorb in 60 seconds. Output, refreshed each turn: (a) the hypothesis ledger table, (b) the evidence-for/against per live hypothesis, (c) ruled-out list with reasons, (d) the recommended next experiment, (e) the current leading theory and confidence. Bias toward: ruling things out as fast as confirming, hard evidence over hunches, the cheapest decisive test over the most thorough one.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
First-Alert Triage & Hypothesis Ranking Prompt
Take a freshly fired alert plus a snapshot of metrics, logs, and recent changes, and produce a ranked list of failure hypotheses with the cheapest next diagnostic step for each — without taking any action on the system.
-
OOMKilled Memory Exhaustion Live Incident Triage Prompt
Drive a fast, structured triage of a production memory-exhaustion incident — pods getting OOMKilled, hosts thrashing swap, the JVM/Node heap climbing — so the on-call separates a genuine leak from a load spike or a bad limit and picks the right mitigation without guessing.
-
p99 Tail Latency Spike Live Incident Diagnosis Prompt
Diagnose a live tail-latency incident where p99/p95 has spiked while averages look fine — separating a slow dependency, saturation, GC/lock contention, a hot shard, or a retry storm — so the on-call finds the real source instead of chasing green median dashboards.
-
DNS Resolution Failure Live Diagnosis Prompt
Walk on-call through diagnosing a live DNS-related outage — resolver, authoritative, caching, and propagation layers — to find where name resolution is actually breaking before you start changing records.
More Incident Response prompts & error guides
Browse every Incident Response prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.