AI Incident Response Playbook
Prepare containment, ownership, communication, and review steps for AI workflow failures.
Fill this onlineTemplate preview
The exact sections inside the download.
Frame the operating decision
Which signal shows the workflow is unsafe, degraded, or unavailable? What must be paused, blocked, revoked, or routed to humans? Use the combined view to name the business outcome, source of truth, and owner who will decide whether to proceed.
Set the control boundary
Who needs to know internally or externally? What fallback path restores operational continuity? State the risk to avoid, review or escalation route, and record needed to keep the workflow controlled.
Commit to the first move
Which prompt, tool, policy, source, or review gate must change? Low, moderate, high, or critical? Record the smallest safe scope, baseline, owner, evidence, decision date, and next action.
Decision summary
Low, moderate, high, or critical? Who leads the response and who approves restart? Summarize the proposed move, operating benefit, and the evidence that supports it.
Evidence and control
Which logs, traces, prompts, sources, and outputs must be preserved? State the source, review boundary, accountable owner, and condition that would require revision or pause. Keep the decision receipt with the workflow record.
Next review
Record the decision owner, evidence source, review date, and the explicit condition to scale, revise, defer, or stop. Confirm how the resulting decision will be communicated, implemented, and retained in the operating record.
01 / 03
Frame the decision
Name the real operating need before designing a solution.
Name the assistant, agent, automation, or operating loop.
Bad advice, data exposure, stale context, unauthorized action, outage, or escalation failure.
Name the role accountable for containment and communication.
How to use it
Start with one real decision.
Complete the canvas with the workflow owner, then use the blank areas to expose missing context and controls.