Data Incident Triage & Communication Form

Structured interactive triage form to capture incident facts, assign owners, record mitigation and rollback plans, notify stakeholders, and drive post‑incident follow-up. Saves submissions for audit, timelines, and analytics.

Interactive Tool

Data Incident Triage & Communication Form

Purpose

Use this form to capture essential information when a data incident is detected. It standardizes triage, owner assignment, mitigation, communications, and post‑incident follow‑up so teams can act quickly and preserve evidence.

Severity guide

  • S1 (Critical): Major outage or data loss affecting many customers or core business flows — immediate response required.
  • S2 (High): Significant degradation or incorrect data impacting key processes or decision‑making.
  • S3 (Medium): Localized issues with limited business impact; workaround available.
  • S4 (Low): Minor anomaly or non‑urgent data quality issue requiring investigation.

Roles

  • Incident Lead: Owns the operational response and decisions during the incident.
  • Engineering Lead: Manages technical mitigations, rollbacks, and root cause investigation.
  • Communications Lead: Prepares stakeholder updates and external messages.
  • Forensics / Compliance: Engaged when legal, regulatory, or sensitive data issues are suspected.

This form supports operational response only. For legal, regulatory, or forensic investigations, escalate to Security or Compliance immediately.

Summarize what happened in 1–2 sentences (what, observed when, who reported).
Use ISO 8601 where possible (e.g., 2026-08-27T15:04:00Z).
Person or system that detected or reported the incident.
Select all teams impacted.
List dataset names, pipeline IDs, dashboards, reports, or artifacts affected.
Choose the best-fit severity based on business impact.
Share early hypotheses (config change, schema change, bad upstream data, deployment, etc.).
Describe actions taken so far (stop jobs, revert change, apply patch, isolate dataset) and next immediate steps.
If yes, provide the rollback plan in the following field.
Include specific commands, versions, snapshot timestamps, and an owner for the rollback. If not applicable, enter 'N/A'.
e.g., Execs, Product Owners, Customers (if impacted), Legal, Compliance, Support. Include channel (email, Slack, ticket).
Template: '[Short summary of incident], impacted systems: [list], known impact: [summary], mitigation in progress: [actions], ETA for next update: [time], contact: [name/email].' Include links to incident page or ticket.
List primary and secondary contacts with preferred contact method and expected SLA to respond.
Typical suggestions: S1=1 hour, S2=4 hours, S3=24 hours, S4=72 hours. Enter a numeric value.
Links to logs, dashboards, dataset snapshots, queries, tickets, or storage locations where evidence is preserved.
Choose items to ensure the incident is fully addressed.
Person responsible for ensuring postmortem actions are completed.
Provide a date/time for the review. Use ISO 8601 where possible.
Any other relevant context, blockers, or constraints.
You can explore this tool now. Sign in or create an account to save your responses and return to them later.
Make this tool part of your work

Save a personal copy, bring it to your team, or tailor the questions and workflow to fit what you are hungry to improve.

Member customization and team collaboration are coming soon.

Discussion

Comments and conversation will live here.