An internal incident handoff prompt should produce a decision ledger with event time, author, evidence ID, current owner, action state, unresolved question, and next check. It is more than a prose recap. The incoming responder needs to know which commands were requested, which actually ran, which receipts exist, and which changes must not be repeated. Keep raw customer data and credentials out of the handoff; link to controlled records by internal identifier when authorized. Preserve uncertainty and corrections. If a timestamp is missing, mark it missing rather than sorting an inferred event into a fabricated sequence.
Incident handoffs: preserve actions and decisions
Operational case
Harbor's first responder hands off at 14:20 UTC. The ledger records snapshot HC-1410, rollback start at 14:16, the operator receipt showing deployment traffic switched, and the still-open question of whether error rates have returned to baseline. The next owner must query a later window and run a representative checkout before marking recovery. A short public update can omit internal deployment detail, but the handoff cannot. It also records the approved 14:30 update commitment, so the next communications lead does not miss it while debugging. The model drafts the ledger; the outgoing and incoming responders verify action states together.
14:10 UTC | HC-1410 | 3,720/18,600 failed attempts | verified.
14:16 UTC | rollback started | operator action | receipt pending.
14:20 UTC | traffic switch receipt recorded | not recovery proof.
Owner: incoming incident commander.
Open: later-window rate and synthetic checkout.
Communication commitment: next public update by 14:30 UTC.Performance and operating cost
Maintaining a ledger of A actions is O(A) append work; verifying a handoff is O(A) for the active slice, not the whole historical incident. A compact evidence index reduces repeated searches while preserving links to full controlled records. Timezone normalization is a small extra cost that prevents action-order mistakes. Avoid copying entire logs into the prompt: a task-scoped event slice is cheaper to review and less likely to disclose user data or bury the next required action.
Common Mistakes
- Do not mark a requested command as executed without a receipt.
- Do not erase a mistaken update; record its correction and time.
- Do not omit the next public-update commitment from the handoff.
Connected lessons
- Production prompt engineering
- Prompt Engineering
- Incident triage prompts: build a timestamped evidence ledger
- Tool effects: reconcile receipts before retrying
- Incident reviews: turn a timeline into tested corrective work
- Incident updates: audience, owner, and release gate
- Incident impact: window, denominator, and scope
- Incident updates: separate facts, hypotheses, and ETA
- Incident resolution: verify recovery and correct the record
- Project: draft Harbor Checkout incident updates
- Incident-communication prompt decisions
