Operations · inspect by default
/ops-incident
Organize symptoms, evidence, impact, hypotheses, and immediate actions
Use for current operational triage; ops-postmortem reconstructs the completed incident.
Make it your own.
In Claude Code, use the slash command and add your context. In Codex, select ops-incident from the just-vibe skill picker, then send the same brief.
Version 0.11.0 also supports /jv ops-incident, /just-vibe ops-incident and /jv:ops-incident in Claude. See shortcut setup and context examples.
/just-vibe:ops-incident Organize this incident's impact, timeline, and next diagnostic actions without restarting services./just-vibe:ops-incident Triage rising errors after a deployment with an unrelated provider incident./just-vibe:ops-incident Inspect supplied incident evidence without restarting services or sending customer messages./just-vibe:ops-incident Roll back checkout-api to the previous release and restart the payment worker; I authorize both.What the agent does
- Establish impact, time window, affected revision, and recent changes and dependencies.
- Keep a timestamped ledger separating facts, hypotheses and actions.
- Prefer reversible mitigations within scope.
Inputs
- symptoms, affected service/environment, incident window, and known impact.
Optional context: scope, references, constraints, successCriteria, environment, mode, budget.
Scope
- Reads
- Organize triage and recommend immediate actions; an authorized mitigation runs in apply mode.
- Writes
- Inspect/plan: triage and recommend; save requested artifacts only. Apply: carry out only the specific mitigation the user authorized, such as a rollback, restart, flag change or queue drain, against its resolved target after capturing the state it may erase; one step at a time, each verified and recorded. Customer messages, failovers and unrelated changes need their own exact request.
- Mode
- Inspect; symptoms, affected service/environment, incident window, and known impact. Apply for a specific mitigation the user authorizes.
- Prerequisites
- Exact service/environment, time window, revision/configuration identity, authorized logs/metrics, and operational constraints. Prefer observation before intervention; live restarts, traffic changes, restores, and notifications require the requested target/action. Redact sensitive telemetry.
Expected output
- Current incident brief with impact and timeline, supported hypotheses, next diagnostic steps, mitigation options and observed recovery.
How the work is checked
- A coincident deployment is a hypothesis until supported; unknown customer impact is not reported as zero.
When to stop or clarify
- No unrequested restarts, failovers, or customer messages. Preserve evidence before interventions that may erase it.
Handling missing context
- Infer
- Read service/environment, time window, revision, available telemetry and existing incident or recovery procedure.
- Assume
- Start from supplied logs and read-only observation; rank hypotheses without presenting an unexecuted intervention as recovery.
- Ask
- Resolve the precise target and missing authority before restart, restore, notification or traffic changes; continue evidence analysis while waiting.
Technical guidance
- Evidence
- Resolve incident window/timezone, service/revision, customer impact and available logs/metrics/traces.
- Method
- Maintain a timeline separating observation, hypothesis and intervention; preserve evidence before state-changing recovery.
- Pitfall
- A nearby deployment is correlation, not proof; missing telemetry cannot establish no impact.
- Check
- Tie each conclusion to timestamped evidence and record whether the proposed mitigation actually changed the observed symptom.
Situational decisions
When an intervention may erase evidence or duplicate effects: Capture relevant state and define its observation/abort condition before acting.
When the user authorizes a specific mitigation: Resolve the exact target and action, capture the state it may erase, state the expected observation and abort condition, run it once, verify the symptom changed, and record the step in the incident ledger.
The coding agent follows this workflow using its available tools. Installation does not grant service access or guarantee an outcome. Read the compatibility notes.