Business — Incident Response Funnel
An operations incident funnel: raw alerts narrowing to the incidents that were paged, declared and reviewed. Typed FlowScript for business strategy. Keywords: OKR, objective, key result, funnel.
Make it your own.
// An operations incident funnel: raw alerts narrowing to the incidents
// that were paged, declared and reviewed. The cohort chain accounts for
// every alert that fell out, and the funnel view is drawn from the same
// numbers rather than a second set typed beside them.
initiative reliability_program {
title: "Halve customer-visible incident minutes"
owner: "Ops leadership"
horizon: "FY26"
}
kpi mttr {
title: "Mean time to restore"
baseline: 94
target: 45
unit: "minutes"
}
kpi page_precision {
title: "Pages that became a declared incident"
baseline: 31
target: 60
unit: "%"
}
kpi review_coverage {
title: "Declared incidents with a written review"
baseline: 72
target: 100
unit: "%"
}
segment enterprise {
title: "Enterprise accounts on a 99.95 percent SLA"
size: 340
acv: 84000
}
segment self_serve {
title: "Self-serve accounts, best-effort SLA"
size: 21800
acv: 290
}
// ── The funnel, as accounted arithmetic. Each step names what it
// dropped, so 12 840 alerts reduce to 268 written reviews with
// nothing unexplained in between.
cohort alerts_raised {
n: 12840 source "Alertmanager export, Q1"
}
cohort alerts_deduplicated {
n: 4310
from: alerts_raised
excluded: {
duplicate_of_open_alert: 7912
flapping_below_threshold: 618
}
}
cohort pages_sent {
n: 1204
from: alerts_deduplicated
excluded: {
auto_remediated: 2415
suppressed_in_maintenance: 691
}
}
cohort incidents_declared {
n: 373
from: pages_sent
excluded: {
no_customer_impact: 702
resolved_before_acknowledgement: 129
}
}
cohort reviews_written {
n: 268
from: incidents_declared
excluded: {
severity_3_no_review_required: 94
review_waived_by_owner: 11
}
}
// The same five numbers as funnel steps, for the conversion view — each
// one derived from the cohort it restates rather than retyped beside it.
// A funnel_step chain carries no arithmetic check of its own, so a
// hand-copied restatement can drift from the cascade it claims to show
// and nothing will say so.
funnel_step raised { n: = alerts_raised.n, title: "Alerts raised" }
funnel_step distinct { n: = alerts_deduplicated.n, from: raised, title: "Distinct alerts" }
funnel_step paged { n: = pages_sent.n, from: distinct, title: "Paged a human" }
funnel_step declared { n: = incidents_declared.n, from: paged, title: "Declared an incident" }
funnel_step reviewed { n: = reviews_written.n, from: declared, title: "Written review" }
view funnel: funnel(raised)
view okrs: okr_grid(reliability_program)
view triage: consort(alerts_raised)