Skip to content
FlowScript templates

Business — Incident Response Funnel

An operations incident funnel: raw alerts narrowing to the incidents that were paged, declared and reviewed. Typed FlowScript for business strategy. Keywords: OKR, objective, key result, funnel.

Template previewFlowScript
Conversion funnel5 steps · base n = 12,840Alerts raised12,840100.0% of baseDistinct alerts4,31033.6% of base▲ 33.6% step convPaged a human1,2049.4% of base▲ 27.9% step convDeclared an incident3732.9% of base▲ 31.0% step convWritten review2682.1% of base▲ 71.8% step conv

Make it your own.

// An operations incident funnel: raw alerts narrowing to the incidents
// that were paged, declared and reviewed. The cohort chain accounts for
// every alert that fell out, and the funnel view is drawn from the same
// numbers rather than a second set typed beside them.

initiative reliability_program {
  title: "Halve customer-visible incident minutes"
  owner: "Ops leadership"
  horizon: "FY26"
}

kpi mttr {
  title: "Mean time to restore"
  baseline: 94
  target: 45
  unit: "minutes"
}

kpi page_precision {
  title: "Pages that became a declared incident"
  baseline: 31
  target: 60
  unit: "%"
}

kpi review_coverage {
  title: "Declared incidents with a written review"
  baseline: 72
  target: 100
  unit: "%"
}

segment enterprise {
  title: "Enterprise accounts on a 99.95 percent SLA"
  size: 340
  acv: 84000
}

segment self_serve {
  title: "Self-serve accounts, best-effort SLA"
  size: 21800
  acv: 290
}

// ── The funnel, as accounted arithmetic. Each step names what it
//    dropped, so 12 840 alerts reduce to 268 written reviews with
//    nothing unexplained in between.
cohort alerts_raised {
  n: 12840 source "Alertmanager export, Q1"
}

cohort alerts_deduplicated {
  n: 4310
  from: alerts_raised
  excluded: {
    duplicate_of_open_alert: 7912
    flapping_below_threshold: 618
  }
}

cohort pages_sent {
  n: 1204
  from: alerts_deduplicated
  excluded: {
    auto_remediated: 2415
    suppressed_in_maintenance: 691
  }
}

cohort incidents_declared {
  n: 373
  from: pages_sent
  excluded: {
    no_customer_impact: 702
    resolved_before_acknowledgement: 129
  }
}

cohort reviews_written {
  n: 268
  from: incidents_declared
  excluded: {
    severity_3_no_review_required: 94
    review_waived_by_owner: 11
  }
}

// The same five numbers as funnel steps, for the conversion view — each
// one derived from the cohort it restates rather than retyped beside it.
// A funnel_step chain carries no arithmetic check of its own, so a
// hand-copied restatement can drift from the cascade it claims to show
// and nothing will say so.
funnel_step raised      { n: = alerts_raised.n, title: "Alerts raised" }
funnel_step distinct    { n: = alerts_deduplicated.n, from: raised, title: "Distinct alerts" }
funnel_step paged       { n: = pages_sent.n, from: distinct, title: "Paged a human" }
funnel_step declared    { n: = incidents_declared.n, from: paged, title: "Declared an incident" }
funnel_step reviewed    { n: = reviews_written.n, from: declared, title: "Written review" }

view funnel: funnel(raised)
view okrs: okr_grid(reliability_program)
view triage: consort(alerts_raised)