Skip to content
SIPOC templates

SIPOC — Sev-1 Incident Response

Written in the terse s/i/p/o/c dialect with a prose scope sentence, this map bounds payments incident response at seven steps and shows the 68-minute mitigation time missing its 30-minute target while acknowledgement beats its own.

Template previewSIPOC
Sev-1 incident response — payments platformScope · From alert fires to postmortem publishedProcess ownerIncident commander on ro…Time to acknowledge4target 5 · -1 minTime to mitigate68target 30 · +38 minPostmortems inside 5 days62%target 90% · -28%SSuppliers4IInputs5PProcess7OOutputs4CCustomers4Monitoring platformCustomer support deskPayment processor statusfeedOn-call rotaPaging alertCTQFires inside 60 seconds ofthe SLO burn and names oneowning serviceError budget dashboardService runbookReviewed in the last 90 daysand carries a testedrollback commandCustomer impact reportsRecent deploy manifestStatus page updatesCTQFirst update inside 15minutes, then every 30minutesMitigation changeIncident timelinePostmortem withactionsBlameless, with a namedowner and due date onevery actionAffected merchantsSupport deskEngineering leadershipCompliance auditors1Alert fires2Acknowledgeand declare3Open responsechannel4Diagnose andmitigate5Verifyrecovery6Communicateresolution7Publishpostmortem4 suppliers · 5 inputs · 7 process steps · 4 outputs · 4 customers3 of 5 inputs have no stated requirement: “Error budget dashboard”, “Customer impact reports”, “Recent deploy manifest”.2 of 4 outputs have no stated requirement: “Mitigation change”, “Incident timeline”.Scope starts at “alert fires”, matching step 1 “Alert fires”.Scope ends at “postmortem published”, matching the last step “Publish postmortem”.Metric “Time to acknowledge” meets target: 4 against 5.Metric “Time to mitigate” misses target: 68 against 30, a gap of 38 min.Metric “Postmortems inside 5 days” misses target: 62% against 90%, a gap of 28 %.

Make it your own.

title "Sev-1 incident response — payments platform"
scope "From alert fires to postmortem published"
owner "Incident commander on rota"
metric "Time to acknowledge" target: 5 actual: 4 unit: min
metric "Time to mitigate" target: 30 actual: 68 unit: min
metric "Postmortems inside 5 days" target: 90% actual: 62% better: higher

s: Monitoring platform, Customer support desk, Payment processor status feed, On-call rota
i: Paging alert, Error budget dashboard, Service runbook, Customer impact reports, Recent deploy manifest
p: Alert fires -> Acknowledge and declare -> Open response channel -> Diagnose and mitigate -> Verify recovery -> Communicate resolution -> Publish postmortem
o: Status page updates, Mitigation change, Incident timeline, Postmortem with actions
c: Affected merchants, Support desk, Engineering leadership, Compliance auditors

requirement input "Paging alert": "Fires inside 60 seconds of the SLO burn and names one owning service" (CTQ)
requirement input "Service runbook": "Reviewed in the last 90 days and carries a tested rollback command"
requirement output "Status page updates": "First update inside 15 minutes, then every 30 minutes" (CTQ)
requirement output "Postmortem with actions": "Blameless, with a named owner and due date on every action"