SIPOC — Sev-1 Incident Response
Written in the terse s/i/p/o/c dialect with a prose scope sentence, this map bounds payments incident response at seven steps and shows the 68-minute mitigation time missing its 30-minute target while acknowledgement beats its own.
Make it your own.
title "Sev-1 incident response — payments platform"
scope "From alert fires to postmortem published"
owner "Incident commander on rota"
metric "Time to acknowledge" target: 5 actual: 4 unit: min
metric "Time to mitigate" target: 30 actual: 68 unit: min
metric "Postmortems inside 5 days" target: 90% actual: 62% better: higher
s: Monitoring platform, Customer support desk, Payment processor status feed, On-call rota
i: Paging alert, Error budget dashboard, Service runbook, Customer impact reports, Recent deploy manifest
p: Alert fires -> Acknowledge and declare -> Open response channel -> Diagnose and mitigate -> Verify recovery -> Communicate resolution -> Publish postmortem
o: Status page updates, Mitigation change, Incident timeline, Postmortem with actions
c: Affected merchants, Support desk, Engineering leadership, Compliance auditors
requirement input "Paging alert": "Fires inside 60 seconds of the SLO burn and names one owning service" (CTQ)
requirement input "Service runbook": "Reviewed in the last 90 days and carries a tested rollback command"
requirement output "Status page updates": "First update inside 15 minutes, then every 30 minutes" (CTQ)
requirement output "Postmortem with actions": "Blameless, with a named owner and due date on every action"