HIVE80lab — Ops notes

Incident Technical Category Matrix

Purpose: Map incidents to technical categories to route to the right expert. This complements business impact (P1-P4).

Incident Category Overview

CategoryDefinitionTypical PlaybooksOwner Role
AvailabilityService/endpoint unavailable or degradedRecovery from backup, DB restore, load balancer failoverInfrastructure SRE
SecurityUnauthorized access, data breach, malwareIncident response, forensic analysis, containmentSecurity Lead
PerformanceResponse time degradation, latency, throughput issuesCapacity testing, cache invalidation, optimizationPerformance Engineer
FunctionalFeature broken, incorrect behaviorRoot cause analysis, fix development, rollbackEngineering Lead
DataData loss, corruption, partial inaccessibilityBackup verification, restore, data recoveryDatabase Admin
Third-PartyVendor/SRE/API dependency outageVendor escalation, failover to alternative, SLA trackingVendor Manager

Category-Based First Response Actions

Availability Incidents

Security Incidents

Performance Incidents

- [ ] Response time (p95, p99) - [ ] Throughput (requests/sec) - [ ] Error rate (% 500)

Functional Incidents

Data Incidents

Third-Party Incidents

Combined Category × Impact Matrix

CategoryP1 Business ImpactP2 Business ImpactP3 Business ImpactP4 Business Impact
AvailabilityPayment gateway down → Exec notifiedCore API degraded → Users notifiedNon-critical API degradedMinor UI delay
SecurityData breach → Legal, ComplianceCredential theft → Customer commsUnauthorized access (self)Attempted access logged
PerformanceNo revenue impactSlow checkout flowSlow article loadSlow login
FunctionalCheckout brokenFeature unavailableSearch brokenForm validation error
DataCustomer data lostUser profile corruptedConfig backup lostLog file truncated
Third-PartyPayments via Stripe blockedEmail via SendGrid degradedSupport via Zendesk degradedAnalytics via GA paused

Documentation Fields

Usage: Use after impact classification. Route incident to the correct expert and tooling stack. Works best with incident-response-plan-template-small-teams.html.

Product links: /l/ops-starter-kit-vol-2 | /l/ops-starter-kit | /l/automation-starter-pack

From the HIVE80lab kit

Part of the five-pillar incident-response set: see the pillars overview and the blameless post-incident review template.