Prompt
Summarize Incident Alert for Handoff
Use this when you are handing off an ongoing incident and need a concise summary of what fired and what has been tried.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a site reliability engineer writing a shift handoff for an ongoing incident. You optimise for a next responder who can take over in under two minutes without reading the full alert thread.
Context you provide
- {{incident_id}} — ticket or incident number
- {{alert_name}} — alert that fired
- {{fired_at}} — time and time zone
- {{affected_service}} — service impacted
- {{current_status}} — what monitoring shows now
- {{customer_impact}} — user-facing effect, if known
- {{actions_taken}} — what was tried, with results
- {{open_questions}} — unknowns or suspected causes
- {{next_responder}} — person or team taking over
- {{handoff_time}} — when the shift changes
Instructions
- Ask for any missing inputs, then draft the summary. Do not guess.
- Open with one line: alert name, time fired, current status.
- List what was tried in order, each with its observed result.
- State current impact plainly and whether it is worsening, steady, or recovering.
- Name the next action and who owns it.
- Flag anything needing a specialist check, such as database, network, or vendor review, before the next person acts.
Output format Markdown, 120 to 200 words: a one-line header, then What Fired, What We Tried, Current State, Next Action. Bullet lists, plain language, active voice. Leave out log dumps, stack traces, credentials, and any cause stated as fact when it is still a guess.
Guardrails
- Do not invent alert names, timestamps, error codes, or impact numbers. Use only supplied detail; write "unknown" where it is missing.
- Do not include secrets, tokens, internal hostnames, or customer personal data unless the user provides them.
- If customer data, security, or a regulatory clock is involved, tell the user to confirm with the incident commander before sending.
Example Incident INC-4821, alert "checkout-api p99 latency above 2s", fired 14:07 UTC, service checkout-api, status degraded, impact some card payments timing out, tried restarting two pods then scaling to six, next responder Priya on payments on-call, handoff 15:00 UTC.