Skip to content

Incident Response

Use this playbook for policy, payment, verification, or escalation incidents.

Severity triggers

  • Verification failures spike unexpectedly
  • Escalation queue cannot be drained
  • Reversal/unwind jobs stall
  • Webhook failures create sustained dead-letter growth

Standard response flow

  1. Contain
  2. Freeze affected tenant/agent surface.
  3. Stop unsafe automation paths.
  4. Preserve evidence
  5. Export receipts/closepacks and relevant logs.
  6. Stabilize
  7. Recover queue processing and operator decision loop.
  8. Recover
  9. Replay/reconcile deterministic artifacts.
  10. Review
  11. Publish root cause + preventative controls.

Useful commands during response

npm run ops:x402:hitl:smoke
npm run ops:money-rails:reconcile:evidence
npm run ops:dispute:finance:packet
npm run test:ops:throughput:incident

Exit criteria

  • Verification path green for normal traffic
  • Escalation backlog and dead letters reduced to normal range
  • Finance reconciliation packet produced and reviewed
  • Follow-up controls queued with ownership