Ten runbooks for the incidents AI systems actually have.
Each one starts with evidence and containment in the first fifteen minutes and the first hour, then lists the evidence to collect, containment options, durable controls, communications, and closure criteria. Written by the people who run these incidents; published so you can run them without us.
How to use these. They are generic by design: they do not know your environment, your provider, or your legal obligations. Free to use and adapt inside your organization; keep the source line if you republish. Version 1.0, 27 August 2026. Every runbook ends with the same rule: before closure, convert the incident into a diagram, a root-cause finding, a hunt analytic, a regression test, a validation memo, and an owner. That conversion is the part most teams skip, and it is the part we are hired for.
Before any adversarial work we sign a written scope. The rules-of-engagement template is public.
Happening now?
Send a project inquiry and set timing to active incident. Joey Victorino reads those first and answers the same business day, US Pacific. Put no credentials, prompts, or customer data in the form.