<!--
Generated from a Ledgerium SOP template.
Fill in the [bracketed] fields for your process, or delete this block before publishing.
-->

# Incident management SOP template

## How to use this template

- Fields written as `[fill in: ...]` are blanks — replace each one with the value for your process.
- Lines starting with `>` are guidance, not part of the SOP — delete them once you've filled in the real content.
- Recording this process in Ledgerium generates a filled-in version of this SOP automatically.

## Document control

- Process owner: [fill in: process owner]
- Version: [fill in: version]
- Effective date: [fill in: effective date]
- Last reviewed: [fill in: last reviewed date]
- Approved by: [fill in: approver name or title]

## Applies to / Use when

> Who uses it: On-call engineers and operations staff who respond, the incident commander who coordinates, and the service owner who runs the post-incident review. Managers reference it for response targets.
> When to use it: Use it when onboarding on-call staff, standardizing how incidents are classified and escalated across the team, or documenting a response process for a review.

- Applies to: [fill in: who this applies to in your organization]
- Use when: [fill in: when your team should follow this procedure]

## Purpose

> Why the procedure exists and the response and reliability targets it supports.

[fill in: purpose details]

## Scope

> Which systems and incident types the procedure covers, and what is out of scope.

[fill in: scope details]

## Roles

> Who responds on call, who commands the incident, and who runs the review.

[fill in: roles details]

## Procedure

> The ordered steps from detection to a resolved, reviewed incident.

[fill in: procedure details]

## Exceptions

> How to handle major incidents, escalations, and cross-team response.

[fill in: exceptions details]

## Records

> What is logged during the incident and where the post-incident review is filed.

[fill in: records details]

## Worked example — steps from a real recording

> Example steps from a real recording — replace with your own.

1. **Detect and log** — Open the incident and record the first symptoms and time.
2. **Classify severity** — Set severity from the classification rules to drive response.
3. **Escalate on call** — Page the on-call owner and escalate if severity requires.
4. **Contain and resolve** — Mitigate the impact, then apply and confirm the fix.
5. **Review and close** — Run the post-incident review and close the incident.
6. [fill in: step]
7. [fill in: step]

## Review checklist — common mistakes to avoid

- [ ] Leaving the severity classification out, so response is sized inconsistently
- [ ] Documenting the fix but not the on-call escalation path
- [ ] Closing incidents without a post-incident review, losing the root cause

## Limitations of this template

A template is a starting structure. Your real severity rules and escalation path are captured best by recording an actual incident response rather than filling in a blank outline.

---
Template: https://ledgerium.ai/sop-templates/incident-management · Generated automatically from a real recording, or fill in by hand.

Template last updated: July 2026
From Ledgerium recordings: A generated incident management SOP captures the severity classification and on-call escalation step by step and times detection to resolution, so it shows where response time is lost, which a happy-path template never captures.
See the full recorded workflow: https://ledgerium.ai/workflow-library/incident-management-workflow
