Every incident, the same scramble.
The scenario:
The outage started at 9:40. The fix took 25 minutes. Finding who to call at the client, which systems they deemed critical, and who was authorized to approve emergency spend took longer than the fix.
Incident response has two halves: the technical work, and everything around it. The second half is where the scramble lives, and it is entirely preparable.
Test it against your last incident honestly. Write down the minutes spent on the fix, then the minutes spent finding numbers, chasing authority, and drafting the update from scratch. For most desks the second number wins, and it is the number the client experiences, because it is all delay between impact and information.
The prompt:
You are building per-client incident packs for an MSP.
Context: [client count, where client info lives today, the last incident where information hunting cost time]
Build:
The one-page incident pack per client: named contacts with out-of-hours numbers, escalation order, critical systems ranked, emergency spend authority, communication preference
The comms templates pre-attached: first notification, hourly update, resolution note, each under 100 words
The storage rule: where packs live so they are reachable when the documentation system itself is down
The freshness cycle: packs reviewed at every QBR, owner named
