Page 3 of 8~245 min topic

Incident response lab

Run the incident response baseline

One clean transaction through **POST /v1/rag/answer** must match the oracle: INC-RAG-CIT-2201: feature flag off in 8m; customer update sent; groundedness restored.

~30 min this pageHappy path

1Learn the idea

Read

Order the successful transaction

Code the narrow path that serves incident commander coordinating mitigate → communicate → verify: accept → authorize/normalize → call dependency → validate → record. Keep stages named so a trace can show which boundary passed. Success must emit evidence useful to time_to_declare_m, time_to_mitigate_m, customer_update_sent, not only a 200 with prose. Predict the observable for POST /v1/rag/answer before running: INC-RAG-CIT-2201: feature flag off in 8m; customer update sent; groundedness restored.

Read

Run with fakes first

Drive the path with recording fakes or local stubs. Assert call order and arguments. Idempotency keys or stable ids should keep retries from duplicating costly work where the product requires it. Product under test remains correctness incident for invalid RAG citations (SEV2) — resist adding unrelated features mid-path.

Read

Implementation artifact

flags set policy_retriever_v3 off --reason INC-RAG-CIT-2201
curl -sf $URL/answer -d @fixtures/policy_leave.json | jq .citations

Read

Compare prediction to result

For Incident response lab, paste the CLI/HTTP transcript beside your prediction for POST /v1/rag/answer. If the oracle is unmet (INC-RAG-CIT-2201: feature flag off in 8m; customer update sent; groundedness restored), stop and debug this page; do not compensate with prompt folktales. Re-run once after a clean process start to catch hidden global state that would invalidate INC-RAG-CIT-2201.

Read

Stage depth

Performance sketch: measure local p95 for the fake-backed path so later regressions are obvious. Keep concurrency modest until failure-handling proves limits. Log a single structured event per success with request id, revision, and the evidence field behind time_to_declare_m, time_to_mitigate_m, customer_update_sent. Avoid hidden global caches in the happy path unless the lab is about caching — and even then key by tenant. If the path calls a model, pin model id in config and echo it in the response for auditability. Remember incident commander coordinating mitigate → communicate → verify experiences wall-clock time, not your debugger’s single-step comfort.

Read

Field notes for `incident-response-lab` / `happy-path`

Prefer explicit function names over a single god-object handleRequest. Thread a correlation id from ingress to the last log line. When streaming, define what partial failure means before coding. Snapshot one successful response body in fixtures after redaction. If the path writes to a queue, assert message attributes in the fake. Stop adding retries on this page; that is the next concern. In this chapter the product is correctness incident for invalid RAG citations (SEV2), the human stakeholder is incident commander coordinating mitigate → communicate → verify, and the incident id you design against is INC-RAG-CIT-2201. Re-state the oracle in your notes — INC-RAG-CIT-2201: feature flag off in 8m; customer update sent; groundedness restored — and keep the invariant visible: declare early; preserve evidence; mitigation scoped; no blame in channel. Track time_to_declare_m, time_to_mitigate_m, customer_update_sent as the scoreboard. Surface under change control: POST /v1/rag/answer. If you only have forty minutes, finish the fixture for team debugs for an hour without declaring — customers keep seeing wrong policy cites before polishing UI. Promotion language stays ternary: promote, hold, or roll back based on evidence, not hope.

Go deeper

Before you start

Why this matters

Without calling production, order the steps a single success takes for incident commander coordinating mitigate → communicate → verify. Circle the first irreversible side effect. Your prediction should mention POST /v1/rag/answer and the evidence field that proves INC-RAG-CIT-2201: feature flag off in 8m; customer update sent; groundedness restored.

Check your understanding

Page assessment

Answer from memory. Completion is saved from this evidence, not from opening the next page.

1. Is call order asserted, not assumed?
2. Does success evidence support time_to_declare_m, time_to_mitigate_m, customer_update_sent?
3. Did you compare prediction vs transcript?

All responses are required.