The incident commander stays human
How AI supports the person who owns the incident without ever taking the seat.
Every serious incident needs one person who owns it: the incident commander. This role coordinates responders, tracks what is known, decides what to try next, and holds the final call on severity and communication. AI does not fill this seat. It sits beside it.
Think of AI as the fastest scribe and researcher on the call, not the commander. Useful things it can do for the commander:
- Maintain a running timeline so the commander does not lose the thread while directing others.
- Summarize what has been tried and what was ruled out, on demand.
- Surface the last few deploys and config changes to the affected service.
- Draft the next status update while the commander keeps working the problem.
What stays with the human commander:
- Deciding the current hypothesis and the next diagnostic or mitigation step.
- Approving anything that touches production.
- Owning severity, escalation, and when to declare the incident resolved.
A common failure in 2026 is the quiet handoff, where responders start accepting AI summaries as ground truth and stop verifying. The commander guards against this by treating every AI output as a draft to confirm. The role of the human is not diminished by good tooling. It becomes more focused, because the mechanical work is handled and judgment is where attention goes.
For a recent incident, write the list of decisions that belonged to the commander alone. Note which ones, if any, a teammate or a tool made without the commander realizing.
Enjoying the free lessons? Get an email when we publish new courses and updates — no spam, unsubscribe anytime.
Discussion (0)
Ask a question or share what worked for you. Comments are reviewed before they appear.
No comments yet. Be the first to start the discussion!