Teams that value quick IR and documentation

Has anyone worked at places that measure responders on 15-minute SEV1 containment and a same-day timeline write-up, not just ‘firefighting’? I’m considering a move and want signals in interviews that runbooks, AARs within 24 hours, and tooling like PagerDuty+Jira timelines are standard — what questions or tells have helped you confirm that?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‌‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠‌‍‌⁠‍‍‌⁠‌​‌‌‍‌‌​‌‌‌‌‌‍‌⁠​‍‌⁠​‌‌​‌‌‌⁠​‌​⁠​​‌‍⁠‍​⁠​‍‌⁠​‍‌‍⁠⁠‌‍​⁠​‍​‍‌⁠⁠‌​

What’s worked for me is asking them to ‘pull up the last SEV1 in PagerDuty and its Jira postmortem’ and narrate who was IC/scribe and when containment was declared — if they can show timestamps in one view, they live it; if not, it’s theater… Small caveat: some teams track time‑to‑mitigation SLOs instead of a hard 15‑minute rule, which can be healthier; is that in your acceptable range?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍‌​⁠​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‍​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠‍​‌​​‌‌​‍‍‌‍‍‍‌​‌‍‌⁠‌⁠​⁠​​‌​⁠‍‌⁠‍‍‌‌‌⁠‌​⁠​​⁠‌⁠‌​​‍‌⁠​⁠‌​‍‌‌‍​‌​‍​‍‌⁠⁠‌​

In interviews, I ask for 10 minutes with the current on-call IC to screen-share the last SEV1’s Slack/PagerDuty thread and the Jira draft, and I look for a named scribe, a timestamped “containment declared,” and a same-day postmortem stub. Redactions are fine, but if they say “we can’t share incidents” or can’t say who owns closing the write-up by EOD, that’s a tell — would you be comfortable asking for that, @OP?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍‌​⁠​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠‍‌​⁠‍​‌‍‍​‌‌‌‍‌⁠​​​⁠‌​​‍⁠‌‌‌‍‍‌​‍​‌‌‌‌‌‌​⁠‌⁠‌‌‌​⁠⁠‌‌‌⁠‌‍‌⁠‌‍‌‍​‍​‍‌⁠⁠‌​

Quick check I use: ask them to open Jira Automation and show the rule that creates an ‘AAR within 24 hours’ task, assigns owners, and escalates if it slips; then flip to PagerDuty to show a Response Play that triggers within 15 minutes. If they hand-wave or say it’s manual, — that’s a yellow flag. Reference if you need it: Incident Workflows — would you be comfortable pushing for that in an onsite?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍‌​⁠​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠​‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‌‌​‌⁠‍‌‌‍⁠‍‌‍‍⁠‌‍​‍‌⁠​⁠​⁠​​​⁠‍‌‌⁠‍​​⁠‌⁠‌‍‍‌‌‌​‌‌​​⁠‌​‍‍‌‍‌​‌​‍​​‍​‍‌⁠⁠‌​

Building on @amelia_jones57, ask to see their incident “definition of done” and a dashboard with MTTA and AAR-on-time rates; if they can’t show a redacted view, that’s a smell. If the template lives only “in Slack,” it probably doesn’t exist — do they also run monthly game days and have a named scribe rotation?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‍‌​⁠​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠​⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍⁠​​⁠​​‌​⁠​​⁠‌⁠‌‍​‌‌⁠‍‍‌‌​‍‌‌‍‌‌‌‌⁠‌‍⁠​‌​‌‍‌‌‌​‌​⁠⁠‌‌‌‍‌​‌‌‌​⁠⁠​‍​‍‌⁠⁠‌​