Skip to content
Back to skills

Triage Incident Vs Problem

ASecurity

Classify an issue as an incident (restore service now), a problem (remove the recurring cause), or a major incident (declare command), and open the right record. Reach for this when something is broken or keeps breaking.

  • 7 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 23, 2026
ai-agentsgit

Security analysis

A100/100

Scanned September 23, 2026

npx -y skills add mcorbett51090/RavenClaude --skill triage-incident-vs-problem --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Triage Incident Vs Problem?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Triage Incident Vs Problem
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/mcorbett51090-triage-incident-vs-problem/badge)](https://www.skillsdirectory.com/skills/mcorbett51090-triage-incident-vs-problem)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: triage-incident-vs-problem
description: "Classify an issue as an incident (restore service now), a problem (remove the recurring cause), or a major incident (declare command), and open the right record. Reach for this when something is broken or keeps breaking."
---

# Skill: Triage incident vs problem

Two different jobs with two different success metrics. Get the classification right or you firefight forever (§2 #1).

## Step 1 — Is it a major incident?
Check the major-incident criteria (broad impact / critical service down / high urgency). If yes, declare it and switch to the major-incident process (commander + comms) — see the [`major-incident-runbook`](../../templates/major-incident-runbook.md).

## Step 2 — Incident or problem?
- **Incident** — service is degraded/down *now*; the job is to **restore** it fast (a workaround counts). Metric: time-to-restore.
- **Problem** — the underlying **cause** of one or more incidents; the job is to **remove** it. Metric: recurrence eliminated.
- A recurring incident is the signal to open a *problem* alongside restoring the *incident*.

## Step 3 — Prioritize the incident
Impact × urgency → priority. Restore with the fastest safe path; a documented workaround is a legitimate restoration.

## Step 4 — Drive the problem to root cause
Open a problem record, run RCA, and log the **known error** (cause + workaround) so the next occurrence is fast to handle.

## Step 5 — Feed the permanent fix forward
The permanent fix usually needs a change → hand to the change-and-release-manager. Traverse the routing tree in [`../../knowledge/itsm-decision-trees.md`](../../knowledge/itsm-decision-trees.md).

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…