Operations · Incident governance

Severity means the same thing.
Across every team.

Forge classifies incidents into four severity levels to standardize response, prioritization and escalation. FABRIC can recommend; accountable people review and decide.

1

Reference

Incident severity model

SeverityDescriptionBusiness impactExamplesAction
🔴 SEV 1 · CriticalComplete production outage or critical security issueVery highService unavailable, failed deployment, data corruptionRespond immediately, assign an incident commander, notify stakeholders, roll back or hotfix.
🟠 SEV 2 · HighMajor functionality unavailable or significantly degradedHighPurchase failures, matchmaking failures, critical gameplay issuesPrioritize immediately, engage owners, and prepare a hotfix.
🟡 SEV 3 · MediumPartial degradation with an available workaroundMediumPerformance degradation, isolated gameplay bugs, UI issuesInvestigate and schedule a fix in the current sprint.
🔵 SEV 4 · LowMinor defects with minimal player or business impactLowCosmetic issues, text errors, minor UX improvementsAdd to the backlog and address during routine maintenance.
2

Evidence-based recommendation

How severity is assigned

FABRIC may recommend severity using bounded evidence about player impact, business and revenue impact, security risk, service availability, release status, stability and the reported number of affected users. Missing evidence remains missing—it is not converted into a score.

🤖 AI suggested severity

A recommendation with evidence and limitations, never an automatic lifecycle transition.

📊 Impact score

Separate 0–100 dimensions for Players, Revenue, Stability and Security. An absent value is shown as “—”, not zero.

👥 Suggested owner

A likely accountable team or person when the evidence supports it. Assignment remains a human action.

⚡ Recommended next action

The next evidence-backed response step, grounded in incident-management RAG and source telemetry.

Human review and override are required.FABRIC recommendations are hypotheses. The incident owner or commander confirms severity against authoritative telemetry and records any override in the timeline.
3

Governed lifecycle

Response workflow

1

Incident detected

Normalize bounded Datadog, Bugsnag or manual evidence.

2

AI recommends severity

Score only supported impact dimensions and state limitations.

3

Human review or override

Confirm severity from authoritative evidence.

4

Assign owner

Name the accountable owner and, for critical response, the incident commander.

5

Execute response

Follow the relevant playbook and governed Engineering or Operations route.

6

Validate resolution

Observe provider health through the stable recovery window.

7

Close and learn

Record cause, recovery evidence and corrective actions.