Back to Incident & Issue Reporting

Process Runbook / SOP

How the automation works day-to-day: what is automatic, what needs a human, how exceptions are handled, and who to contact.

4 pagesPDF · Operations
FS-DOC-03Operations

Process Runbook / SOP

Incident and Issue Reporting

[YourCompany.com] · Operations Department · Prepared by FullSpec · [Today's Date]

This runbook is your day-to-day operating guide for the automated Incident and Issue Reporting process. It covers how the process works end to end, what the automation handles without any action from you, where your team steps in, and what to do when something goes wrong. FullSpec builds, monitors, and maintains the automation. Your role is limited to reviewing escalated incidents, approving edge-case classifications, and confirming closure on complex cases. Keep this document accessible to anyone on your team who may need to act on an incident.

01Process overview

The Incident and Issue Reporting process captures every operational incident, near-miss, or equipment failure through a single structured Google Form. From there, two agents handle all classification, record creation, notification, and status-chasing automatically. The Incident Triage Agent reads each submission, scores severity against an agreed rubric, assigns a category, and writes a full record to Google Sheets and Notion. The Notification and Escalation Agent then sends the assigned owner a Slack message, sends the reporter an email acknowledgement via Gmail, and fires a PagerDuty alert for any high or critical severity incident. Automated reminders continue until the incident is marked resolved. The operations manager's remaining work is reviewing escalations and confirming closure on complex cases, down from roughly 84 minutes of manual handling per incident to around 12 minutes of review-only activity.

Process name
Incident and Issue Reporting
Trigger
A staff member submits the Google Form with incident details, replacing all verbal, email, and chat-based reporting
Final output
A closed, fully documented incident record in Google Sheets and Notion, with resolution notes, close timestamp, and all communications logged
Agents running
Incident Triage Agent; Notification and Escalation Agent
Tools involved
Google Forms, Google Sheets, Notion, Slack, Gmail, PagerDuty
Weekly volume
Approximately 10 incidents per week (approx. 40 per month)
Human checkpoint
Operations Manager reviews escalated (high/critical severity) incidents and confirms final closure on complex cases
Process owner
[Your name], Operations Manager
Process Runbook / SOPPage 1 of 4
FS-DOC-03Operations

02Step-by-step: what happens and who acts

What you actually need to do: There is one human step in this process. When a high or critical severity incident is flagged, you receive a PagerDuty alert and a Slack notification. You review the Notion record, confirm the classification is correct, and take any immediate action the situation requires. For standard incidents, no action is needed from you unless the assigned owner fails to respond and the escalation reminder reaches you. Everything else, including logging, classifying, assigning, notifying, chasing, and updating, runs automatically.
Step
What happens
Who acts
Type
1
A staff member opens the Google Form and submits an incident report. The form captures required fields including a description of the incident, location, estimated severity, and any photo attachments. This replaces all unstructured verbal, email, and Slack-based reporting.
Staff member
Human
2
The Incident Triage Agent reads the incoming form response and scores it against the agreed severity rubric. It assigns a category based on keywords and field values, and determines whether the incident needs immediate escalation or standard routing.
Incident Triage Agent
Automated
3
A new row is written to the Google Sheets incident log. The row includes all form fields, the assigned severity score, category, a unique incident ID, and a timestamp. The record is immediately visible to the operations manager in the shared log.
Incident Triage Agent
Automated
4
A structured Notion page is created for the incident. It pulls in all form fields and classification outputs, and provides a workspace for investigation notes, evidence uploads, and resolution details as the incident progresses.
Incident Triage Agent
Automated
5
The automation checks whether the severity score meets the high or critical threshold. If it does, a PagerDuty alert is fired immediately to the on-call manager. The operations manager is expected to review the Notion record and act without delay.
Notification and Escalation Agent / Operations Manager
Human
6
A Slack direct message is sent to the responsible owner. The message includes the incident summary, assigned severity level, resolution deadline, and a direct link to the Notion record. No manual notification is required from the operations manager.
Notification and Escalation Agent
Automated
7
An automated Gmail message is sent to the reporter confirming that their submission has been received. The email includes the assigned incident ID, the name of the responsible owner, and the expected resolution timeframe.
Notification and Escalation Agent
Automated
8
If the assigned owner has not updated the Notion record by the deadline, the Notification and Escalation Agent sends a scheduled reminder via Slack. Reminders repeat on a set cadence until the record is marked resolved or the operations manager intervenes.
Notification and Escalation Agent
Automated
9
When the assigned owner marks the Notion page as resolved and adds resolution notes, the automation detects the status change and updates the Google Sheets row with the resolved status, resolution notes, and close timestamp. The loop is complete.
Notification and Escalation Agent
Automated
Process Runbook / SOPPage 2 of 4
FS-DOC-03Operations

03Handling exceptions

Situation
What the system does
What you do
Form submitted with missing required fields
The Google Form is configured to require key fields before submission is accepted. If the form is bypassed or a legacy submission arrives with missing data, the Triage Agent flags the record in Sheets with a status of 'Incomplete' and sends the reporter an automated Gmail asking them to resubmit or supply the missing information.
If the reporter does not respond within 24 hours, follow up directly to collect the missing details and update the Sheets row manually. Contact FullSpec support if the form validation appears to have failed.
A duplicate incident report is submitted for the same event
The Triage Agent compares incoming submissions against recent records using the incident description, location, and timestamp. If a likely duplicate is detected, the new record is created in Sheets with a status of 'Possible Duplicate' and linked to the original incident ID. No second Notion page or owner notification is sent.
Review the flagged record in Sheets and confirm whether it is a true duplicate or a related but separate event. Merge or close the duplicate manually in Sheets and update the Notion record on the original incident to note the duplicate submission.
Severity rubric cannot classify the incident (edge case not covered)
If the Triage Agent cannot confidently assign a severity score because the submission does not match any rubric category, it creates the Sheets row and Notion page with a status of 'Needs Review' and sends a Slack alert to the operations manager.
Open the Notion record, review the full submission, and manually assign a severity level and category. Update the Sheets row to reflect your decision. If the same type of submission recurs, contact FullSpec support to extend the rubric to cover the new category.
Assigned owner does not respond and reminders are exhausted
The Notification and Escalation Agent sends reminders on the configured cadence. If the incident remains unresolved after the final reminder threshold is reached, it sends an escalation Slack message directly to the operations manager, flagging the incident ID, the assigned owner, and the number of days overdue.
Contact the assigned owner directly to confirm they received the original notification and understand the deadline. If they are unavailable, reassign the incident to an alternative owner by updating the Notion record and the Sheets row. The automation will pick up the new owner for subsequent reminders.
PagerDuty alert fires but the on-call manager is unavailable
PagerDuty manages its own escalation policy. If the primary on-call contact does not acknowledge the alert within the configured response window, PagerDuty automatically escalates to the secondary contact defined in its escalation schedule.
Ensure the PagerDuty escalation schedule is kept up to date with current on-call contacts. Review the alert as soon as you are available and confirm in the Notion record whether immediate action was taken or deferred. Contact FullSpec support if PagerDuty alerts are not firing as expected.
A connected tool is unavailable (Slack, Gmail, Notion, or PagerDuty outage)
The automation platform retries failed actions up to three times with a short delay between attempts. If all retries fail, the affected step is logged as an error in the workflow run history and the operations manager receives a fallback notification by email to the address registered with FullSpec.
Check the tool's status page to confirm whether an outage is in progress. For high or critical severity incidents that cannot be escalated via PagerDuty or Slack during an outage, contact the assigned owner and relevant manager directly by phone or an alternative channel. Report the outage and any affected incident IDs to FullSpec support at support@gofullspec.com so the run history can be reviewed and any missed steps replayed once the tool recovers.

04Who to contact and when

Fill in the rows below once your team is confirmed. Add names, email addresses, and preferred contact methods for each role so anyone using this runbook knows exactly who to reach and how. The FullSpec rows are fixed and do not need to be changed.

Role
Name
How to reach them
Process owner (Operations Manager)
[Your name]
[Rep email] / Slack handle: [your Slack]
Incident backup contact (when Operations Manager is unavailable)
[Backup name]
[Backup email] / [Phone or Slack]
PagerDuty on-call primary
[On-call name]
PagerDuty escalation schedule + [mobile number]
PagerDuty on-call secondary
[Secondary name]
PagerDuty escalation schedule + [mobile number]
Compliance Lead (for regulatory or safety-related incidents)
[Compliance Lead name]
[Compliance email] / [Slack or phone]
FullSpec builder (automation issues, rubric changes, build updates)
FullSpec team
support@gofullspec.com
FullSpec support (errors, outages, unexpected behaviour)
FullSpec support
support@gofullspec.com
Process Runbook / SOPPage 3 of 4
FS-DOC-03Operations

05Ongoing maintenance

The automation runs without daily intervention, but a small number of regular checks will keep it accurate and reliable. The table below sets out who does what and when.

When
What to do
Who
Whenever a new incident category or team role is added
Update the severity rubric document and notify FullSpec support at support@gofullspec.com so the Triage Agent configuration can be updated to reflect the new category or routing rule. Do not change the Sheets column schema or Notion template without coordinating with FullSpec first, as field mapping changes can break the automation.
Operations Manager + FullSpec team
Whenever the Google Form fields or Notion page template need updating
Contact FullSpec support before making any changes to form field names, question order, or Notion database properties. Changes to these directly affect how the Triage Agent reads and maps incoming data. FullSpec will update the agent configuration in parallel with any template changes.
Operations Manager + FullSpec team
Monthly spot-check (first week of each month)
Open the Google Sheets incident log and review the past month's records. Confirm that all submissions have a severity score, category, assigned owner, and resolved or in-progress status. Flag any rows showing 'Incomplete' or 'Needs Review' that have not been actioned. Check that the Notion pages for closed incidents contain resolution notes.
Operations Manager
Monthly error log review (first week of each month)
Review the automation workflow run history for any failed steps, retry errors, or skipped notifications over the past 30 days. If recurring errors appear on a specific step or tool connection, report them to FullSpec support with the affected incident IDs so the root cause can be diagnosed.
Operations Manager + FullSpec team
Whenever a team member changes role or leaves
Update the PagerDuty escalation schedule to reflect the new on-call contact. Update any Slack channel memberships or direct-message routing that the Notification Agent uses for owner assignment. Inform FullSpec support if routing rules reference a specific user by name so agent configurations can be updated.
Operations Manager + FullSpec team
Quarterly volume review (every three months)
Review the total number of incidents logged over the quarter against the baseline volume of approximately 40 per month. If volume has grown significantly, assess whether the current PagerDuty alert thresholds and reminder cadences remain appropriate. Discuss any adjustments with FullSpec support. Also review whether the rubric categories still reflect the types of incidents the business is seeing.
Operations Manager + FullSpec team
Most common maintenance issue for this process: The severity scoring rubric drifts out of alignment with real-world incidents over time. New categories of equipment failures, near-misses, or service events that were not anticipated at launch cause the Triage Agent to fall back to 'Needs Review' status more frequently. Review the rubric at least once per quarter and contact FullSpec support whenever a new type of incident recurs two or more times without a clean classification. Keeping the rubric current is the single most effective thing you can do to maintain automation accuracy.
Process Runbook / SOPPage 4 of 4

More documents for this process

Every document generated for Incident & Issue Reporting.

Launch Plan
Operations · Owner
View
ROI and Business Case
Finance · Owner
View
Developer Handover Pack
Technical · Developer
View
Integration and API Spec
Technical · Developer
View
Test and QA Plan
Quality · Developer
View