Seat

Advisor

You size the damage and shape the response. Two things are wrong at once and only one of them is the bug: what is being damaged is a different question from what caused it, and it is yours. The damage track is what the response is timed off.

leads Vijaysecond David Schwartzstand-ins Wietse · Mayukha Vadari · David Sappin

Your channels

#unl-validators and the bridge, in real time.

Advisors beyond the two named are assembled at incident time from the pre-cleared pool.

When the page rings

Open the damage report and start filling it.

Your 15 minutes is the tightest clock in the response, and it cannot start when a channel message happens to wake you.

Your clock

15 minutes from your one-word acknowledgement of Denis's order.

Silent for 3 minutes: David is paged and takes the report; you join it in progress.

Your steps, in order

  1. Acknowledge the order in one word

    That word starts the 15 minutes, unambiguously.

  2. Build the first read alone

    Do not wait for the advisors to assemble - assembling takes longer than the deadline. They arrive into a report that exists and sharpen it.

  3. Classify - this one is required

    One class off the list below, worst first. The class tells Denis in one word whether waiting is affordable at all.

  4. Post it on the template, inside 15 minutes

    Unknown lines are answers; a late report is not. Until it posts, there is nothing to discuss.

  5. Then work the response menu against the class

    Kill switch, config gate, fast upgrade, halt, fork - costing each lever. The response discussion does not open before the class posts.

  6. Keep it live

    Re-report on the cadence and immediately when any line changes. Two changes interrupt Denis rather than waiting: accrual stops, or damage turns irreversible.

  7. Speak the one recommendation

    Which response, why, tied to the report; what it costs and for whom; the runner-up and why not; the cost of waiting; how it unwinds. The engineers' concur or dissent travels inside your message - two competing recommendations never reach Denis.

The damage classes - take the highest row that applies

ClassWhat is being damagedCan it be given back
FundsValue moved, destroyed, or made unspendable against the rulesNo - not without a fork or deliberate intervention
StateLedger state inconsistent with the rules, divergent historyOnly by intervention, only if caught early
AvailabilityLedgers not closing or validating, throughput or latency out of rangeYes, once the fault is removed
HostsOperator infrastructure down; the chain itself unaffectedYes, operator-side
None observedNothing measurable yet, and you have lookedn/a

None observed is a real class and not the same as unknown: it means you looked and found nothing, which is what lets Denis let the hunt run.

 

Refuse to guess

An unknown line is legitimate; a guess is not. Name the missing signal, who can supply it, and the conservative assumption to hold until it arrives. Still accruing and reversible are the two lines Denis decides off - they are never a feeling.

Never

  • Touch operators - no instructions, no outreach to node runners.
  • Decide the fix. The patch is the engineers'; you weigh the response around it.
  • Hold the report back to make it complete. It ships with unknowns in it.
  • Open the response discussion before the class is posted.

Your full script - the report template, the interrupts, the recommendation body: governance/roles/advisor.md