Seat

Incident Coordinator

You run the response; you do not decide on operators' behalf. You sequence, translate, and track - the one role that holds the whole board. Everyone else reads their line; you are the reason the lines connect.

Denis Angellsecondary David Schwartztertiary - unfilled

Your channel

#unl-validators

You post once in #dunl-operators-only: naming the UNL Leader. You run the bridge, start to finish.

When the page rings

Acknowledge inside 5 minutes, check correlation, declare.

Silent for 5 minutes: David is paged and takes the seat outright, declaring immediately.

The record is yours

There is no scribe.

Declarations, orders, interrupts, decisions, re-declarations, handoffs - each with its time, appended as it happens.

Your steps, in order

  1. Declare

    On the fixed body: condition off the seven-word list, severity off the SEV rubric, damage line or its due time, Cause: not yet established, the bridge link, the UNL Leader named, the authorization regime. Unknown is a complete condition and the normal one at minute zero.

  2. Open the bridge

    The standing pre-shared link, in the same minute. If it fails: any room, link posted in channel under the poster's own name, never by DM.

  3. Two orders in one message

    Vijay builds the damage report, due 15 minutes from his acknowledgement. Ayo finds the root cause, proven by a failing test the team can run. Plus the embargo: nothing leaves #unl-validators and xrpld-private until you clear it.

  4. Name Brett in #dunl-operators-only

    Your only post there: he is the only person who will pin instructions; keep nodes running as normal. You never hold the operator net yourself.

  5. Pin the interrupt rule and the cadence

    Leaders interrupt you through anything when it cannot wait; everything else reports by exception on the interval. Leaders report, not members.

  6. Run both tracks

    Damage times the response; cause determines the fix. You are the only person who sees both, and you say out loud which one you are waiting on, every time it changes. The trap is living on the cause track because it is the interesting one.

  7. Call the interim response off the damage report

    Accruing and irreversible: act now. Accruing and reversible: act if the rate is material. Stopped: let the hunt run, and say that you are choosing to.

  8. Hand Brett the instruction

    Translated into one of the five operator actions, with the do-not line, verification, target, and deadline. Anything unsigned - restart, config, halt - you countersign in the thread, restating the action in your own words.

  9. De-escalate and order the unwind

    Reverts come off at de-escalation, in reverse order, so the 24-hour window runs clean. The bridge closes here.

  10. Declare stand-down

    Only when four things hold as facts: threshold met or a lower number accepted in writing; no recurrence through one full 24-hour window; the network normal on its own terms; interim measures unwound and counted. A recurrence inside the window is the same incident: reset the window, re-declare.

 

Two numbers, one source each

The release ETA is Ayo's; the adoption count is Brett's. You are the only person who restates either outward, and everyone else quotes you with the time you said it. No third figure exists.

Never ask "any update?" - ask the specific missing fact, one question to one named leader: still accruing or stopped; failing test yes or no; count and the names outstanding.

Which regime is in force

Incident regime: you authorize on the team's recommendation; the count measures compliance; an operator's done is an acknowledgement, not a vote.

Coordinated regime: no incident or no authorized action; the operators' agreement is collected first on the README thresholds. Say which regime applies in the declaration and in every instruction.

Your full script - the declaration body, the condition list, disclosure widening, handoff, stand-down: governance/roles/incident-coordinator.md