Some events go beyond the scope of a technical incident: a major outage, a cyberattack, a disaster on a site, ... They require quickly mobilizing several people, coordinating actions, and communicating regularly about the situation. This is the role of crises in Astry.
A crisis includes in particular:
- a title, a status (Open or Resolved) and tags
- a status message, which describes the situation and is communicated to the people concerned
- a list of actions to carry out during the crisis
- notification rules, which define who is informed, when, and how
- an assigned team, impacted resources and custom fields
- the full history of the crisis (comments, changes, completed actions, notifications)
Crises appear in the Inbox, alongside incidents (with a CRISIS badge). As long as a crisis is open, a banner is displayed at the top of every Astry page to bring it to the attention of all users, with its duration and status message.
Declaring a crisis
A crisis is declared from the Inbox, using the Declare a crisis button, or directly from the page of a resource. Two modes are available:
- Predefined template: you select a crisis template, then fill in the fields requested by the template. The status message is then generated automatically (a preview is shown). The actions defined in the template are pre-selected: you can remove some, or add custom actions.
- Manual configuration: you fill in the title and summary of the crisis yourself, as well as its actions.
In both cases, you can assign the crisis to a team and associate resources and tags with it. An Advanced configuration section also lets you adjust the crisis notification rules.
The status message
The status message describes the current state of the crisis. It can be updated throughout the crisis; each update can be sent with or without notifying the people concerned. When the crisis was declared from a template, the status message is updated by filling in the template fields.
Actions
Actions represent what needs to be done during the crisis (for example: Inform stakeholders, Mitigate the problem, Plan the post-mortem, ...). Each action includes:
- a name and a description (optional)
- a required or optional nature: required actions must be completed before the crisis can be resolved
- an execution mode: simultaneous (it starts at the same time as the other actions) or sequential (it waits for the previous actions to be completed). The step shown indicates a suggested order: any action can be completed at any time.
- a responsible position: the action is then assigned to the member of the crisis team holding this position, who is alerted about it
- an alert method (email, SMS, voice call, push notification or Microsoft Teams) and a repeat interval: as long as the action is not completed, the alert is sent again at this interval
- possibly resources useful to carry out the action, and a field to fill in to be able to close it
From the crisis page (or the dedicated page of each action), you can mark an action as completed, complete it on behalf of someone else, cancel its completion, or edit its settings. The Declare a performed action button also lets you log an action carried out during the crisis that was not planned.
Note: If a position is configured with an escalation, an action assigned to this position and not completed within the planned delay is automatically re-assigned to the next position (see Positions).
Notification rules
The notification rules of a crisis define who must be informed, and under which conditions. Each rule reads as When ... Then notify ...:
- When: one or more conditions about an action (for example: a required action has been unfinished for more than 30 minutes) or about the crisis (for example: the crisis was just declared, was just resolved, just received a comment, has been open for more than 4 hours, has an unfinished-actions ratio above 50%, receives a periodic status update, ...)
- Then notify: recipients (teams, positions, users, the team assigned to the crisis or its creator), through one or more channels (SMS, email, push), with a repeat interval
Default rules are offered when a crisis is declared, and crisis templates can define their own rules. Rules can then be added, edited, activated or deactivated during the crisis.
Resolving a crisis
A crisis can only be resolved once all its required actions have been completed. Upon resolution, a closure message is sent: it is generated from the closure fields of the crisis template (if any), with a preview before sending. A resolved crisis can be re-opened if needed.
Crisis report
The Export report button lets you download the history of the crisis (events, comments, actions, photos, ...):
- in CSV format: a table of events and comments (without photos)
- in PDF format: a full report, with photos
This report provides a basis for your post-incident review. Statistics about all your crises are also available in reporting.
Access rights
Owners and Responders can act on a crisis (actions, status message, comments, resolution). Stakeholders have read-only access. Only Owners can delete a crisis.