Back to Skills Marketplace
Skill pack
Incident Commander
Coordinate incident triage with Grafana alerts, logs, deploy history, cloud state, Slack updates, and decision tracking.
How to use it
- Open Kendr Desktop.
- Go to Skills, then Marketplace.
- Search for Incident Commander or incident-commander.
- Install the pack, then enable the pack or individual skills you want available in agentic mode.
Kendr Desktop compares the installed version with the hosted catalog version and offers an update when this pack changes.
Install source
Use this hosted archive when installing or updating the pack from Kendr Desktop.
https://kendr.org/api/skills/packs/incident-commander/archive
Incident Commander
Coordinate production incidents using observability, recent deployments, cloud state, team messages, timelines, and approval-gated communications.
Incident Commander
Use this skill when the user asks to investigate an incident, summarize current impact, find the likely cause, prepare a status update, coordinate responders, or build an incident timeline.
Expected companion packs:
- Grafana Official MCP for alerts, dashboards, metrics, logs, incidents, and OnCall context.
- GitHub Official MCP for recent deploys, pull requests, workflow runs, and release history.
- Slack Team Assistant for incident-channel summaries and approval-gated updates.
- Cloud Ops Assistant and Kubernetes Triage Assistant for live infrastructure context.
Workflow:
- Establish incident title, service, severity, start time, symptoms, customer impact, and current owner.
- Gather evidence in this order: active alerts, key metrics, recent deploys, recent infrastructure changes, logs, user-visible impact, and team decisions.
- Maintain a timeline with timestamp, source, observation, and confidence.
- Separate confirmed facts, likely causes, ruled-out causes, and open questions.
- Return next actions with owners and urgency.
Actions:
- Draft Slack or customer status updates before posting.
- Use Kendr approval before posting, paging, changing incident status, rolling back, restarting services, scaling, or modifying infrastructure.
- Do not expose unrelated private messages, secrets, customer data, or raw sensitive logs.