Kepner-Tregoe (KT) Operations Overlay
Use KT to improve incident discipline without adding unnecessary runtime or paperwork. The default is proportional KT: use the smallest KT structure that makes the decision safer and clearer.
KT Depth Policy
| Scenario | Required depth | Output target |
|---|---|---|
| P1/P2 incident | Full KT: SA -> PA -> DA -> PPA |
Structured incident response and closure artifact |
| P3/P4 incident | Lightweight KT: brief SA plus targeted PA or DA |
Concise evidence and next action |
| Production write action | Minimum DA + PPA; use full KT if P1/P2, broad blast radius, or irreversible |
Approval-ready remediation rationale |
| Read-only scheduled health/reporting task | ADAC only | Short operational summary |
| Routine low-risk recommendation | No formal KT unless uncertainty or impact warrants it | Evidence, confidence, next step |
Do not expand a low-risk read-only task into a full KT worksheet. Prefer compact bullets and only include sections that change the decision.
ADAC Lightweight Reliability Pattern
Use ADAC when full KT is unnecessary:
- Auto-Detect: what signal, scope, and failure boundary were identified.
- Auto-Declare: what can fail, expected degradation, blast radius, confidence, and owner.
- Auto-Communicate: how to validate, who is notified, and what action is recommended.
ADAC is enough for routine health checks, anomaly summaries, and low-risk scheduled tasks.
KT Flow Mapping
SA - Situation Appraisal
Purpose: classify concerns, set priorities, and choose the next analysis.
Use when:
- severity or blast radius is unclear
- multiple symptoms compete for attention
- the agent needs to choose between PA, DA, or PPA
Minimum output:
- concern/deviation
- impact and urgency
- known/unknown
- next analysis path
PA - Problem Analysis
Purpose: identify the most likely cause using IS / IS NOT logic.
Use when:
- a deviation exists and root cause is unknown
- rollback/remediation depends on knowing the cause
- symptoms could come from platform, workload, dependency, or release change
Minimum output:
- problem statement
- key
IS / IS NOTdistinctions byWHAT,WHERE,WHEN,EXTENT - likely causes and confidence
- verification method
DA - Decision Analysis
Purpose: choose the best option using explicit objectives.
Use when:
- selecting between rollback, scale, restart, patch, failover, or wait-and-observe
- proposing production write actions
- human approval is required
Minimum output:
- decision to be made
- must/want criteria
- options considered
- selected option and rejected options
- rationale and approval need
PPA - Potential Problem Analysis
Purpose: protect execution of the chosen action.
Use when:
- a production action can make things worse
- rollback/roll-forward must be ready
- action success requires validation thresholds
Minimum output:
- potential problems
- preventive actions
- contingent actions
- rollback trigger and validation window
Output Shapes
Full KT Incident Output
Use for P1/P2 and high-risk incidents:
- Situation Appraisal
- Problem Analysis
- Decision Analysis
- Potential Problem Analysis
- Recommended Action
- Risk and Rollback
- Owners and Timeboxed Next Steps
- Validation Evidence
Lightweight KT Output
Use for P3/P4 or targeted analysis:
- Situation Summary
- Evidence and Confidence
- Chosen Analysis (
PA,DA, orPPA) - Recommendation
- Validation / Escalation Trigger
ADAC Output
Use for routine read-only automation:
- Auto-Detect
- Auto-Declare
- Auto-Communicate
Domain Guidance
AKS
- SA: split cluster, node pool, namespace, workload, and dependency concerns.
- PA: compare affected vs unaffected nodes, pods, namespaces, versions, and deployment windows.
- DA: compare restart, scale, rollback, config fix, node cordon/drain, or wait-and-observe.
- PPA: define failure triggers and safe rollback before action.
Container Apps
- SA: classify impact by app, environment, revision, and ingress path.
- PA: compare current revision against known-good revision and recent configuration changes.
- DA: choose traffic shift, rollback, scale, config patch, or hold.
- PPA: protect rollout with threshold triggers and abort plan.
Drasi on AKS
- SA: separate ingestion lag, query staleness, runtime faults, platform faults, and external dependency faults.
- PA: isolate Drasi runtime vs AKS platform vs upstream/downstream dependency.
- DA: choose scale, rollback, configuration correction, restart, or dependency escalation.
- PPA: define fallback, validation windows, and post-mitigation probes.
Governance Hook Policy
Use hooks to enforce only the minimum required KT depth:
- P1/P2: reject outputs missing meaningful
SA,PA,DA, andPPA. - Production write action: reject outputs missing meaningful
DAandPPA; require full KT only when severity or blast radius warrants it. - P3/P4 read-only: do not block for missing full KT; require concise evidence, confidence, and next step.
See kt-templates.md and hooks-governance.md.