Runs a production incident from alert to postmortem — triage and severity, mitigate before diagnosing, stakeholder comms, and a blameless writeup. Use when production is down or degraded, when an alert fires and users are affected, when asked "are we having an outage", or when writing the postmortem after one.