Run a live production incident — declare severity, assign roles, stabilize (mitigate before fixing), communicate on a cadence, keep a timeline as you go, and hand off to a postmortem when it's resolved. Use when prod is down or degraded right now, an alert has paged, or the user says "we have an incident" / "prod is broken" / "everything's on fire".