War-game an SLO breach response by proving each burn class has a named owner, a measured containment window, and a reverse path before the calendar starts governing every uptime claim.
SLO breach responses fail when "contained" means a status without a decision artifact, when teams dual-count a draft burn as both approved and live, and when high-risk customer paths still pin to one thin roster because the inventory is incomplete. The review needs one written inventory of burn classes, one owner who can deny a risky shortcut, and a documented consequence when a failed containment ages past the deadline.
Freeze the breach scenario
State which service burned the error budget, which cohorts saw it, how severity was assigned, and what already changed in production. Separate customer-visible harm from internal noise. If the packet mixes an SLO rewrite with a pager cut and a runbook rewrite, split them. One breach under fire is enough.
Write the decision the review will produce: keep the burn label, reclassify, open a broader hold, or close with documented residual risk. Also write the reverse criteria that would reopen the case inside a stated window if new evidence arrives.
Seats on the breach
- Reliability ops. Burn math, window timing, and what the dashboard hides if labels soften after the review.
- On-call engineering. Root cause depth, dual-counted fixes, and the patch that would leave sibling burns open past lock.
- Support and success. Ticket load, customer promises that break in process, and relationship damage with accounts.
- Product. Feature freezes, roadmap slips, and the first ninety minutes of thinner coverage.
- Skeptic. The claim that looks strongest and is least sourced.
Give every seat the same exhibits: burn timeline, customer samples, severity rubric, open siblings, and the hold policy you intend to use. Private data for one seat invents agreement that will not survive the real room.
Loop until the ledger sticks
Load Pingpong with the breach packet and seat briefs. Early passes may steelman the current burn. Later passes attack from reliability, on-call, support, and product. End with a short ledger of surviving objections, mitigations, or a changed burn label. Agreement across models is not evidence. Keep gaps that still lack sources.
Adjacent pages: the reliability ops lead seat, a pager rotation cut stress test, a pager policy review, and an on-call rotation stress test. Browse the war-game decisions hub.
Close the review only when approved and blocked burn labels can be reproduced from stored SLO exports without a verbal override.