Situation reports (SitReps) are vital for effective incident management. They help align current responders, orient new responders, and keep stakeholders updated. Here’s how to create impactful SitReps:

Consider multiple audiences:

  • Responders: Provide an overview of the problem and current actions being taken.
  • Executives/Stakeholders: Provide high-level information on the impact and prospects for resolution.

Make each SitRep self-contained, and keep it short:

  • A good SitRep should be readable and understandable in under two minutes.
  • Each SitRep should provide sufficient information for a new team member to understand the incident without needing to read previous reports.
  • Avoid making SitReps a comprehensive log of everything that has happened in the incident so far; focus on current information, and direct readers to Slack channels or incident logs for a full history.

Remember the mnemonic “CAN” for structuring your SitRep:

  • Conditions: What is the current situation?
  • Actions: What are we doing about it?
  • Needs/Next Steps: What additional resources are required? What are we planning to do next? Sometimes, all you need is time for an in-progress fix to finish rolling out; if that’s the case, just say so.

Maintain a predictable cadence:

  • Establish a regular schedule for SitReps (e.g., hourly for availability incidents) so readers know when to expect updates and how current the information is.
  • Include a timestamp on each SitRep, so readers can judge how “fresh” it is.
  • Explicitly state when the next SitRep is expected to be shared. Provide a specific timeframe, such as “next update in 60 minutes”; avoid vague statements such as “next update when circumstances change.”
  • Publish early for significant changes, but never delay a scheduled SitRep, even if there are no major updates.

Leverage Slack features and facilitate sharing:

  • If you’re using Slack for incident communications (as you should be; see my previous blog post Why Slack outshines Zoom for incident management), pin the most recent SitRep in the incident channel.
  • Train responders and observers to check pinned posts when they first join an incident channel.
  • Unpin older SitReps when new ones are pinned to keep the number of pinned posts manageable.
  • Create each SitRep as a separate message or document to facilitate easy forwarding, sharing, and pinning.

Guide follow-ups:

  • Clearly state who to contact and how for questions or corrections (e.g., DM the Incident Commander, post in the incident channel).

Standardize with templates:

  • Develop a consistent SitRep template for use by all incident commanders and communication leads in order to save time, ensure comprehensive coverage, and provide a familiar format for readers.

Here’s an example of a good SitRep:

SitRep 07-Jun-2025 13:35 PDT (20:35 GMT)
#i-5150-api-timeouts Active Sev-2
IC @brent

Situation: Since about 10:30 PDT, dozens of customers have reported slow performance and frequent timeouts on API calls. Dashboards indicate that about 27% of API calls are exceeding SLO targets.

Conditions: Responders have determined that the slow and failing API calls are all related to the users database table. It appears that a database schema change that rolled out at about 10:00 PDT missed a critical index on the users table, which is making database calls that access or update that table much slower than expected.

Actions: @lynn from the Databases team is preparing a further database schema change PR to redefine and regenerate the missing index; @ravi is standing by to review the PR as soon as it is ready. @sami from Customer Care has published a banner on the “report a problem” web page to let customers know that we’re aware of the problem, and @jamie from Developer Relations is sending an email to Tier 1 customers who use the API, informing them of the problem and that we’re working on a fix.

Needs: @ravi from the Databases team needs to finish reviewing and approving the database schema change PR with the fix. Then, we need to deploy it and wait while the index is rebuilt. We currently estimate that the rebuild will take approximately 2 hours, but we won’t know for sure until it is underway and we can see how fast it is proceeding.

Expect the next update in 1 hour, or sooner if circumstances warrant. If you have any questions or concerns, please bring them up in the incident channel (#i-5150-api-timeouts), or DM them to the Incident Commander (currently @brent).

By following these best practices, you can create SitReps that are clear, concise, and contribute to effective incident management.

—–

IT incidents can be costly, impacting both customers (through lost revenue and damaged reputation) and staff (with reduced productivity, decreased morale, and increased turnover). Proactive preparation and continuous learning from incidents are crucial. As an expert incident management consultant, advisor, and coach, I can help your organization develop these critical skills and avoid costly mistakes. Contact me today to learn more.