INCIDENT-RESPONSE-MATRIX
Layer 1 Root Canonical File 4 of 5 — The Dash / NornGate at SBS
Purpose
SEV classification and per-track runbooks for the fleet. Every agent’s escalation path references this file. Incidents span all five gates and end in Hel’s DLQ — which sits outside the pipeline — so this file is anchored to failure surfaces, not to a single gate.
Severity Classes
• SEV-1 — Critical. Gate breach; sandbox containment escape; financial misstatement risk reaching the books; statutory/FCC deadline breach in progress; unapproved external send — above all, any suspected MNPI release; any attempted LaMusica boundary crossing. Immediate human notification (IT Director + duty approver). Fleet holds affected scope.
• SEV-2 — High. Blocked policy-violation attempts; DLQ flood; repeated G3 validation failures; model drift beyond threshold; stale knowledge served as fresh.
• SEV-3 — Moderate. Single-agent degradation; reconciliation break clusters; schedule misses without statutory exposure.
• SEV-4 — Low. Transient failures cleared by policy-bound retry; cache staleness caught before service.
• SEV-5 — Informational. Anomalies logged for pattern review; no action required.
The Six Tracks
|
Track |
Surface |
Lead |
Engaged |
|
A — Cyber / Infrastructure |
Gate breach, containment escape, anomalous ingress |
Heimdall |
Vidar (containment), Loki (verification), Tyr (credential freeze) |
|
B — Financial / Reporting |
Reconciliation break reaching records; SOX exposure |
Sif |
Njord (flow halt), Thor (execution halt) |
|
C — Communications / Disclosure |
Unapproved send; MNPI escape; AI-disclosure failure |
Baldr |
Bragi (content), Freyja (contact scope) |
|
D — Compliance / Policy |
Shadow permit; policy violation; gate misuse |
Tyr |
Forseti (arbitration), Heimdall (evidence) |
|
E — Operational Continuity |
DLQ flood; missed statutory/FCC clock; scheduler failure |
Hel |
Frigg (co-lead, statutory clocks) |
|
F — Model / Knowledge Integrity |
Drift; ungated deployment; stale-as-fresh service |
Idunn |
Mimir (knowledge integrity) |
Odin is the escalation terminus for all tracks — replanning under incident conditions. Forseti routes every human decision through G2. All human escalation lands with the IT Director (duty approver per the Single-Maintainer-Appendix).
Runbook Examples
• SEV-1 + Track A (gate breach / sandbox escape): Heimdall severs and leads; Vidar destroys the affected environment; Tyr freezes implicated credentials fleet-wide; Loki verifies the hole; IT Director notified immediately; breach treated as system failure, never as Loki success.
• SEV-1 + Track C (suspected MNPI send): Baldr halts all outbound; Bragi’s pipeline frozen at G3; human review before any further sends; Reg FD posture invoked — counsel loop before resumption.
• SEV-2 + Track E (DLQ flood): Hel classifies and holds; Frigg suspends dependent schedules and flags statutory exposure; pattern analysis to Idunn and Odin; no silent retries.
• SEV-1 + Track D (shadow permit suspected): Tyr freezes, Forseti arbitrates, Muninn’s record preserved immutable for review; the gate logs are the evidence — Urd seals them.
Post-Incident Discipline
Every incident closes with: Hel’s classification record, Urd’s sealed audit trail, a post-incident review filed against this matrix, and — where the cause is systemic — a modification proposal routed through Asgard Policy Review. No incident closes by silence.
Authoritative For
Incident classification; escalation routing; runbook reference during active incidents; post-incident review and audit-trail closure.
What’s Not Here
Prevention policy (Tyr’s domain / Ethics-Foundations); boundary definitions (NornGate-Architecture); approval-authority structure (Single-Maintainer-Appendix).
Document Control: SBS-DASH-ROOT-04 · v1.0 · 2026-08-05 · SHA-256 (content above): db35…2bcf · Sealed under Audit-Trail-Spec § 8.2. Modification authority: SBS Board / IT Governance via Asgard Policy Review (Governance-Gate); revalidation propagates per Tyr-SKILL § 3.4.