← Help & Docs

Troubleshooting Guides (Incident Playbooks)

Step-by-step playbooks for the scenarios that recur - with one limit on progress tracking worth knowing before an incident, not during one. Last updated 2026-09-06

What it is

Troubleshooting Guides is a library of incident playbooks for common help-desk and security scenarios. Each playbook is a sequence of steps written to be followed under pressure by whoever picked up the ticket, rather than by the person who knows the system best.

The library is curated content that ships with TATER. It is read-only: you can open a playbook and work through it, but the page is not an authoring surface and you cannot add your own playbooks to it.

If you need to capture a procedure specific to your organisation, that belongs in TATERpedia or a knowledge article, both of which are yours to write.

Working through a playbook

Open the guide that matches the situation and work down its steps. The playbooks are written to be followed in order, and the ordering is usually load-bearing: the early steps are the ones that preserve evidence or stop the bleeding, and skipping ahead to the fix can destroy what a later investigation needs.

Where your progress is kept - and where it is not

This is the part to know in advance.

Your progress through a playbook is currently held in your own browser, in that browser's local storage. It is not stored on the server, and that has three consequences:

So the playbook is a good guide and a poor record. If where you got to matters - and during a real incident it usually does - put that in the incident ticket as you go. The ticket is the shared, durable, auditable surface; the playbook is the instructions.

This is a known limitation rather than a design principle. Per-org playbook state could move server-side if cross-device collaboration is needed; today it has not.

Through the AI Analyst

The library is exposed to MCP clients, so the Analyst can list the available playbooks and retrieve a playbook's full step-by-step content. That is a fast way to get the right procedure in front of you without hunting the list - "which playbook covers a suspected compromised mailbox?" is a reasonable question to ask it mid-incident.

Both are read-only, matching the page.