Playbook / Staff+ interview craft / Principal leadership — executive incident brief

Principal leadership — executive incident brief

Expected question

"The CEO is on the line. An agent sent the wrong external message / RAG cited a revoked doc / fraud model spiked false positives. Brief them."

Variant forms

  • "Give me the five-minute exec update on an AI incident."
  • "How do you communicate uncertainty without sounding like you're hiding?"
  • "What do you freeze first — model, tools, or traffic?"

Executive summary

30-second thesis

I'd lead with customer harm and what's already stopped — then cause class, blast radius, and the next checkpoint with an owner. No jargon pile. No "still investigating" without a time.

2-minute spoken brief

Here's the harm: [who was affected, how many, what irreversible happened]. We've already [kill switch / revoke tool / pin previous model / force HITL]. Blast radius is [contained / still widening] because [tenancy / alias / cache]. Likely cause class is [injection / bad promote / skew / threshold], not yet root-caused to a single commit. Next update in [30/60 minutes] from [name]. What I need from you: [decision / comms / customer call] — not a debug party.

What I'd refuse: blaming "the LLM" as if that were a root cause. Models don't ship themselves; promote paths and gates do.

Checklist before you dial

  • Kill switch actually flipped?
  • Audit trail for the bad action?
  • Customer list and severity?
  • Previous known-good alias warm?

Staff+/Principal signal rubric

  • Senior: can describe the outage.
  • Staff+: contains blast radius and owns the next checkpoint.
  • Principal: speaks exec language, separates harm from hypothesis, asks for the decision they need.