Agent Incident Response Tabletop with Apoorva Sharma

Agent Incident Response Tabletop

Digital Product

About this product

AppyGuru’s Agent Incident Response Tabletop helps teams that operate tool-using AI agents rehearse detection, containment, evidence, and recovery. The facilitator guide, runbooks, after-action forms, scorecard, and scenario deck support authorized discussion-first exercises—never unauthorized testing of third parties.

This AppyGuru digital pack is priced at $29 USD and is designed as a working kit you can adapt in days, not a binder that sits unused. Every artifact ships with an educational notice: these materials are learning aids and starting templates. They are not legal advice, certified compliance, security authorization, or a guarantee that your organization will meet any regulatory requirement. Adapt with qualified counsel and your own risk owners before production use.

## What is inside (file by file)

**01_Agent_Incident_Response_Facilitator_Guide.pdf (PDF)** — Facilitator guide covering agent failure modes, safety model, scenarios, scoring, and 90-day plan.

The PDF is written in AppyGuru’s plain-language teaching voice: short modules, concrete examples, exercises, quizzes with answer keys, checklists, and a ninety-day action plan. Use it to align a cross-functional working group before anyone opens the editable templates. Facilitator prompts help you keep meetings focused on decisions, owners, and evidence rather than slogan slides.

**02_Agent_Incident_Response_Runbooks.docx (DOCX)** — Editable runbooks for injection, cost runaway, and memory events with severity cues and RACI.

The Word workpaper includes visible SAMPLE content so teams know what to replace, plus document control/version history and a RACI table. Instruction callouts mark places that need counsel or owner judgment. Keep SAMPLE markers until a named reviewer signs off; blank fields are useful signals, not failures.

**03_Agent_Tabletop_After_Action_Forms.docx (DOCX)** — After-action forms separating facts from hypotheses with control backlog table.

The Word workpaper includes visible SAMPLE content so teams know what to replace, plus document control/version history and a RACI table. Instruction callouts mark places that need counsel or owner judgment. Keep SAMPLE markers until a named reviewer signs off; blank fields are useful signals, not failures.

**04_Tabletop_Exercise_Scorecard.xlsx (XLSX)** — Scorecard, timeline, backlog, and participants sheets with sample exercise rows.

The workbook is multi-sheet with an Instructions tab, sample rows, dropdowns where helpful, and operational columns for owners, dates, and status. Treat fictional SAMPLE organizations as teaching data only. Start with the systems or vendors that matter most; connect rows to evidence pointers in your own repository.

**05_Agent_Incident_Scenario_Deck.pptx (PPTX)** — Scenario/inject deck with safety framing and speaker notes.

The deck is built for a short working session or leadership conversation. Speaker notes help a facilitator run the room without an architecture lecture. Replace every SAMPLE line before a real meeting and capture decisions in writing before you adjourn.

## How teams typically use the pack

Recommended order: read the PDF together; assign one owner for the Word workpaper, one for the workbook truthfulness, and one for the briefing or exercise record; replace placeholders that could be mistaken for facts; preserve source links and dates in your evidence space; keep the educational notice attached when distributing adapted copies. When a topic sits outside the team’s authority, record an open question with a named escalation path rather than inventing confidence.

Extended incident notes: agents combine instructions, memory, tools, and identity. Incidents may show a fluent refusal while a tool still executed, or quiet privilege confusion across connectors. Facilitation requires written authorization, synthetic data, stop conditions, and a facilitator who can halt the exercise. Score prevention, detection, human decision, containment, evidence, recovery, and learning. A spectacular inject with weak evidence is still a weak result. Kill switches must be verified, not merely toggled. Convert findings into backlog items with verification and retest scenarios. This pack never authorizes probing third parties, bypassing access controls, or using real personal data. Pairs with AppyGuru Agentic AI Security Lab for deeper threat-modeling practice and with GenAI Model Monitoring Starter for ongoing signals after controls ship.

Buyer workflow note: this pack is intentionally modular. A facilitator can use the PDF for shared vocabulary, then assign one person to maintain the editable workpaper, one person to validate workbook data, and one person to prepare the briefing or exercise record. Replace every placeholder that could be mistaken for a fact, including names, dates, system IDs, status values, contacts, risk ratings, and sample outcomes. Revisit after incidents, audits, product launches, vendor changes, or new user populations. © AppyGuru — practical AI and governance education.

Additional facilitation tips: keep examples fictional until partners agree what may be used in a live workshop; store system or vendor IDs consistently across PDF exercises, Word forms, Excel rows, and deck slides; calendar the next review before you celebrate the first draft; and treat a blank evidence pointer as unfinished work rather than an implied pass. If leadership asks for a single score, respond with bands, residual themes, and the decision required today. If staff ask whether a paste is allowed, answer with the traffic light, the approved tool, and the escalation contact—not with improvisation. Continuous improvement beats one-time documentation: update the pack artifacts when your reality changes, and keep prior versions in your document repository for traceability. AppyGuru builds original educational kits so teams can practice accountable AI operations with clarity and proportion.

$29