# Incident Narrative Desk

*/Opportunities/Incident_Narrative_Desk*

## Opportunity Overview

**Wedge**: Begin with B2B SaaS engineering teams running on AWS and Slack. This niche utilizes standardized tooling and faces acute pressure to provide external Root Cause Analyses to their enterprise customers quickly. Expand outward by adapting the synthesis engine for cybersecurity incident reporting, and finally into automated compliance documentation generation.
**Timing**: Large language models with extended context windows can now ingest massive, unstructured incident chat logs, pager alerts, and system metrics in a single pass. This eliminates the previously prohibitive engineering cost of building custom parsers for every individual monitoring tool and log format.
**Why This I C P**: Enterprise Site Reliability Engineering and Incident Response teams face strict compliance mandates for incident reporting and suffer extreme fatigue from manual post-mortem writing, making them highly motivated buyers with immediate budget access.
**Size Of Prize**: There are roughly 40,000 mid-to-large enterprises globally with dedicated IT or security operations teams. At an estimated annual software spend of $15,000 per organization for automated incident reporting and communication tools, the total addressable prize is $600M.
**Gap Narrative**: Site reliability engineers and security teams spend hours manually reconstructing timelines, correlating logs, and drafting executive summaries after a critical incident. Current tooling captures alerts and chat logs but fails to synthesize these fragments into coherent, accurate post-mortems and stakeholder updates. The gap is an automated synthesis engine that converts disparate operational exhaust into standardized incident narratives.
**Defensibility**: Defensibility relies heavily on workflow integration and switching costs. Once the system wires directly into the company's Slack workspaces, Jira, PagerDuty, and Confluence to automatically generate reports, removing it requires retraining the entire engineering organization on a manual post-mortem process. The core generation is a commodity, but deep integration creates deep workflow lock-in.
**Why This Thesis**: A Service-as-Software approach fits because incident reporting is an outcome-oriented task, not a software workflow problem. The buyer wants the completed post-mortem document delivered directly to Confluence or Jira, rather than a new dashboard requiring manual operation.

## Opportunity Linked Thesis

**Thesis**: [Service-as-Software](/Theses/Service-as-Software)

## Opportunity Linked I C P

**Icp**: [Managed Service Provider](/CompanyTypes/Managed_Service_Provider)

## Opportunity Market Sizing

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**S A M**: ~$500M-800M targeting North American and European mid-market MSPs managing strict client SLAs
**S O M**: ~$15M-30M realistic 3-year capture targeting mid-sized North American MSPs
**T A M**: ~150k global IT MSPs × ~$12k-15k/yr allocated to incident communication and RCA labor ≈ ~$1.8B-2.2B
**Growth Rate**: ~12-18%/yr, driven by tightening cyber insurance documentation requirements and stricter client SLAs
**Paid Comparable Spend**: ~$15k-30k/yr in displaced labor per MSP, specifically Level 2 and 3 engineers spending billable hours writing post-mortems and client status updates

## Opportunity Incumbents

- [PagerDuty Incident Response](/Products/PagerDuty_Incident_Response) — Tool
- [FireHydrant](/Products/FireHydrant) — Tool
- [Rootly](/Products/Rootly) — Tool
- [Atlassian Opsgenie](/Products/Atlassian_Opsgenie) — Tool
- [Ad-Hoc Google Docs](/Products/Ad-Hoc_Google_Docs) — DIY
- [Manual Tracking Spreadsheets](/Products/Manual_Tracking_Spreadsheets) — Spreadsheet

## Opportunity Win Conditions

**Kill Thresholds**:
- Average human-in-loop editing time exceeds 15 minutes per report after 30 days of usage
- Platform adoption remains under 50 percent of targeted L2/L3 engineers at Day 60
- Zero closed-won deals above $10,000 ACV in the first 90 days of active selling
- Client rejection rate on first-submission RCAs exceeds 20 percent
**Leading Metrics**:
- Time to generate initial incident timeline draft
- Human-in-loop editing minutes per Root Cause Analysis report
- Client SLA acceptance rate on first submission
- Percentage of deployed L2/L3 engineers completing at least one report weekly
- Time-to-first-value measured from initial alert ingestion to first published update
**What Proves Right**: Level 2 and Level 3 engineers at mid-market MSPs use the platform to generate client-facing status updates and Root Cause Analysis documents. These generated reports pass strict client SLA and cyber insurance compliance checks with less than 5 minutes of human revision. MSPs pay $12,000 to $15,000 annually to reclaim billable engineering hours, demonstrating high engagement across the engineering team and minimal churn.
**What Proves Wrong**: Engineers abandon the platform for Google Docs because the generated timelines lack technical accuracy or require extensive manual rewriting. Clients reject the standardized outputs, demanding custom incident formats that the platform cannot handle. MSP owners treat incident documentation as an unavoidable cost of doing business rather than a solvable problem, capping their willingness-to-pay below a sustainable threshold.

## Opportunity Build Profile

**Hardest Part**: Synthesizing a strictly factual chronological timeline from noisy engineering Slack channels and system logs without hallucinating technical details or introducing legal liability.
**Min Viable Scope**: Restrict v1 entirely to internal engineering post-mortem document generation based on Slack and PagerDuty logs. Leave out live crisis communications, legal compliance drafting, external customer status pages, and automated system remediation.
**Cold Start Problem**: The system lacks context on internal service topologies, custom alert names, and company-specific jargon. Overcome this by requiring design partners to provide read access to historical PagerDuty and Slack incident channels to build the initial knowledge graph before a live crisis occurs.
**Time To First Value**: Same-day on historical incidents; gating step is granting read permissions to Slack and PagerDuty APIs to process past data.
**Data Moat Available**: true
**Technical Difficulty**: High

## Neighborhood

### Where the gap lives

- [Protective Service Occupations](/Occupations/Protective_Service_Occupations) — latent gap · Occupations

### Incumbent in

- [Manual Tracking Sheets](/Products/Manual_Tracking_Sheets) — incumbent in · Products
- [FireHydrant](/Products/FireHydrant) — incumbent in · Products
- [Rootly](/Software/Rootly) — incumbent in · Software
- [PagerDuty Incident Response](/Products/PagerDuty_Incident_Response) — incumbent in · Products
- [Ad-Hoc Google Docs](/Products/Ad-Hoc_Google_Docs) — incumbent in · Products
- [Atlassian Opsgenie](/Products/Atlassian_Opsgenie) — incumbent in · Products
- [Axon Records](/Products/Axon_Records) — incumbent in · Products
- [Microsoft Word Templates](/Products/Microsoft_Word_Templates) — incumbent in · Products
- [Carbon Copy Logbooks](/Products/Carbon_Copy_Logbooks) — incumbent in · Products
- [TrackTik Incident Reporting](/Products/TrackTik_Incident_Reporting) — incumbent in · Products
- [Tyler Technologies RMS](/Products/Tyler_Technologies_RMS) — incumbent in · Products
- [Motorola PremierOne](/Products/Motorola_PremierOne) — incumbent in · Products
- [Dictation Transcription Services](/Products/Dictation_Transcription_Services) — incumbent in · Products

### Applies thesis

- [Managed Service Provider](/CompanyTypes/Managed_Service_Provider) — applies thesis · CompanyTypes
- [Private Security Firm](/CompanyTypes/Private_Security_Firm) — applies thesis · CompanyTypes

### Embodies

- [Service-as-Software](/Theses/Service-as-Software) — embodies · Theses
- [Software](/Theses/Software) — embodies · Theses

### Similar Opportunities

- [Automated Incident Reporter](/Opportunities/Automated_Incident_Reporter) — similar · Opportunities
- [Reliability Reporting Automation](/Opportunities/Reliability_Reporting_Automation) — similar · Opportunities
- [Incident Context Synthesizer](/Opportunities/Incident_Context_Synthesizer) — similar · Opportunities
- [Automated Fault Triage](/Opportunities/Automated_Fault_Triage) — similar · Opportunities
- [Root Cause Analyst](/Opportunities/Root_Cause_Analyst) — similar · Opportunities
- [SLA Degradation Triage](/Opportunities/SLA_Degradation_Triage) — similar · Opportunities
- [Automated Incident Dispatch](/Opportunities/Automated_Incident_Dispatch) — similar · Opportunities
- [Status Reporting Agent](/Opportunities/Status_Reporting_Agent) — similar · Opportunities
- [Outage Detection Automation](/Opportunities/Outage_Detection_Automation) — similar · Opportunities
- [Troubleshooting as a Service](/Opportunities/Troubleshooting_as_a_Service) — similar · Opportunities
- [Automated Incident Reporting for Warehousing](/Opportunities/Automated_Incident_Reporting_for_Warehousing) — similar · Opportunities
- [AI Incident Triage](/Opportunities/AI_Incident_Triage) — similar · Opportunities
- [Staged Runbook Retrieval](/Opportunities/Staged_Runbook_Retrieval) — similar · Opportunities
- [Autonomous SRE Responder](/Opportunities/Autonomous_SRE_Responder) — similar · Opportunities
- [Root Cause Investigator](/Opportunities/Root_Cause_Investigator) — similar · Opportunities
- [Automated Log Reconciliation](/Opportunities/Automated_Log_Reconciliation) — similar · Opportunities
- [Predictive Telemetry Engine](/Opportunities/Predictive_Telemetry_Engine) — similar · Opportunities
- [Automated SLA Recovery](/Skills/Systems_Evaluation/Opportunities/Automated_SLA_Recovery) — similar · Opportunities
- [Incident Resolution Automation](/Opportunities/Incident_Resolution_Automation) — similar · Opportunities
- [Automated Compliance Reporting Generation](/Opportunities/Automated_Compliance_Reporting_Generation) — similar · Opportunities
