adobe-incident-runbook
Adobe Integration Incident Command
Overview
Triage, contain, recover, and review Adobe auth, product, async-job, event, storage, spend, or App Builder incidents with evidence. This workflow produces a reviewable artifact and evidence before any live side effect.
Prerequisites
- Current first-party Adobe documentation for every selected service, API version, auth flow, limit, and lifecycle.
- Named product, identity, security, data, budget, release, and operations owners appropriate to the scope.
- Synthetic or approved non-production fixtures with secret and content canaries.
Current Contract
Vendor status, local deployment, credentials/entitlement, request validity, queues, storage, and downstream systems are separate failure domains. Containment preserves evidence while stopping new harm; recovery never starts with blind retry or credential deletion. Recheck the dated evidence map before relying on mutable product behavior.
Authentication
A suspected secret or signed-URL exposure is a security incident. Add/rotate/deploy/verify before approved old-secret deletion; invalidate exposed temporary access and preserve last-use evidence.