Game Day Facilitation
A game day is a scheduled drill of people and process. Produce a facilitation pack: objectives, roles, inject script, abort criteria, observer sheet, and debrief. Fault hypotheses belong to chaos-experiment-design. A live SEV belongs to incident-command.
Workflow
- Objective. One learning goal (runbook, paging, failover comms, shadow independence). "Break prod and see" is not an objective.
- Scope and env. Staging, or an announced approved prod window. Named blast radius. Named abort conditions before any inject.
- Roles. Facilitator, inject operator, primary, shadow, observers, scribe. Dual-hat on a small team is fine; say who wears which hats.
- Inject script. Timed cards. Each inject has stop/rollback. No surprise extras mid-drill.
- Safety brief. Blameless. How to abort. Who may abort. Freeze if a real incident starts.
- Run. Facilitator owns the clock. Observers stay quiet on the bridge unless safety is at risk.
- Debrief same day. Facts, process and runbook gaps, 1–3 owned actions. No blame.
Roles
- Facilitator — clock, inject cadence, abort, psychological safety.
- Inject operator — executes the scripted fault; never freelances.
- Primary — treats it as real; owns mitigate decisions.
- Shadow — does the work or narrates; primary can take over.
- Observers — watch comms, decisions, runbook use; no coaching unless the facilitator asks.
- Scribe — UTC timeline of detections, decisions, injects, aborts.
Output format
# Game day: <name>
**When / env:** …
**Objective (one line):** …
**In scope / out of scope:** …
**Abort if:** …
**Who may abort:** …
## Roles
| Role | Name | Notes |
## Inject script
| T+ | Inject | Expected | Rollback | Owner |
## Observer prompts
- Comms: …
- Decisions: …
- Runbook: …
- Shadow: …
## Safety brief (read aloud)
- This is a drill. Blameless. Freeze on real SEV → `incident-command`.
- Never surprise prod. Abort is success, not failure.
## Debrief
**What we saw:** …
**Runbook / paging gaps:** …
**Actions (max 3):**
- [ ] … — Owner: … — Due: …
Rules
- Never surprise production. Refuse unannounced prod injects; offer a scheduled drill or a tabletop instead.
- Abort criteria are mandatory and specific (error budget, customer impact, real pager, facilitator call). Abort ends the drill cleanly.
- Psychological safety: no gotchas, no public scoring of people, no blame in notes or debrief.
- One inject variable at a time unless the script already says otherwise.
- Do not invent SLO numbers, customer counts, or tool syntax.
- Fault hypothesis / blast radius →
chaos-experiment-design. Keep this skill on roles, injects, observers, and debrief. - Live SEV → stop the drill and hand to
incident-command.
Edge cases
- Tabletop only: same pack; injects are narrative cards, not live faults. Still abort, observers, debrief.
- On-call shadow, no inject: objective is the pager path and handoff; observer watches; still debrief.
- Real incident during the drill: abort immediately; announce freeze; remaining work is
incident-command. - "Kill pods in prod for fun": refuse. Staging or a scheduled, approved window with abort criteria only.
- User wants only the chaos hypothesis: point at
chaos-experiment-design; do not turn this into experiment design.