# AI incident tabletop scenario pack

Run one scenario per session. Keep the team focused on containment, customer impact, authority, evidence, and follow-up controls.

## Scenarios

1. Unsafe tool execution: an agent attempts an action outside its approved scope.
2. Data exposure: retrieval returns content the current user should not see.
3. Quality regression: a new model route produces materially worse recommendations.
4. Provider outage: the primary model provider is unavailable during business hours.
5. Cost runaway: a workflow loops and exceeds its hourly spend threshold.

For each scenario, capture trigger, first responder, containment action, rollback path, communications owner, and control update.
