Agent Incident Communication Template
When an agent does something it shouldn't, communication matters as much as the fix. This template structures it.
Internal communication
What happened: [incident summary]
Impact: [financial, data, operational]
Root cause: [pattern + missing rule]
Current status: [contained / investigating / resolved]
Next steps: [rule added, review date]
External communication (if needed)
What we know, what we're doing, when we'll update.
No speculation, no blame — facts and fixes.
One-liner
Agent [X] spent [amount] at [time] due to [pattern]. [Rule] added; [review] scheduled. Full log available in the audit trail.
Clear, honest, complete.
FAQ
When should we communicate externally?
When customers or regulators could be affected — and when your terms require it.
What's the most important line?
The fix — what rule now prevents the pattern.
Related
Stop the next $12,400 night.
One API call (or MCP tool) in front of every agent transaction — APPROVED, BLOCKED, or FLAGGED, deterministic, ~5 ms, fully logged.
See plans — from $99/mo Try a live check