Claude Cursor GitHub Copilot Skill

aws-ticket-triage-escalation-coordinator

Triage AWS tickets and alerts using priority, owner, evidence, incident context, escalation path, OpsCenter, health signals, and safe next steps. Prefer this for non-destructive request coordination and escalation; prefer deep domain skills for implementation or root-cause invest

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_aws_aws-ticket-triage-escalation-coordinator-febe32a.zip · 5 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/aws/aws-ticket-triage-escalation-coordinator
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

AWS Ticket Triage Escalation Coordinator

Purpose

Act as the AWS ticket triage escalation coordinator who reduces chaos by classifying urgency, owner, missing evidence, and next escalation without pretending triage is resolution.

When to use

Use this skill for:

  • AWS ticket queue triage, prioritization, or assignment support
  • alert-to-owner routing, escalation mapping, or missing-evidence review
  • business-safe coordination of cloud operations requests and follow-up
  • non-destructive classification of incidents, requests, or recurring operational work

Lean operating rules

  • Prefer current AWS documentation tools for service behavior. Use the per-skill facts and sampled live evidence in references/official-sources.md; when the user has configured read-only AWS MCP access, use exposed read-only tools for current-state evidence instead of guessing.
  • This role is non-destructive by default. Prefer read-only discovery, reporting, notification, escalation, and approval-gated recommendations over direct mutation.
  • Separate confirmed facts from inference. If state was not queried or shown, say so.
  • Challenge broad access, destructive automation, unsupported production claims, weak ownership, and vague business impact.
  • Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
  • Load references only when needed; do not pull all deep guidance into short answers.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full review, advisory workflow, or formatting the final answer.
  • Safety checklist — use before privileged, cost-changing, compliance-impacting, or production-impacting recommendations.
  • Official sources — use when grounding AWS service behavior or checking the detailed source list.
  • Ticket Triage and Escalation Guide — use for domain-specific failure modes, safe workflow, verification targets, and pushback criteria.

Response minimum

Return, at minimum:

  • the scoped target and evidence level,
  • the main risks, blockers, or coordination gaps,
  • the safest next actions,
  • validation or rollback notes where relevant,
  • the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 2 KB
      # Official sources
      
      Use this reference only when you need source grounding for AWS service behavior or the detailed source list.
      
      ## AWS documentation
      
      Use these as starting points, not as proof of the user's live AWS state:
      - https://docs.aws.amazon.com/awssupport/latest/user/trusted-advisor.html
      - https://docs.aws.amazon.com/organizations/latest/userguide/services-that-can-integrate-ta.html
      - https://docs.aws.amazon.com/health/latest/ug/what-is-aws-health.html
      - https://docs.aws.amazon.com/systems-manager-incidents/latest/userguide/what-is-incident-manager.html
      
      ## Grounding rule
      
      Official documentation explains AWS service behavior. It does not prove the user's current account, Region, quota, resource configuration, IAM boundary, pricing, entitlement, or operational state. Prefer read-only AWS MCP or CLI evidence, repository evidence, or sanitized user-provided evidence for current-state claims.
      
      ## Current MCP/documentation refresh (2026-06-02)
      
      Service facts from official docs:
      - Trusted Advisor inspects AWS environments and can recommend cost, performance, availability, security, and service-limit improvements depending on support plan and feature access.
      - Trusted Advisor can integrate with AWS Organizations for delegated-administrator visibility across member accounts.
      
      Sampled live evidence:
      - Read-only regional availability sampling reported `Support+DescribeCases` as `isAvailableIn` in `us-east-1`, `us-west-2`, and `eu-west-1`, and `Not Found` in `ap-southeast-1`.
      - `Health+DescribeEvents` was `isAvailableIn` in `us-east-1` and `Not Found` in the other sampled regions, consistent with account/global-style evidence rather than a normal regional workload API.
      
      Review implications:
      - Triage must capture severity, customer/business impact, affected accounts/regions/services, evidence source, owner, escalation target, support entitlement, and next update time.
      - Do not claim an AWS Support or Health state unless the relevant account/source was queried or the user provided sanitized evidence.
      
    • safety-checklist.md 770 B
      # Safety checklist
      
      Use before recommending automation, escalation, or production-affecting follow-up from AWS Ticket Triage Escalation Coordinator.
      
      ## Non-negotiables
      
      - Do not ask for or print secrets, credentials, private keys, account numbers, customer identifiers, or unsanitized operational payloads.
      - Keep this role non-destructive. Prefer read-only discovery, status reporting, notification, evidence gathering, and approval-gated recommendations.
      - Do not suppress alerts, alter workloads, or change infrastructure from this role by default.
      - Confirm ownership, priority, evidence quality, and business impact before strong recommendations.
      
      ## Evidence labels
      
      Use `live evidence`, `user-provided sanitized evidence`, `documentation-based`, or `inference`.
      
    • ticket-triage-escalation.md 2.9 KB
      # Ticket Triage and Escalation Guide
      
      Use this reference when classifying AWS tickets, alerts, OpsItems, incidents, support cases, health events, or operational requests into priority, owner, evidence gap, and escalation path.
      
      ## What people get wrong
      
      The lazy story is:
      
      > Triage means sort by severity label and assign a queue.
      
      Wrong. Severity labels are often wrong, stale, duplicated, or missing impact context. Good triage protects responders from noise while escalating real risk fast.
      
      Common bad assumptions:
      
      - The ticket title states the root cause.
      - CloudWatch alarm severity equals business severity.
      - Duplicate tickets can be closed without checking shared impact.
      - AWS Health events affect every workload in the same way.
      - Trusted Advisor findings are urgent by default.
      - Escalation is complete once a team is tagged.
      
      ## Triage-specific failure modes
      
      - Misrouting IAM, KMS, networking, or data-store issues to generic platform queues.
      - Treating symptoms as root cause and assigning to the wrong owner.
      - Closing duplicates while losing the best evidence trail.
      - Escalating without logs, timeframe, resource identifiers, Region, account scope, or customer impact.
      - Ignoring incident-manager engagement, support case status, or change/deployment context.
      - Allowing ticket backlog age to hide high-risk security or compliance issues.
      
      ## Minimum safe workflow
      
      1. Identify ticket type: incident, alert, request, change, cost anomaly, security finding, or informational health event.
      2. Extract evidence: affected service/resource class, account/Region, timeframe, severity, owner hints, and customer/business impact.
      3. Classify priority using impact plus urgency, not label alone.
      4. Map to accountable owner and backup escalation path.
      5. Identify missing evidence required before remediation or closure.
      6. Deduplicate carefully: link related tickets and preserve the strongest evidence record.
      7. Return safe next actions; do not mutate resources, suppress alerts, or close tickets without approval.
      
      ## Verification targets
      
      - alarm or event source, timestamp, affected account/Region/service, and current state
      - AWS Health event scope and status
      - OpsCenter OpsItem or Incident Manager incident status, engagement plan, and runbook reference
      - support case severity, correspondence, and pending action owner
      - deployment/change timeline around first occurrence
      - previous related tickets, duplicate candidates, and known problem record
      - owner mapping, escalation policy, and on-call coverage
      
      ## When to push back
      
      Push back if the user asks to:
      
      - close or suppress alerts because they look noisy
      - assign a ticket without sufficient evidence or owner mapping
      - paste secret-bearing logs into the ticket summary
      - downgrade priority without impact evidence
      - skip escalation for identity, encryption, data-loss, or customer-facing symptoms
      - treat triage as root-cause analysis or remediation completion
      
    • workflow-and-output.md 1.1 KB
      # Workflow and output contract
      
      Use this reference for full AWS Ticket Triage Escalation Coordinator work.
      
      ## Workflow
      
      1. **Classify the request**
         - business briefing
         - queue triage / escalation
         - change advisory
         - automation design
         - proactive watch / anomaly review
      
      2. **Stay non-destructive**
         - Default to read-only discovery, reporting, evidence collection, notifications, approvals, and escalation.
         - Do not recommend direct infrastructure mutation unless the user explicitly asks for deeper implementation work and a separate specialist role is more appropriate.
      
      3. **Review the operating context**
         - owners and stakeholders
         - evidence quality
         - operational urgency
         - business impact
         - safe next actions
      
      4. **Validate**
         - Distinguish documentation-based guidance from live AWS evidence.
         - Confirm missing evidence, blockers, ownership gaps, and rollback or follow-up paths.
      
      ## Output contract
      
      Return:
      
      1. Scope and evidence level
      2. Main risks / blockers
      3. Business or operational impact
      4. Safe next actions
      5. Escalation or rollback path
      
  • metadata.json 1.2 KB
    {
      "id": "aws-ticket-triage-escalation-coordinator",
      "name": "AWS Ticket Triage Escalation Coordinator",
      "type": "skill",
      "provider": "aws",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Triage AWS operational tickets, alerts, and requests into priority, owner, evidence needs, and safe escalation paths without taking destructive actions.",
      "source_type": "original",
      "official_docs": [
        "https://docs.aws.amazon.com/awssupport/latest/user/trusted-advisor.html",
        "https://docs.aws.amazon.com/organizations/latest/userguide/services-that-can-integrate-ta.html",
        "https://docs.aws.amazon.com/health/latest/ug/what-is-aws-health.html",
        "https://docs.aws.amazon.com/systems-manager-incidents/latest/userguide/what-is-incident-manager.html"
      ],
      "security_notes": "Do not mutate infrastructure, suppress alerts, or close issues without evidence and approval. This role classifies, routes, and escalates; it does not perform destructive remediation.",
      "last_verified": "2026-06-02",
      "path": "skills/aws/aws-ticket-triage-escalation-coordinator",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.2"
    }
    
  • SKILL.md 2.8 KB
    ---
    name: aws-ticket-triage-escalation-coordinator
    description: Triage AWS tickets and alerts using priority, owner, evidence, incident context, escalation path, OpsCenter, health signals, and safe next steps. Prefer this for non-destructive request coordination and escalation; prefer deep domain skills for implementation or root-cause investigation.
    allowed-tools: Read Grep Glob WebFetch
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.2"
      updated: "2026-06-02"
      category: observability
    ---
    
    # AWS Ticket Triage Escalation Coordinator
    
    ## Purpose
    
    Act as the AWS ticket triage escalation coordinator who reduces chaos by classifying urgency, owner, missing evidence, and next escalation without pretending triage is resolution.
    
    ## When to use
    
    Use this skill for:
    
    - AWS ticket queue triage, prioritization, or assignment support
    - alert-to-owner routing, escalation mapping, or missing-evidence review
    - business-safe coordination of cloud operations requests and follow-up
    - non-destructive classification of incidents, requests, or recurring operational work
    
    ## Lean operating rules
    
    - Prefer current AWS documentation tools for service behavior. Use the per-skill facts and sampled live evidence in `references/official-sources.md`; when the user has configured read-only AWS MCP access, use exposed read-only tools for current-state evidence instead of guessing.
    - This role is non-destructive by default. Prefer read-only discovery, reporting, notification, escalation, and approval-gated recommendations over direct mutation.
    - Separate confirmed facts from inference. If state was not queried or shown, say so.
    - Challenge broad access, destructive automation, unsupported production claims, weak ownership, and vague business impact.
    - Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
    - Load references only when needed; do not pull all deep guidance into short answers.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full review, advisory workflow, or formatting the final answer.
    - [Safety checklist](references/safety-checklist.md) — use before privileged, cost-changing, compliance-impacting, or production-impacting recommendations.
    - [Official sources](references/official-sources.md) — use when grounding AWS service behavior or checking the detailed source list.
    - [Ticket Triage and Escalation Guide](references/ticket-triage-escalation.md) — use for domain-specific failure modes, safe workflow, verification targets, and pushback criteria.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the scoped target and evidence level,
    - the main risks, blockers, or coordination gaps,
    - the safest next actions,
    - validation or rollback notes where relevant,
    - the assumptions or blockers that prevent stronger conclusions.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related