What does an incident commander do?
During an incident, the commander owns the process of the response. While a technical lead digs into logs and a communications lead drafts status updates, the incident commander maintains the big picture: What do we know? What are we trying next? Who is doing what? When do we update stakeholders? Without a commander, incidents tend to drift. Multiple people investigate the same theory, no one updates the status page, and decisions stall because nobody feels authorized to make them. A commander removes that ambiguity—every question about the response has a clear owner.Incident commander responsibilities
The exact scope varies by organization, but incident commanders typically:- Declare and scope the incident — confirm severity, impact, and which services are affected.
- Assemble the response team — pull in the right responders and assign roles like technical lead, communications lead, and scribe.
- Drive decisions — choose between mitigation options, approve risky actions like rollbacks or failovers, and break ties when responders disagree.
- Manage communication cadence — make sure stakeholders, support teams, and customers get timely updates, even if someone else writes them.
- Track the state of the response — keep a running picture of what has been tried, what is in progress, and what comes next.
- Manage responder workload — rotate people out of long incidents and escalate when the team needs more help.
- Hand off cleanly — brief the next commander during long-running incidents, and kick off the retrospective once the incident is resolved.
What makes a good incident commander?
Good incident commanders are calm under pressure, decisive with incomplete information, and comfortable delegating. Deep technical knowledge of the affected system helps but is not required—in fact, commanders who dive into debugging themselves usually stop commanding, which is the failure mode the role exists to prevent. Look for people who:- Communicate clearly and summarize well, especially in writing
- Ask direct questions (“What do we know? What’s blocking you?”) rather than speculating
- Make timeboxed decisions instead of waiting for perfect information
- Stay blameless and keep the response focused on mitigation, not fault
Incident commander vs. incident manager vs. on-call engineer
These titles are often used loosely, but they describe different things:- Incident commander — leads a specific incident from declaration to resolution. It’s a temporary, per-incident role, not a job title.
- Incident manager — often a permanent job function focused on the incident program: process design, tooling, metrics, and post-incident follow-through. In some organizations “incident manager” is simply their name for the commander role.
- On-call engineer — the person paged first when something breaks. They triage and often resolve small incidents alone. For larger incidents, they may become the incident commander, or they may declare the incident and hand command to someone else while they investigate as technical lead.
How to assign incident commanders automatically
Manually figuring out who should command an incident at 3 a.m. wastes the minutes that matter most. In Rootly, incident commander is a configurable incident role—alongside roles like technical lead, communications lead, and scribe—with clear ownership visible in the incident sidebar, Slack summaries, and the incident timeline. You can fill the role automatically using workflows, Rootly’s automation engine. A workflow can assign the incident commander based on severity, impacted services, incident type, or the current on-call schedule—so the moment a SEV1 is declared, command is already assigned and announced in the incident channel. Responders can also assign or reassign the role directly from Slack, and every change is tracked in the timeline for the retrospective. You can also just ask. Mention@Rootly in the incident channel and tell the Rootly AI agent to assign roles—“make me the incident commander” or “assign Priya as communications lead”—and it applies the change and announces it, without opening a form.
To get started, see Managing Incident Roles Through the Web Interface or Managing Incident Roles Through Slack.