Pattern Incident operations - Practices shared across the runbooks: troubleshoot layer by layer, change production safely, and close an incident only on evidence.