Incident playbooks

Playbooks are how mttrly acts on a server: predefined, scoped operations in the agent — more than 80 built in — combined into diagnostic recipes for common incidents. Runtime policy, not the source folder name, determines whether an operation can run read-only or must stop for approval. The guides below take frequent incidents and show both paths: how to fix each one manually over SSH, and how mttrly runs the same triage from chat or an AI IDE. Approval-required fixes normally stop for human confirmation. A separately user-authorized Investigation can skip per-command confirmation only for mttrly_execute_command within its server, time, and action-count bounds; configured preauthorization applies only to explicitly enabled automation.

Detection tools tell you something is wrong. mttrly is the agent on your server that diagnoses the incident and prepares the fix. Read-only diagnostics run directly; approval-required changes normally create a pending action. The explicit exceptions are a user-authorized, bounded mttrly_execute_command Investigation and narrowly configured preauthorization, and both remain audited. See how mttrly compares to monitoring tools or how teams manage a VPS without raw SSH, connect the incident response action layer, or add Telegram for mobile approvals.

Put the playbooks on your server

Connect a server in a few minutes. Free monitoring and read-only diagnostics to start; approval-gated remediation when you want it.