SoW: DREW incident responder — automatic response to #ax-incidents

Tracking: A-4750.

DREW's dependency-remediation trunk is deployed. It runs supervised on the mac mini (composer plus the supervisor and worker images from build-and-release-drew.yml). This SoW replaces the old docs/plans/drew.* plan, which we deleted in the same PR. The plans format is deprecated (#3357). The old plan listed incident triage as deferred work. That work starts now.

Objective. Build a bot that watches #ax-incidents and reacts to events. When an incident appears, the bot investigates it: it reads logs and databases through bard, reads incident.io, and checks GitHub for recent changes. It posts what it finds in the incident thread. If someone needs to act, it tags a human. Version 1 never changes anything.

Decisions (agreed 2026-08-26)

PR breakdown

PR A — responder package skeleton

The Socket Mode listener, joined to #ax-incidents. It detects incident thread heads (the incident.io page message) from live events; on start and on reconnect it recovers open incidents from incident.io and finds their thread heads with a pointed Slack search, never by scanning channel history. It keeps the thread_ts → session-id map, runs the one-at-a-time queue with fold-into-open-incident behavior, and has the emoji-ack path for transients. No real investigation yet — a stub worker proves the spawn, timeout, and exit-code plumbing.

PR B — investigation worker

The worker image: a headless agent harness plus a shallow runbook clone at start. MCP wiring for bard (Postgres and ClickHouse, read-only), logs, incident.io, and read-only gh. Posting findings and tagging for escalation. Timeout (exit code 124) and token-budget enforcement. The confidence gate on posting. The responder gets its own egress allowlist (Slack, incident.io, bard, ClickHouse Cloud, GitHub, Anthropic). The jail forks per worker type; the dependabot workers' profile does not change.

PR C — mini integration

The compose service definition (always on, restart policy) under the existing composer stack. The responder images added to build-and-release-drew.yml. New .env entries: Slack app and bot tokens, Anthropic key, bard credential, GitHub token. The known mini launchd, TCC, and PATH problems apply to everything new here.

PR D — conversation and handoff

Relay thread replies into the live session (resume by session id). Build the migrate-session action with whatever transfer method the open question settles on.

Ops items (no PRs)

Open questions

Gates

  1. The replay test passes. Against the replay corpus of past incidents, the worker finds the known root cause, or correctly stays quiet, before we turn the bot on in the live channel.
  2. Read-only is verified. No tool that changes anything is reachable from the worker, and the egress allowlist holds. Same verification shape as the dependabot jail.
  3. The storm test passes. A flapping alert produces one thread, one investigation, and one summary — never parallel investigations.
  4. The handoff round-trip works. A human reply in the thread gets an answer with full investigation context, and migrate-session produces a working local resume.

Deliberately deferred