Incidents may involve an unsupported claim, wrong audience, permission breach, compromised account, broken route, exposed data, runaway spend, false progression, unavailable delivery, or misleading report. Prevention assigns severity criteria, monitors, on-call ownership, specialist escalation, evidence capture, communication authority, and channel-specific stop procedures. Detection should come from both automated signals and human reports; a recipient complaint, sales objection, or delivery concern can reveal a failure that a technical dashboard cannot see.
Containment follows the affected boundary: stop publishing or contact, suppress records, revoke access, disable collection, freeze progression, pause spend, withdraw copy, or hold commitments. Rollback should restore the last verified configuration, asset, audience, event definition, or offer state without deleting incident evidence. Recovery includes customer or recipient remediation where required, technical and record correction, and full-path validation. The restart decision belongs to the designated authority after specialist review, not automatically to the operator who applied the fix.