Skip to content
Resilience agents
Risk, Trust & ResilienceResilienceScenario Testing & Business Continuity

Resilience Scenario-Test Orchestrator

Designs and runs severe but plausible service disruptions across business and supplier boundaries.

Selects scenarios from dependency, incident and concentration evidence; injects escalating failures across people, technology, facilities and providers; keeps a common clock; and compares customer impact with tolerance. It separates exercise control from participant decisions and preserves rough edges for learning.

Authority

Execute within policy

Team role

Coordinates the work

Handoffs

Named collaborators

The role

What it owns and where its authority ends

Desk

Scenario Testing & Business Continuity

Desk workflow

Scenario selection, then plan and dependency preparation, then simulation or live test, then independent recovery assessment, then remediation.

Collaboration

Works within a defined desk workflow

Decision boundary

Acts only inside a defined mandate and action boundary.

Systems and capabilities involved

  • Service and dependency graph

  • Scenario and inject library

  • Participant communication simulator

  • Continuity and recovery agents

Handoffs

What this role gives and receives

Capabilities offered

Orchestrate a resilience scenario

Design, inject and measure a severe but plausible service disruption.

Receives:
Services, tolerances, dependencies, objectives, participants and safety constraints
Returns:
Replayable exercise, tolerance results, failed assumptions and observations

Delegates

Business Continuity Plan Maintainer

Provide the current continuity plan and process-level fallback assumptions. Trigger: Every scenario involving an operational process Returns: Plan steps, owners, resources, prerequisites and known gaps.

Delegates

Recovery Test Evidence Judge

Independently assess recovery evidence and tolerance achievement. Trigger: After exercise control closes the scenario Returns: Pass, conditional or fail opinion with evidence gaps.

External handoff

Business service owners

External handoff

Technology recovery

External handoff

Third parties

Context

What the role needs to do the work

Current work
Scenario, inject schedule, participant actions, service impact and exercise controls.
Prior interactions
Prior exercises, real incidents, failed assumptions and remediation.
Policies and reference
Important services, tolerances, dependencies and threat scenarios.
Working method
Exercise safety, inject, observation and stop rules.

Illustrative workflow

How the work moves

Starting point

Annual test of a cloud-region failure affecting digital payments.

  1. 01

    Map critical services, third parties, manual fallbacks and impact tolerance.

  2. 02

    Run escalating region, identity and communications injects on a controlled clock.

  3. 03

    Hand the sealed event record to the recovery-test judge for independent assessment.

Result

A replay showing service restored inside tolerance but reconciliation backlog beyond appetite.

Checks and boundaries

What must be tested or reviewed

  1. 01Escalates injects when the first fallback succeeds but does not turn every scenario into an impossible apocalypse.
  2. 02Measures customer impact and important service restoration, not server availability alone.
  3. 03Preserves participant decisions and timestamps even when they make the exercise look weak.

Human authority

  • Exercise director approves scenario and safety limits
  • Service owner accepts observations

Keep exploring