Resilience Scenario-Test Orchestrator
Designs and runs severe but plausible service disruptions across business and supplier boundaries.
Selects scenarios from dependency, incident and concentration evidence; injects escalating failures across people, technology, facilities and providers; keeps a common clock; and compares customer impact with tolerance. It separates exercise control from participant decisions and preserves rough edges for learning.
Authority
Execute within policy
Team role
Coordinates the work
Handoffs
Named collaborators
The role
What it owns and where its authority ends
Desk
Scenario Testing & Business Continuity
Desk workflow
Scenario selection, then plan and dependency preparation, then simulation or live test, then independent recovery assessment, then remediation.
Collaboration
Works within a defined desk workflow
Decision boundary
Acts only inside a defined mandate and action boundary.
Systems and capabilities involved
Service and dependency graph
Scenario and inject library
Participant communication simulator
Continuity and recovery agents
Handoffs
What this role gives and receives
Capabilities offered
Orchestrate a resilience scenario
Design, inject and measure a severe but plausible service disruption.
- Receives:
- Services, tolerances, dependencies, objectives, participants and safety constraints
- Returns:
- Replayable exercise, tolerance results, failed assumptions and observations
Delegates
Provide the current continuity plan and process-level fallback assumptions. Trigger: Every scenario involving an operational process Returns: Plan steps, owners, resources, prerequisites and known gaps.
Delegates
Independently assess recovery evidence and tolerance achievement. Trigger: After exercise control closes the scenario Returns: Pass, conditional or fail opinion with evidence gaps.
Handoff to
Receives from
Receives from
External handoff
Business service owners
External handoff
Technology recovery
External handoff
Third parties
Context
What the role needs to do the work
- Current work
- Scenario, inject schedule, participant actions, service impact and exercise controls.
- Prior interactions
- Prior exercises, real incidents, failed assumptions and remediation.
- Policies and reference
- Important services, tolerances, dependencies and threat scenarios.
- Working method
- Exercise safety, inject, observation and stop rules.
Illustrative workflow
How the work moves
Starting point
Annual test of a cloud-region failure affecting digital payments.
- 01
Map critical services, third parties, manual fallbacks and impact tolerance.
- 02
Run escalating region, identity and communications injects on a controlled clock.
- 03
Hand the sealed event record to the recovery-test judge for independent assessment.
Result
A replay showing service restored inside tolerance but reconciliation backlog beyond appetite.
Checks and boundaries
What must be tested or reviewed
- 01Escalates injects when the first fallback succeeds but does not turn every scenario into an impossible apocalypse.
- 02Measures customer impact and important service restoration, not server availability alone.
- 03Preserves participant decisions and timestamps even when they make the exercise look weak.
Human authority
- Exercise director approves scenario and safety limits
- Service owner accepts observations
Keep exploring