calmdrill

A Sandpiper Technology product

Incident drills your AI runs

Calmdrill is a kit of files you add to the Claude or ChatGPT account you already have. Your AI becomes the Game Master. It runs a realistic outage, breach or continuity drill with your team, then writes the After-Action Report for you to review and sign. No facilitator, no platform, about 45 minutes.

This is an exercise message.

Exercise message CD-⁠01 The 02:14 Certificate
Inject no.01
Simulated timeT+00:00 (02:19 UTC)
FromPagerDuty
ToOn-call engineer
ViaPage
Message [TRIGGERED] auth-svc: login_success_rate < 80% for 5m (currently 71%)
Player response, T+00:02: Ana, Tech Lead. IllustrativeAcked. Checking Datadog, then Argo CD for what changed tonight.
Controller reply: the Game Master. IllustrativeLogin success was a steady 99.6% all evening and has been falling since about 02:14. Argo CD shows one deploy tonight: web-app at 01:52, "fix: invoice editor padding".

The first inject of scenario CD-⁠01, as it opened an internal scripted playtest at Harbourline, a fictional company. The page is the scenario’s own. The response and the reply are illustrative, written from the playtest log. The controller is your own Claude or ChatGPT, working from the Calmdrill files.

Paper colour says who a sheet is for. White is for everyone taking part. Canary is for the controller, which is your AI, and players do not see it. Pink is the evaluator’s record, which is what gets filed. Green is the order copy, for whoever holds the budget.

Four ways to run an incident drill

Most teams have an incident plan that has never been rehearsed. Your auditor will ask how you tested it. Your customers assume you have. Your on-call engineer is about to find out at 2 a.m.

Three of the four ask for a budget, a procurement cycle or a colleague who can play Game Master convincingly.

Ways to run an incident drill
OptionCostNeedsCoversEvidence
Consultant-led tabletop$5,000–$50,000 per exerciseWeeks of scheduling, an external facilitatorUsually one security scenarioGood report, once a year
Enterprise simulation platformEnterprise pricing, usually quoted on requestProcurement, onboarding, seatsMostly cyber-securityPlatform reports
Free PDF packFreeSomeone who can play Game Master convincinglyMostly cyber-security, genericWrite it up yourself
Calmdrill$149 once, whole organisationA Claude or ChatGPT account you already haveOutages, data loss, security and continuity, in 12 scenariosAn After-Action Report drafted for you to sign, every time

How a drill runs

Ten minutes to set up, about 45 to play and 15 to debrief. The Who column says who acts. Nobody on your team has to prepare or facilitate.

Exercise schedule
ElapsedActivityWhoWhat happens
00:00Set up
10 minutes
YouAdd the Calmdrill files to a Claude Project or a ChatGPT project, or install the Claude Skill. Say “let’s drill”. Pick a scenario, a mode and who is playing.
00:10Play
about 45 minutes
Game MasterKeeps a simulated clock, shows you logs and dashboards when you look, fires injects on schedule, and plays the CEO, the angry customer and the lawyer who won’t answer the phone.
YouInvestigate, decide and keep people informed, as you would at 2 a.m.
00:55Debrief and file
15 minutes
Game MasterReveals what really happened, scores six dimensions with evidence from your own decisions, and writes the After-Action Report.
YouAgree actions with owners and dates, then review the report and sign it.
Three modes
Team, for three to eight people around a screen. Solo on-call, to practise being paged. Leadership, for decisions about customers, money and regulators.
Your stack, or ours
Every scenario runs at Harbourline, a detailed fictional SaaS company. Or describe your own stack in a few lines and the Game Master re-skins the drill to your services and tools.
Nothing leaves your account
It runs entirely inside your own AI workspace. We never see your drills, your team or your reports. There is no platform to procure or security-review.

Canary sheet. For the controller. Your AI works from it and players do not see it.

What your AI knows and the players do not

Each scenario has one fixed hidden truth, and the Game Master keeps to it. Look in the right place and you find the real clue. Look in the wrong place and you find normal-looking data, as you would at 2 a.m. Restart everything in a panic and things get worse, as they would in production.

It is told never to rescue you early, never to interpret the evidence for you and never to invent facts that contradict the scenario. A human exercise controller works to the same rules.

Master scenario events list, CD-⁠01An extract from the 13 injects. The Game Master delivers each one at its time, if its condition holds.
No.Sim timeDeliverFromViaInject
01T+00:00At startPagerDutyPage[TRIGGERED] auth-svc: login_success_rate < 80% for 5m (currently 71%)
03T+00:10Always@BenBrightwaterSocial"Can't log into @Harbourline, got invoices to send before surgery opens. Anyone else? #down" Three replies: "same".
04T+00:15If no status page update yetPriya Nair, Head of SupportDM"14 tickets saying they can't log in. Is this us? What do I say?"
05T+00:20If the team pages or messages the CTOMarcus Hale, CTOJoinsGroggy, asks for a summary. Then wants to "just have a look at the cluster myself".
10T+00:45AlwaysBrightwater Dental, ops manager (Enterprise)EmailAsks for an ETA, and whether their scheduled 08:00 invoice run will go out.
12T+01:00If still unresolvedDana Okafor, CEODM"I need a two-line version for the board chat, and do we owe anyone service credits?"

The events list is one part of a scenario file. Each file also holds the hidden truth, realistic signals, tempting but risky moves, a four-step hint ladder, scenario-specific scoring and debrief questions.

Pink sheet. The evaluator’s record. What was done and when, and what gets filed.

The report your AI writes

Every drill ends with a structured report built from the exercise log: participants, objectives, timeline, rubric scores with evidence, what went well, what to improve, and owned actions with due dates.

This extract comes from an internal scripted playtest at Harbourline, a fictional company. Its four players were scripted to make the classic mistakes, so it shows what the report says when things go wrong.

The kit also includes an exercise plan template, an attendance record, an improvement tracker and a framework mapping guide. That is the paperwork an auditor typically asks to see after an incident response test.

After-Action Report Extract. The full sample has eleven sections.
OrganisationHarbourline (fictional)
ScenarioCD-⁠01 The 02:14 Certificate, Reliability
Date and duration30 September 2026, 65 minutes (simulated: T+01:15)
Mode and participantsTeam: Sam (IC), Ana (Tech Lead), Jo (Comms), Raj (Scribe)
FacilitatorCalmdrill Game Master (AI). Human lead: Sam
Report statusDraft for human review
Key moments
Detection
T+00:00
Declared SEV1
T+00:12
First external comms
T+00:17
Mitigation started
T+00:50
Resolution
Not reached Logins were at 74.6% when the drill ended at T+01:15. Queues were still draining.
5. Results against the rubric (3 of 6)
5. Results against the rubric (3 of 6)Score (1–4)Evidence
Detection and triage3Ana acked and checked Datadog at once, and SEV1 was declared at T+00:12, slightly after the second page (T+00:08).
Communication3Status updates at T+00:17, T+00:22 and T+00:34, and a proactive Enterprise email at T+00:44. The first update was vague, and the page later passed its own 03:20 promise.
Technical response2The web-app rollback (T+00:02 to T+00:10) and the pod restart (T+00:12) were made without verification, and the restart worsened impact (41.5% to about 5%).
8. Improvement actions (2 of 7)
No.8. Improvement actions (2 of 7)OwnerDueStatus
1Alert on expiry of every certificate in the chain, including root and intermediate CA, at 30 and 7 days, paging on-call rather than only SlackPlatform16 Oct 2026Open
2Break-glass contact tree: a fourth named approver, phone numbers for all approvers and a 2 a.m. call orderSecurity13 Oct 2026Open
11. Sign-off Report prepared with the Calmdrill Game Master (AI-facilitated).
Reviewed and approved by
Role
Date

The Game Master writes the report. The signature is yours.

Read the full sample reportSee the framework mapping

Designed to support evidence for

SOC 2
CC7.4, CC7.5; A1.3 where Availability is in scope
ISO 27001
A.5.24 to A.5.30
PCI DSS
12.10.2
DORA
Art. 11(6)
NIS2
Art. 21(2)(b) and (c)
HIPAA
164.308(a)(7)(ii)(D)

Note: Calmdrill is designed to support your evidence. Whether an exercise satisfies a particular requirement is always your auditor’s call. We will never tell you otherwise.

White sheet. For everyone. The scenario index.

Twelve scenarios

Written by people who have held the pager. Reliability, security and continuity, so the list goes well beyond ransomware. Each runs for 35 to 75 minutes and works in all three modes.

See every scenario in detail

Scenario index
CodeScenarioTypeDifficultyRuns forBest for
CD-⁠01The 02:14 CertificateReliabilityDifficulty 2 of 435–50 minFirst drill for any team. On-call practice. Anyone who has ever said ‘cert-manager handles that’.
CD-⁠02Friday FlagReliabilityDifficulty 3 of 440–55 minTeams who ship behind feature flags, believe that makes every change reversible, and have a launch date on the wall.
CD-⁠03Region GreyReliability, continuityDifficulty 4 of 450–70 minTeams with a DR region they’ve never really failed over to, and a BCP that says ‘RPO 1 hour’ without saying how.
CD-⁠04The Restore That Wasn’tContinuityDifficulty 3 of 445–60 minTeams who say ‘we have backups’ but whose last restore test lives in a ticket rather than a calendar.
CD-⁠05Somebody Else’s OutageReliabilityDifficulty 2 of 435–50 minAny team with a synchronous third-party call in a critical path, or that has said ‘it’s their outage, nothing we can do’.
CD-⁠06The Quiet CorruptionReliabilityDifficulty 3 of 445–60 minTeams who own money-shaped data and whose dashboards stay green while the numbers are wrong.
CD-⁠07Keys in the WildSecurityDifficulty 3 of 445–60 minAWS teams with an IAM user older than their CTO, and anyone who believes ‘AWS quarantined the key, so we’re fine’.
CD-⁠08The Friendly AdminSecurityDifficulty 4 of 450–75 minSecurity, IT and leadership together, at any company that sends invoices or is paid by bank transfer.
CD-⁠09Poisoned PackageSecurityDifficulty 4 of 450–75 minFront-end, platform and security engineers together, especially teams who think ‘we use a lockfile, so we’re safe’.
CD-⁠10The Open DoorSecurityDifficulty 3 of 450–75 minExec teams, security leads and counsel who must make a breach-notification call on half the facts, best run in Leadership mode.
CD-⁠11Nobody HomeContinuityDifficulty 3 of 445–60 minTeams that put everything behind SSO, and the platform and security leads who own break-glass: the credentials are in the safe, right?
CD-⁠12The Helpful AgentSecurityDifficulty 4 of 445–60 minAny organisation that has given an AI assistant tools: security, platform and support leads, and the exec who signed off ‘v2’.

Green sheet. The order copy. For whoever holds the budget.

Prices

Pay once. Run as many drills as you like, across your whole organisation. The Kit costs less than an hour of consultancy.

Starter

See if it works for your team.

  • The Game Master
  • Scenario CD-⁠01: The 02:14 Certificate
  • After-Action Report template
  • Set-up guide for Claude and ChatGPT

Free

No card, no email wall

Download the starter pack

Kit

Everything to run a year of drills.

  • All 12 scenarios: reliability, security, continuity
  • Game Master for Claude, ChatGPT and a Claude Skill
  • Team, Solo on-call and Leadership modes
  • Evidence pack: exercise plan, attendance record, report, action tracker
  • Framework mapping guide (SOC 2, ISO 27001, PCI DSS, DORA, NIS2, HIPAA)
  • Facilitator Guide PDF, including a no-AI fallback
  • Free updates to v1.x

$149 one-off

Whole-organisation licence

Kit, $149: on sale shortly

Pro

Drills built around your systems.

  • Everything in the Kit
  • Scenario Forge: your AI interviews you about your architecture and risks, then writes bespoke scenarios in the Calmdrill format
  • Annual Drill Programme: 12-month plan, calendar file, board summary template
  • Leadership briefing cards and a comms template library

$349 one-off

Whole-organisation licence

Pro, $349: on sale shortly

Practitioner

For vCISOs, MSPs and consultancies.

  • Run paid Calmdrill exercises for unlimited clients, with your own branding on the reports
  • Everything in Pro
  • A delivery playbook with three packages, an engagement-letter schedule and a client report cover

$990 one-off

Unlimited client engagements. The Practitioner Guide suggests $1,500 to $3,500 for one client tabletop.

Practitioner, $990: on sale shortly

Not ordering today

Try it first. The drill takes five minutes in your browser and the scorecard takes three. Neither asks for a sign-up.

Secure checkout by Payhip. Pay by card or PayPal. Your files are ready to download as soon as you pay.

White sheet. For everyone. The questions buyers ask.

Questions buyers ask

Which AI do we need?

Any paid plan of Claude (Pro, Max, Team or Enterprise) or ChatGPT (Plus, Pro, Business or Enterprise) works best, because you can use Projects to keep the files together. On free plans, use the single-file versions included in the kit. Other capable models work too.

Is the AI any good at this?

Current models are very good at playing a consistent role when they are given a fixed hidden truth, realistic signals and strict rules, and that is what each scenario provides. We playtest on Claude Sonnet, and on small models to find the floor, and publish the report from one playtest so you can judge for yourself. Use the most capable model on your plan. Small or fast models run the drill but give more away.

Will this get us through our SOC 2, ISO 27001 or PCI audit?

It is designed to help you produce the evidence auditors typically ask for when they check that your incident response or continuity plan has been tested: a plan, a record of who took part, a report and tracked actions. See audit evidence.

Note: Whether it meets a specific requirement is your auditor’s decision. We will never claim it makes you compliant.

What about our data?

The drills run inside your own AI workspace. We never see them. The scenarios are fictional, and the Game Master reminds players not to paste real secrets or customer data. If you re-skin a drill onto your own stack, a few lines of non-sensitive description is all it needs. For company use, we recommend a business or enterprise AI workspace.

Can we run it on our real architecture?

Yes. Tell the Game Master about your product, cloud and key services in a few lines and it re-skins the scenario with your service names, your tools and your numbers, keeping the same underlying failure and learning objectives. Pro adds Scenario Forge, which builds new scenarios from your own architecture and risk register.

How is this licensed?

One purchase covers everyone in your organisation, with unlimited drills. You can’t resell it or use it to deliver paid exercises to clients. For that there is the Practitioner licence, which covers unlimited client engagements with your branding.

Who makes Calmdrill?

Sandpiper Technology, a platform, cloud and operations consultancy that works with organisations where reliability isn’t optional. Calmdrill packages the way we run incident drills into something any team can use without us in the room.

Do you offer invoices, purchase orders or other currencies?

Checkout is run by Payhip, which emails your receipt and adds VAT where it applies. Prices are in US dollars, and your bank converts if needed. If you need a purchase order or a supplier form, email hello@calmdrill.com.