Evidence
The wire, the kernel, or the KRO intent — whichever plane the fault actually lived on.
How an engagement runs
Lesley Murfin sits at the executive table and with the engineers who own the blast radius. We understand impact to the business, to your services, and to your customers before — and while — the technical work. Commercial terms stay off this site.
01
Business — revenue, burn, risk, diligence. Services — launcher, serve, Cloud, SLOs, MTTR. Customers — conversion, trust, and the ghost pane that aborts the session. We name that impact in the room before the capture.
02
Leadership gets risk, blast radius, options, and a decision in plain language. Same command posture as a national major-incident bridge. Not a status meeting that restates the dashboard.
03
We sit with platform, SRE, network, and product. Captures, dashboards, and CI gates are shared. Your people stay the owners. We do not drop a black box in the corner.
04
Symptom → evidence → root cause → config, code, or architecture → prove-it retest. We stay through verification. There is no recommendations PDF and a wave goodbye.
True SRE
The ladder is the order of the work after impact is named. Packet Analysis is how the path gets proved. The migration console is how a Kubernetes fleet then gets moved, with KRO as the source of truth.
What the customer feels — the session, the API, the agent.
The path, the socket, the fabric.
The host, the cgroup, the process tree.
Config, code, or architecture — and a prove-it retest.
What you leave with
Evidence
The wire, the kernel, or the KRO intent — whichever plane the fault actually lived on.
The change
Config, code, or architecture. For a fleet, a RileyApplication and a runway, not another hand-written sync.
The proof
Expected-Red before the patch, Expected-Green after, and 0→1→0 where processes and sockets must return.
Your team
Still in the room. Complex architectural design — networks, data centers, cloud, applications — is done with them, not around them.