A runbook tells you which buttons to press, and works until the incident is not the one it was written for, which is most of them. These are written the other way round: the decision first, the commands second. Severity classification at the top rather than in an appendix, evidence preservation before investigation, because the order matters and getting it wrong is not recoverable.
End-to-end response for a named incident type: what to do in the first hour, what evidence to preserve, who to tell, and how to close it out.
The decision at the front of the queue. What the alert means, what to check first, and the criteria for escalating or closing.
The processes that hold the function together between incidents: evidence handling, on-call, reporting, tooling and review.
Hypothesis-driven hunts with the queries, the data they need, and what a finding looks like when you get one.