12. Demo playbook (30 minutes)

If you only remember 3 things 1. Rehearse the fallback ladder: live POS → recorded backup → make graph-smoke. A deterministic smoke run that always works beats a flaky live demo that fails. 2. Never demo anything you haven't run that morning on that machine. 3. The 7-minute demo has exactly 5 beats (below) — if you're running late, cut explanation, never cut the FIX click.

Time split (per the rubric)

Minutes Segment Owner
0:00–3:00 Problem statement Speaker 1
3:00–8:00 Architecture Speaker 2
8:00–13:00 Workflow deep-dive Speaker 3
13:00–20:00 Live demo Speaker 4 (driver) + Speaker 5 (narrator)
20:00–23:00 Challenges & lessons Speaker 6
23:00–30:00 Q&A (all) Speaker 7 = designated Q&A anchor; others take their domain

Equal participation (a scored line): every one of the 7 speaks in a prepared segment; during Q&A the anchor routes questions to the domain owner (see 13-qa-bank.md role tags). Nobody "just watches".

Pre-demo checklist (T-minus 60 min)

cd /Users/206163/Documents/GENNAI/IncidentIQ
make backend-test          # expect: 103 passed, 2 skipped
make graph-smoke           # expect: 10 chunks, 7 nodes, fix/demo-001 created
# start backend
cd backend && uv run uvicorn app.main:app --port 8000 &
curl -s localhost:8000/api/health        # expect all-green JSON
# start frontend
cd frontend && npm run dev              # http://localhost:5173
# verify Splunk reachable + LLM key works with ONE seeded error first

Minute-by-minute

13:00–20:00 Live demo (the 7 minutes, beat by beat)

Beat Min Action Expected output Say
1. Trigger 13:00 In POS: login cashier/1234, add Greek Yogurt, click Total (demo checkout error ON) Red error banner; 500 in backend log "A real cashier just hit a production error. From here, everything is automated until a human decides."
2. Pipeline runs 14:00 Switch to terminal: curl -s localhost:8000/api/pipeline/status; then Incidents tab Status polling→processing_errors; incident appears with RCA within ~30–60s "Splunk → poller → parallel retrieval+RAG → RCA → recommendation. The graph is paused now — waiting for a human."
3. Review 15:30 Open the incident: RCA, evidence IDs, similar docs, recommendation Structured RCA card "Note the evidence IDs — every claim is tied to supplied logs and docs, and the model was told historical similarity is not proof."
4. Approve 17:00 Click FIX Fix card: branch name, commit SHA, diff, push_status "One click = Command(resume). The router checked confidence ≥ 0.5 and severity before allowing automation. The diff is on a branch — main is untouched."
5. Verify + metrics 18:30 curl -s localhost:8000/api/metrics; show branch (GitHub or git -C data/sample_app branch -a) Counters moved; branch exists "Counters for the full path: processed, rca_success, approval_approved, fix_created. And here's the branch."

Timing buffer: beats 1–4 take ~4 min if healthy; the 3-minute buffer absorbs poller latency. If you're at 18:00 without the RCA, jump to fallback now.

Fallback ladder (decide fast, never debug live)

Failure Symptom Fallback
Splunk down / no event No incident after 2 min Don't wait. Narrate beat 1–2 from the pre-recorded video (have it), then run make graph-smoke live in terminal: "same graph, deterministic inputs, zero external dependencies — watch the 7 nodes and the fix branch."
LLM API fails Incident stuck before RCA Show the recorded full run; then show rca_failed counter + poller retry in /api/metrics: "this is the robustness story — the event isn't marked processed, it retries."
Network/push fails push_status: "local" This is designed behavior — say: "push failed, the branch is local, nothing lost; the tool falls back by design."
Dashboard broken UI error Drive everything via curl (the API is the system; the UI is a view).
Everything fails — make graph-smoke + the test suite (make backend-test, 103 green) + this handbook. The system's correctness doesn't depend on the live demo working.

Golden rule: an evaluator forgives a network outage; they don't forgive 4 minutes of silent debugging. Announce the fallback, execute it, move on.

20:00–23:00 Challenges (Speaker 6)

Use 14-challenges-lessons.md — pick 3: (1) the Splunk schema mismatch (commit 3213f66), (2) the recommend persistence gap (commit bda6c87), (3) the guardrail-vs-router test collision (commit 098a6df). Each: what broke → how found → the fix → the lesson.

Q&A 23:00–30:00

Anchor routes by domain (roles in 13-qa-bank.md). If nobody knows: "Good question — the code is the source of truth; [role] will follow up with the exact line." Never bluff.