The first ten minutes of a field incident: what leaders need to know, and why staff accountability breaks down

In a fast-moving field incident, strong leadership means making uncertainty visible, assigning responsibility, and turning each critical gap into an owned action.

Published on
September 8, 2026
Field team leader coordinating colleagues beside a vehicle during the opening minutes of a remote incident

The first ten minutes of a field incident rarely deliver a complete picture. A road collision may first arrive as a missed check-in. Civil unrest may be reported in one neighbourhood while travellers are moving through several others. A medical emergency may be clear in itself but unclear in its wider consequences. The leader’s task is therefore not to wait for certainty. It is to create enough structure for people to act safely while facts are still arriving.

That distinction matters. ISO 22320 treats incident management as a combination of defined roles, responsibilities, tasks, resource management, joint direction, and cooperation.1 The Joint Emergency Services Interoperability Principles make a related point: no single responder can understand every relevant dimension of an emergency immediately, so information has to be gathered and shared to establish situational awareness.2 Both ideas apply well beyond the emergency services. A country director, regional leader, or head of office needs a disciplined way to turn fragmented reports into a controlled response.

The first ten minutes are not a universal deadline, and they should not become another artificial performance target. They are a useful leadership lens. By the end of that opening period, the organisation should be moving towards answers to five connected questions: what has happened, who may be affected, what could happen next, who is directing the response, and which actions are already under way. Where those questions remain unanswered, the gaps should be visible rather than concealed by a confident-looking dashboard or an incomplete roll call.

 

Why does the first report create so much risk?

An initial report is usually a fragment, not a situation. It may be accurate but incomplete, urgent but imprecise, or delayed by the same event it describes. One caller may describe smoke, another an explosion, and a third a blocked road. These accounts may all refer to the same incident without answering the questions a leader needs to decide whether to shelter, evacuate, suspend movement, or seek external assistance.2, 3

This is why a common operating picture should not be mistaken for a single, perfectly verified truth. FEMA defines it as a continuously updated overview that gives participating organisations a common set of incident information and supports decisions.3 The emphasis belongs on “continuously updated”. A useful picture distinguishes confirmed facts from reports, identifies the source and time of each significant update, and makes uncertainty explicit.

The practical failure begins when messages are copied from calls into email, from email into a chat group, and from the chat group into an executive briefing. Context can be lost at each handover. A tentative report can become a fact through repetition. Two updates about the same person can be treated as two different cases. A decision can be announced without its owner, deadline, or rationale. Senior leaders then receive an impressive volume of information but little decision-grade clarity.7

Field teams will use the communication channel that works. The stronger control is one incident record in which significant updates, tasks, communications, decisions, and status changes remain attached to the same event. AtlasNXT’s Incident Room provides that structure without pretending to make uncertain information certain.

 

What does “accounted for” actually mean?

Staff accountability often fails because organisations begin with a binary question: safe or missing? Reality contains more states. A person may be outside the affected area, travelling towards it, unable to respond, sheltering, injured, assisting someone else, or known to a local manager but not yet reflected in the central picture. A device may show a recent location without proving the person’s present condition. Equally, a failure to reply does not prove that the person is in danger.

FEMA’s current National Incident Management System doctrine treats accountability as a discipline supported by check-in and check-out, incident action planning, unity of command, personal responsibility, span of control, and resource tracking.4 For a field organisation, accountability should still answer two separate questions: where is the person thought to be, and what is actually known about their welfare? Neither element should be inferred casually from the other.

Leaders therefore need status categories that preserve the difference between evidence and assumption. “Responded safe” is different from “recent location received”. “Needs assistance” is different from “no response”. “Not expected in the affected area” is different from “location unknown”. These distinctions prevent two dangerous errors: treating a dot on a map as proof of safety, and treating every non-response as a casualty.

AtlasNXT Check-Ins show responses and non-responses, after which an operator follows the organisation’s agreed standard operating procedure. A well-written Check-In asks for an unambiguous action and gives people meaningful ways to report their status. The resulting picture is valuable precisely because it does not pretend that technology has resolved every unknown. It helps the response team decide which unknowns require another message, a call through a manager, a local welfare check, or escalation under the incident plan.

 

Why does the people list fail before the incident has even begun?

An accountability process is only as sound as its starting population. Office lists, travel bookings, vehicle manifests, visitor records, contractor rosters, and programme schedules may all describe different groups. None necessarily answers the incident-specific question: who could reasonably be affected now?

The problem grows across dispersed operations. Someone assigned to one office may be visiting another. A consultant may sit outside the core human-resources directory. A driver may be known by fleet operations but absent from the meeting list. A traveller may have changed route after the original itinerary was approved. ISO 31030 recommends a structured travel-risk approach covering policy, programme development, threat and hazard identification, risk assessment, and prevention and mitigation.5 That structure is important because accountability cannot be improvised from a booking feed when an event is already under way.

The strongest model builds a defensible working population from people formally assigned to the relevant location or journey, recent authorised operational information, and a route for locally reported exceptions. Each source needs an owner and a time, and the population must remain open to revision as evidence changes.

AtlasNXT Remits can define geographic areas of responsibility and the authorised operator views associated with them. This helps a response team focus on the relevant population without granting every operator visibility of everyone. The boundary still requires judgement. An incident near the edge of a Remit may affect routes, suppliers, or staff outside it, so the operator must be able to widen the assessment under the approved procedure.

 

What should a senior leader see?

A leader does not need every message in chronological order. The response team does. The leader needs a concise view that can support direction, resource decisions, and external coordination without stripping away uncertainty.

The opening brief should distinguish confirmed facts from unverified reports and show when the picture was last updated. It should separate people who have responded safe, people needing assistance, people not expected to be affected, and people without a reliable status. It should also identify immediate risks, critical actions and owners, the next decision point, and any material constraint.

This is a leadership control, not merely a communications product. JESIP’s Joint Decision Model starts with gathering information and intelligence, then assessing threats and risks, considering powers, policies, and procedures, identifying options, taking action, and reviewing what happened.2 The sequence reminds leaders that information is useful only when it changes a decision, an action, or an assessment of risk.

The brief should also reveal the quality of the communications picture. ReachScore™ helps expose communication-readiness gaps before and during an event, but it is not a guarantee that a message will arrive or that a person will respond. A country or regional leader can use the score as a prompt for operational questions. Are the people of greatest concern reachable through an appropriate channel? Are selected staff working beyond cellular coverage equipped and configured for compatible satellite communications? Is the organisation relying on one bearer where local conditions require a more resilient plan? Learn more about ReachScore™.

 

Who is directing the response?

Confusion over authority can waste time even when everyone is acting in good faith.1 A local manager may understand the context but lack authority to suspend a programme. A security lead may control the incident process but not the transport resources. A regional director may make strategic decisions while an office team manages the immediate response. Partners and landlords may operate their own procedures at the same location.

ISO 22320’s focus on roles, responsibilities, tasks, and joint direction is a practical warning against relying on an organisational chart alone.1 Incident roles should be explicit. The person directing the response needs a defined mandate, a deputy, access to relevant information, and a clear route to senior decisions. Functional owners need to understand what they are responsible for delivering. Everyone else needs to know where authoritative instructions will appear.

AtlasNXT can support this by keeping tasks, communications, decisions, and status changes with the event in the Incident Room. The platform does not decide who has authority. The organisation’s governance does. Its role is to make that governance visible in the response, so an operator can see who owns an action, a leader can see what remains unresolved, and the next shift can understand why a decision was taken.

 

What changes when cellular coverage is unreliable?

Remote work changes the assumptions behind an office-based plan. The UK Health and Safety Executive’s lone-worker guidance asks whether someone has a safe way to travel, an adequate and reliable means of communication, and a way to call for help.6 A plan that depends on a data connection, a single mobile network, or a staff member having one particular application open may therefore be brittle when contact becomes difficult.

This does not mean every person needs a satellite device. It means communications should follow the risk. The AtlasNXT app can support alerts, Check-Ins, Panic, Overwatch, and location-enabled functions where appropriate. Compatible satellite devices can support selected users beyond cellular coverage, subject to the chosen hardware, airtime, configuration, and operating procedure. The response design should state which groups use which channel, how the organisation detects a delivery or response gap, and what the operator does next.

The distinction between transmission and accountability remains essential. A sent alert is not an acknowledgement, an acknowledgement is not a welfare assessment, and a recent satellite position is not proof that its carrier can move safely.

 

How should the organisation use the first ten minutes?

The opening response should create a disciplined rhythm. The first report is recorded with its source, time, and confidence. The incident lead is identified. The affected geography and initial population are defined. Immediate protective action is issued where the risk justifies it. A targeted Check-In or other contact method asks a clear question. Responses and non-responses are triaged rather than merely counted. Critical actions receive owners and review times. The leader’s brief is updated as the facts change.

This rhythm must remain flexible. An incident involving immediate danger may require protective action before a broad accountability request. A slowly developing political event may begin with movement restrictions and targeted contact with travellers. A severe-weather warning may allow the organisation to test reachability before conditions deteriorate. The method is consistent, but the order and urgency follow the risk.

IFRC’s current Emergency Operations Centres guidance emphasises situational awareness, information management, decision-making, coordination, and scalable, context-appropriate arrangements.7 The principle of scalability is especially useful for international organisations. The same leadership questions can apply to a vehicle incident involving three people, a sudden closure affecting an office, or a regional event affecting several programmes. The tools and staffing expand, while the decision discipline remains recognisable.

 

How do leaders find out whether the plan will work?

Plans are reassuring on paper because paper does not lose signal, misread a status, change a journey, or go off shift. Exercises introduce those conditions before a real incident does. ISO 22398 provides guidance for planning, conducting, and improving exercises, and is intended particularly for leaders and those responsible for organisational competence.8 HSE guidance similarly stresses clearly agreed, recorded, and rehearsed plans, actions, and responsibilities.9

The most useful exercise is not always the largest. A ten-minute accountability drill can reveal whether the on-call lead can define the affected population, whether staff understand the Check-In, whether non-responses reach the right manager, whether a satellite-equipped colleague is actually configured, and whether the executive brief distinguishes fact from inference. The exercise should test the handovers and exceptions, not only the happy path.

Leaders should pay particular attention to what the system could not answer. An incorrect roster, excessive access, a parallel local list, or repeated manual briefing request should become an owned corrective action with a retest date.

 

What does good leadership look like when certainty is impossible?

Good incident leadership does not eliminate uncertainty. It stops uncertainty from becoming confusion. It establishes authority without silencing local knowledge. It asks for enough information to act without demanding an impossible level of completeness. It makes the difference between known, believed, and unknown visible. It treats accountability as a continuing assessment of location and welfare, not a one-off roll call.

The technology should reinforce those habits. Remits can focus geographic responsibility and authorised views. Check-Ins can collect clear responses and expose non-responses. ReachScore™ can surface communications-readiness gaps. The Incident Room can keep the material record of the response together. None removes the need for an exercised procedure, trained operators, reliable local relationships, or senior judgement.

The first ten minutes matter because they establish the pattern for everything that follows. When the organisation creates a trusted working picture, names the decision-maker, distinguishes evidence from assumption, and turns each critical gap into an owned action, leaders can give direction without pretending to know more than they do.

 

References

1. ISO, “ISO 22320:2018 Security and resilience: Emergency management, guidelines for incident management.” https://www.iso.org/standard/67851.html

2. Joint Emergency Services Interoperability Principles, “The Joint Decision Model.” https://www.jesip.org.uk/joint-doctrine/the-joint-decision-model-jdm/

3. US Federal Emergency Management Agency, “ICS Position Training, Foundations Course Reference Guide,” section on the Common Operating Picture. https://training.fema.gov/emiweb/is/icsresource/assets/ics_training_reference_guide.pdf

4. US Federal Emergency Management Agency, “National Incident Management System, Third Edition.” https://training.fema.gov/EMIWeb/IS/IS700b/Handouts/National_Incident_Management%20System_Third%20Edition_October_2017.pdf

5. ISO, “ISO 31030:2021 Travel risk management: Guidance for organizations.” https://www.iso.org/standard/54204.html

6. UK Health and Safety Executive, “Protecting lone workers: How to manage the risks of working alone.” https://www.hse.gov.uk/pubns/indg73.pdf

7. International Federation of Red Cross and Red Crescent Societies, “Emergency Operations Centres Guide 2026.” https://www.ifrc.org/document/ifrc-emergency-operations-centres-guide-2026

8. ISO, “ISO 22398:2013 Societal security: Guidelines for exercises.” https://www.iso.org/standard/50294.html

9. UK Health and Safety Executive, “Emergency procedures.” https://www.hse.gov.uk/workplace-health/emergency-procedures.htm