Tools · Risk Storming
Say the risk out loud —
before it says itself.
Risk Storming is a structured session where the whole team independently surfaces risks for a Feature, Problem, or Initiative — each rated by Probability and Impact. Lincah runs it live in the browser: blind submission, simultaneous reveal, a plotted 3×3 grid, and a response plan the team actually leaves with.
Participants join with a display name and a 6-character code — no account required.
Every risk lands somewhere on the grid. The cluster in the corner is the conversation that matters.
Said in the retro, after the incident
Alex · Staff Engineer
Sam · Backend
Riko · QA
Mei · Product
Every one of these risks was known to somebody. None of them reached the team.
Why it exists
Teams enter delivery without ever saying the risks out loud.
When risks emerge mid-execution, teams are caught off-guard, with no agreed response plan — even though, more often than not, somebody on the team already had a feeling something might go wrong.
Risk Storming surfaces risks early and collects the full team's perspective simultaneously, avoiding anchoring on whoever speaks first. It leaves the team with a concrete response plan — not just a list of worries nobody owns.
The session
One reveal, then a plotted grid.
The mechanics protect one moment: nobody sees a risk until every risk is in. Try a round on the panel to the right; it behaves like the real thing.
- 01
Name the target
The facilitator sets a clear, specific context — a Feature, Problem, or Initiative the whole team can picture, not a vague roadmap line.
- 02
Submit blind
Each person independently adds one or more risks — Probability, Impact, a Response Type, and a short plan. Nobody sees anyone else’s yet.
- 03
Time-box it
Submissions stay open for 8–10 minutes. Open-ended brainstorming past that point mostly adds noise, not new risks.
- 04
Reveal together
The facilitator triggers one simultaneous reveal. Every risk appears at once — no anchoring on whoever spoke first.
- 05
Plot & discuss
All risks land on the 3×3 Probability × Impact grid. Clusters — not individual dots — become the conversation.
- 06
Leave with a plan
Every risk keeps its Response Type: Avoid, Mitigate, Transfer, or Accept. The team leaves with a plan, not just a list of worries.
A scripted round — the real one syncs live across every device in the room.
In the room
Three screens. One reveal.
The facilitator sets the context and triggers the reveal, participants submit blind from whatever is in their hand, and the projector shows the grid fill in for the whole room — all in sync, all in real time.

Facilitator
You name the target and hold the reveal.
Set the Feature, Problem, or Initiative, watch submissions land in real time, and trigger the reveal the moment everyone is in.
Participant
They submit blind, from their phone.
A display name and a 6-character code. No account, no install — each risk stays hidden until the facilitator reveals.
Your risks
Hidden from the team until reveal

Broadcaster
The grid, on the wall.
A read-only view built for the projector, so the whole team watches the risks land in the same instant.
The spec
When to run the storm.
- What
- A structured session where the full team independently identifies risks for a Feature, Problem, or Initiative — each rated by Probability and Impact, with a proposed response type and action plan.
- When
- Before sprint kickoff, at the start of a new initiative, during delivery planning for a high-stakes feature, or whenever uncertainty needs a plan before it becomes an incident.
- Who
- The entire delivery team — engineers, designers, QA — with a Scrum Master or Agile Coach facilitating. Product Owners and stakeholders may join for the business-risk view.
- Ratings
- Probability (Low / Medium / High), Impact (Low / Medium / High), and a Response Type — Avoid, Mitigate, Transfer, or Accept.
- Joining
- Participants enter a display name and a 6-character code. No account, no install.
- Plans
- Free and Pro plans available.
Field notes
What makes the plan worth keeping.
The tool runs the mechanics. These four habits are what turn a grid full of dots into a plan the team actually follows.
Set a target you could point at.
"Our Q3 roadmap" is too broad for anyone to assess honestly. "The new payment integration going live in week 6" gives the team something concrete to interrogate.
Time-box submission to 8–10 minutes.
Open-ended brainstorming produces diminishing returns fast — most people surface their real risks in the first few minutes and pad after that.
Root cause before owners, in the Critical zone.
When risks cluster at High Probability × High Impact, resist assigning owners immediately. Two risks that look separate often share a single mitigation.
Don’t skip the Low zone.
Low-probability, low-impact risks are still worth a quick scan. An "Accept" response should be a deliberate choice the team made, not a risk nobody looked at.
Storm it before it strikes.
Free and Pro plans. Your team joins with a display name and a 6-character code — nothing to install, no accounts for participants, and every risk lands with a plan attached.