Keep runbooks current: name an owner, review on a risk-based cadence, run them regularly, version every change, review diffs, and fold incident fixes back in.
Require a second reviewer by gating each production command on approval from someone other than the requester, tied to the exact command and recorded for audit.
Turn an incident into a runbook: capture commands and findings as you go, mine shell history, keep what worked, drop dead ends, review, then publish.
An executable runbook is a procedure whose commands run from the document itself, with output streamed under each step and a record of every run.