Skill

Incident Postmortem

Draft a blameless postmortem from an incident timeline and impact summary, following SRE best practices.

Goal

Produce a structured, blameless postmortem document that captures what happened, why it happened, and how to prevent recurrence.

Trigger

Invoke after an incident has been resolved and a rough timeline and impact summary are available.

Steps

  1. 1

    Analyze the incident report below and extract key facts: timeline of events, services affected, duration, and customer impact. $incident_report

    • Timeline is clearly identified with timestamps
    • Affected services and scope are noted
    • Customer-facing impact is quantified where possible
    Analyze the incident report below and extract key facts: timeline of events, services affected, duration, and customer impact.
    
    $incident_report
  2. 2

    Identify the root cause and all contributing factors using a systems-thinking lens. Avoid assigning blame to individuals — focus on process gaps, tooling failures, and environmental conditions.

    • Root cause is a systemic finding, not a person
    • Contributing factors are listed separately from root cause
  3. 3

    Describe the detection and response sequence: how the incident was detected, who was involved in mitigation, what actions were taken, and what resolved it.

    • Detection method is clearly stated (alert, customer report, etc.)
    • Mitigation steps are in chronological order
  4. 4

    Assess the impact in measurable terms: error rates, downtime duration, number of users affected, SLA/SLO breaches, and any financial or reputational consequences.

    • Impact is quantified with numbers where possible
    • SLO or SLA breach status is explicitly noted
  5. 5

    Generate a prioritized action items list with concrete follow-ups: preventive fixes, monitoring improvements, runbook updates, and process changes. Each item should include an owner role and suggested priority (P1/P2/P3).

    • Each action item has a clear outcome, not just a vague task
    • Items are tagged with a priority level
    • At least one item addresses detection speed
  6. 6

    Assemble the full postmortem document in a clean, professional structure with all sections: Summary, Timeline, Root Cause & Contributing Factors, Impact, Detection & Response, Lessons Learned, and Action Items.

    • Tone is blameless and objective throughout
    • All six sections are present and populated
    • Document is ready to share with stakeholders

Output format

Produce a structured postmortem document with clearly labeled sections: (1) Incident Summary — one-paragraph overview; (2) Timeline — bulleted chronological events with timestamps; (3) Root Cause & Contributing Factors — numbered list; (4) Impact — quantified metrics; (5) Detection & Response — narrative paragraph; (6) Lessons Learned — 3–5 bullet points; (7) Action Items — table with columns: Item, Owner Role, Priority.

Use it everywhere

Copy this skill into your library to inject it into Claude, ChatGPT, and Gemini — or install your whole library as / slash commands in Claude Code and Cowork.

Get started free →