Skill

Incident Postmortem

Draft a blameless postmortem from an incident timeline and impact summary in minutes.

Goal

Generate a complete, blameless postmortem document including timeline, root cause analysis, impact assessment, and actionable follow-up items from a raw incident report.

Trigger

Invoke after an incident has been resolved and a timeline with impact notes has been collected.

Steps

  1. 1

    Analyze the incident report below and extract key facts: incident title, start/end times, affected systems, and a structured timeline of events. $incident_report

    • Incident start and end timestamps are identified
    • Affected systems or services are listed
    • At least 3 timeline events are extracted
    Incident Report:
    
    $incident_report
  2. 2

    Identify the root cause(s) using a blameless lens. Focus on systemic failures, process gaps, or environmental conditions — not individual errors. Distinguish between root causes and contributing factors.

    • Root cause is systemic, not person-specific
    • Contributing factors are separated from root cause
  3. 3

    Quantify the impact: describe user-facing symptoms, estimate the number of users or systems affected, duration of degradation, and any data loss or SLA breaches.

    • Impact duration is stated in minutes or hours
    • Affected user or system scope is estimated
    • SLA breach or data loss is noted if applicable
  4. 4

    Draft the Detection and Response section: describe how the incident was detected (alert, user report, etc.), who responded, and evaluate whether detection was timely or could be improved.

    • Detection method is clearly stated
    • Response timeline is summarized
    • Detection gap or improvement opportunity is noted
  5. 5

    Generate a prioritized list of action items to prevent recurrence. Each item should include a description, suggested owner role (not a named individual), and a recommended priority (P1/P2/P3).

    • Each action item maps to a root cause or contributing factor
    • Owner roles are generic (e.g., 'On-call engineer'), not named people
    • Priority level is assigned to each item
  6. 6

    Assemble the full postmortem document in a clean, structured format. Use a professional but accessible tone. Ensure no language assigns personal blame — reframe any blame-implying phrases to systemic observations.

    • All sections are present: Summary, Timeline, Root Cause, Impact, Detection & Response, Action Items
    • No blame-assigning language is used
    • Document reads as a complete, shareable artifact

Output format

Produce a structured postmortem document with clearly labeled sections: (1) Incident Summary, (2) Timeline, (3) Root Cause & Contributing Factors, (4) Impact, (5) Detection & Response, (6) Action Items table with columns for Description, Owner Role, and Priority. Use plain prose under each section. Keep the tone factual, blameless, and concise.

Use it everywhere

Copy this skill into your library to inject it into Claude, ChatGPT, and Gemini — or install your whole library as /korvai: commands in Claude Code.

Get started free →