Incident Postmortem
Incident summary
[Severity and incident window]
Customer impact
[Affected tenants or systems]
Detection and response
[Detection source and time]
Timeline
[Decision and handoff timeline]
Root and contributing factors
[Five-whys evidence]
What went well
[Action owner, due date, and verification]
What failed
[What failed: decision, evidence, owner, constraints, and next action]
Corrective actions
[Corrective actions: decision, evidence, owner, constraints, and next action]
Follow-up review
[Follow-up review: decision, evidence, owner, constraints, and next action]
Measurement and Ownership
| Measure or deliverable | Baseline or input | Target or acceptance condition | Source | Owner | Review date |
|---|---|---|---|---|---|
| [Time to detect] | [Current state] | [Target or acceptance condition] | [System or evidence source] | [Accountable role] | [Date] |
| [Time to acknowledge] | [Current state] | [Target or acceptance condition] | [System or evidence source] | [Accountable role] | [Date] |
| [Time to mitigate] | [Current state] | [Target or acceptance condition] | [System or evidence source] | [Accountable role] | [Date] |
| [Affected requests] | [Current state] | [Target or acceptance condition] | [System or evidence source] | [Accountable role] | [Date] |
| [Error budget consumed] | [Current state] | [Target or acceptance condition] | [System or evidence source] | [Accountable role] | [Date] |
| [Action closure rate] | [Current state] | [Target or acceptance condition] | [System or evidence source] | [Accountable role] | [Date] |