Skip to main content

Postmortem: [short incident title]

FieldValue
DateYYYY-MM-DD
SeverityCritical / High / Medium / Low
Start and end (UTC)HH:MM–HH:MM
User impact[measured impact]
Incident lead[owner]
StatusDraft / Reviewed / Closed

Summary​

[Two or three sentences: what users experienced, the first failing boundary, and how service was restored.]

Impact​

  • Users/accounts affected:
  • Requests/jobs affected:
  • Data loss or privacy impact:
  • Revenue/support impact:
  • How impact was measured:

Detection​

  • First signal and timestamp:
  • Who/what detected it:
  • Why existing alerts did or did not detect it earlier:

Timeline (UTC)​

TimeObserved fact or action
HH:MMFirst confirmed impact
HH:MMIncident declared
HH:MMMitigation started
HH:MMService restored
HH:MMVerification completed

Technical cause​

Describe the causal chain using revisions, job/request IDs, configuration changes, and logs. Mark uncertain statements as hypotheses.

Contributing conditions​

  • Which guard, test, alert, rollout control, or documentation gap allowed the incident to occur or last longer?
  • Which dependencies or operational assumptions mattered?

Response review​

What helped​

  • [specific detection, tool, or decision]

What slowed recovery​

  • [specific missing signal, unsafe manual step, or ownership ambiguity]

Corrective actions​

PriorityActionOwnerDueCompletion evidenceStatus
P0[immediate prevention]@ownerYYYY-MM-DD[test/alert/release]Open
P1[systemic improvement]@ownerYYYY-MM-DD[test/alert/release]Open

β€œImprove monitoring” and β€œbe more careful” are not complete actions. Name the specific detector, invariant, test, or rollout change.

Verification and closure​

  • Fix deployed to the intended project and region.
  • Regression test or rule test added.
  • Unauthorized/negative path retested where relevant.
  • Monitoring and runbook updated.
  • Action items have owners and tracked evidence.
  • Customer or internal communication completed.

Evidence​

Link internal dashboards/tickets by stable identifier. Never include raw tokens, passwords, API keys, session cookies, signed URLs, or private user content.