Free download

The blameless postmortem template

Nine sections that help a team learn from a bad day without looking for someone to blame. Because it could be any of us.

Open a section to see hints and an example.

  1. What happened, in three sentences a new hire would understand.

    Hints

    • Who, what, how long, how it was fixed.
    • Three sentences.
    • No jargon.

    Example

    Acme Shop, checkout down for 47 min (made up)

    On 12 March, checkout failed for 47 minutes because the certificate on our payments API expired. We renewed it by hand and checkout came back.

  2. Who was affected, for how long, and how they found out.

    Hints

    • Use numbers you can check.
    • Say how users found out.

    Example

    Acme Shop, checkout down for 47 min (made up)

    About 1,900 checkout attempts failed between 09:12 and 09:59 UTC. Customers saw 'Payment failed'. Support received 64 tickets.

  3. Times in UTC. What we saw, what we thought, what we did.

    Hints

    • UTC times.
    • What we saw, thought and did.
    • Include wrong guesses.

    Example

    Acme Shop, checkout down for 47 min (made up)

    09:12 first errors · 09:20 alert fires · 09:24 we suspect the database (wrong) · 09:31 on-call finds the expired certificate · 09:52 new certificate deployed · 09:59 errors stop.

  4. Start here. Something always did.

    Hints

    • Start here.
    • Name tools and habits, not heroes.

    Example

    Acme Shop, checkout down for 47 min (made up)

    The alert fired within 8 minutes. Support updated the status page in 10 minutes.

  5. Missing alerts, confusing dashboards, tired people at 3 a.m.

    Hints

    • Confusing signals, missing docs, tiredness.

    Example

    Acme Shop, checkout down for 47 min (made up)

    The error said 'connection reset', not 'certificate expired'. The renewal runbook was out of date.

  6. Conditions, not culprits. No names, no “human error”.

    Hints

    • Conditions, not culprits.
    • Usually more than one.

    Example

    Acme Shop, checkout down for 47 min (made up)

    Auto-renewal broke when we changed DNS providers in January. Nothing checked certificate expiry dates.

  7. Ask "why" five times, starting from the impact. Ask why the system allowed it, never why a person did it.

    Hints

    • Start from what users felt, not from the bug.
    • Each answer should be a fact you can check.
    • If an answer names a person, ask why the system let it happen.
    • Stop when you reach something you can fix. Two chains are fine.

    Example

    Acme Shop, checkout down for 47 min (made up)

    1. Why did checkout fail? The payments API refused connections.
    2. Why? Its TLS certificate had expired.
    3. Why didn't it renew? Auto-renewal broke when we moved DNS providers in January.
    4. Why didn't we notice? Renewal errors went to a log nobody reads.
    5. Why? The renewal job never had an alert. → Fix: alert on renewal errors and on certificates expiring within 14 days.
  8. Each with an owner and a date. Small and real beats big and vague.

    Hints

    • Owner (a team) and a date for each.
    • Small and real beats big and vague.

    Example

    Acme Shop, checkout down for 47 min (made up)

    Alert when any certificate expires within 14 days (Platform team, 26 March). Send renewal errors to on-call (Payments team, 19 March).

  9. Name the help, not the mistakes.

    Hints

    • Name the help, not the mistakes.

    Example

    Acme Shop, checkout down for 47 min (made up)

    Thanks to Support for the fast status update, and to the on-call engineer who joined from a train.

Download .md