<!--
Blameless postmortem template — Pingvera
Source and full guide: https://pingvera.com/blog/blameless-postmortem-web-agency.html

How to use: copy this file into your incident folder and fill the bracketed
fields. Keep the timeline evidence-based — timestamps from your monitoring
history, not memory. A section you cannot answer honestly is a finding in
itself. Free to use and adapt, attribution appreciated.
-->

# Blameless postmortem

Incident ID: [ID]
Service/client: [value]
Date: [UTC]
Facilitator: [role]
Document owner: [role]
Participants: [roles]

## 1. Summary
[What happened and how service recovered.]

## 2. Impact
- Affected journeys/users/regions:
- Impact window:
- Data/integrity/security impact:
- Measurement limitations:

## 3. Detection
- First evidence:
- Alert/notification:
- Incident declaration:
- What monitoring missed or detected well:

## 4. Timeline
| UTC | Fact, decision, action, or communication | Evidence |
|---|---|---|
| [time] | [value] | [link] |

## 5. Trigger and failure mechanism
Trigger: [initiating event]
Failure mechanism: [how impact was produced]

## 6. Contributing conditions
- Technical:
- Process:
- Ownership/communication:
- Testing/monitoring:
- Workload/timing/provider:

## 7. What helped
- [control, person, fallback, tool, or decision]

## 8. What made response harder
- [condition and evidence]

## 9. Decision review
- Which decisions were reasonable with information available?
- Which information arrived too late?
- Which authority or runbook was unclear?

## 10. Actions
| Action | Prevent/Detect/Mitigate/Recover | Owner | Due | Verification | Priority |
|---|---|---|---|---|---|
| [value] | [type] | [role] | [date] | [test/evidence] | [value] |

## 11. Learning to share
[Audience, redactions, and concise lesson.]

## 12. Action review
Next review: [date]
Close condition: [all critical actions verified / accepted risk]
