skrümGitHubGet started

Templates · Analysis

Post-mortem

A review after an incident, covering what held, what was missing, what each person learned and what will catch the same failure earlier.

  • What we liked What held up under pressure and should stay
  • What we missed Gaps the incident exposed: alerts, docs, access
  • What I learned What each person now knows that they did not before
  • For next time Follow-ups with an owner so the same failure is caught earlier
  • Appreciations Credit for people who carried the incident

What it is

A post-mortem looks back at one event, usually an incident: an outage, a failed release, a deadline badly missed. Its five columns separate what held up, what was missing, what people learned, what will be done about it, and who deserves thanks.

Goal

Follow-ups, each with an owner, that make the same failure less likely or caught sooner. And a team that has said openly what happened, without anyone being put on trial.

When to use it

  • Soon after the incident is closed, while memories are fresh.
  • With everyone who took part in the response.
  • Once the timeline is written down. The facts come first; the board is for what they mean.

When to pick another format

If the team does not yet know why it happened, the columns fill with guesses: look for the cause first with Fishbone Analysis. For an ordinary sprint in which nothing broke, this format is heavier than needed; Original 4 keeps the question about learning. To look for failures before they happen, run a Pre-mortem.

How to run it

Open by saying that the session is about the system, not about who made a mistake: people acted on what they knew at the time. Read the timeline together, then:

  1. What we liked: what held up under pressure? An alert that fired, a runbook that was right, a decision taken fast.
  2. What we missed: what did the incident show to be absent? Alerts, documentation, access, someone who knew.
  3. What I learned: what do you know now that you did not know before?
  4. For next time: what would make us catch this earlier, or limit the damage? Write each card as a follow-up someone could own.
  5. Appreciations: who carried the incident? Name the person and what they did.

Discuss What we missed and For next time side by side: each gap should meet a follow-up, or a stated decision to live with it. Turn the follow-ups the team keeps into actions, each with an owner. Close by reading the appreciations aloud.

Columns

ColumnDescription
What we likedWhat held up under pressure and should stay
What we missedGaps the incident exposed: alerts, docs, access
What I learnedWhat each person now knows that they did not before
For next timeFollow-ups with an owner so the same failure is caught earlier
AppreciationsCredit for people who carried the incident

To start a retrospective from this template, see Create a retro.