Skip to content
🎉 Launch sale:50% off everything over $22 — automatically applied at checkout· ends Aug 2Shop the sale →
DevOps AI ToolKit
Newsletter
All guides
Post Mortems with AI By James Joyner IV · · 9 min read

Running a Postmortem Review Meeting: Agenda and Facilitation

The postmortem doc is the easy part. Running the review meeting where the team actually learns is harder. Here's a timed agenda and facilitation playbook.

  • #postmortems
  • #sre
  • #reliability
  • #incident-response
  • #facilitation

You can write a flawless postmortem document and still waste the incident if the review meeting goes badly. The meeting is where a group reconstructs what happened, tests the analysis, and commits to fixes together — or where a defensive engineer, a searching-for-blame room, and a rushed agenda turn an hour into damage. This guide is a timed agenda and a facilitation playbook for running the meeting that makes the document worth writing.

First, decide if you even need the meeting

Not every incident earns a synchronous review. A small, well-understood SEV-3 with an obvious fix can be handled in the doc and a quick async review. Reserve the meeting for incidents that were severe, surprising, or crossed team boundaries — the ones where people genuinely disagree about what happened or what to do. Meeting for every trivial incident trains people to tune out.

The prep that makes or breaks it

A review with no prep becomes an hour of people trying to remember what happened. Do the work first:

  • Assemble the timeline in advance. Pull the incident channel, deploy log, and alerts into a chronological narrative before the meeting. The review examines the timeline; it doesn’t reconstruct it live.
  • Circulate the draft 24 hours ahead. Participants read the timeline and draft analysis before walking in. The meeting is for discussion, not reading aloud.
  • Invite the right people, not everyone. Responders, the service owner, and someone from any adjacent team the incident touched. Not a spectator gallery — a room where everyone can contribute or learn.
  • Pick a neutral facilitator. Not the person who led the incident. They’re too close; they’ll re-litigate their own decisions. The facilitator runs the process; they don’t need the answers.

A timed agenda (60 minutes)

Keep it structured so the conversation doesn’t drift into war stories or blame. Here’s an agenda you can paste into the invite.

## Postmortem review — INC-XXXX (60 min)

00:00 (2m)  Facilitator frames the meeting: blameless, learning-focused.
00:02 (8m)  Author walks the summary + impact. Clarifying questions only.
00:10 (15m) Walk the timeline. Fill gaps, correct times, note surprises.
00:25 (15m) Root cause / contributing factors discussion.
00:40 (10m) Review and sharpen action items: owner, type, due date each.
00:50 (5m)  What went well + where we got lucky.
00:55 (5m)  Confirm owners, next steps, who finalizes the doc.

Two design notes. First, “what went well” comes near the end on purpose — by then the room has processed the failures and is ready to be honest about what saved them, rather than rushing past it. Second, the largest blocks are timeline and root cause, because that’s where disagreement lives and where the learning happens.

Facilitation moves that keep it honest

State the blameless frame out loud. Don’t assume it. Open with something like: “We’re here to understand how the system let a reasonable action cause harm, not to find who to blame. Assume everyone did their best with what they knew.” Saying it changes the room.

Redirect blame in real time. When someone says “if Sam had just checked the dashboard,” reframe it: “So the dashboard existed but wasn’t part of the on-call’s normal flow — why not?” You’re not protecting Sam’s feelings; you’re getting to the systemic finding that a name obscures.

Protect the quiet responder. The person who made the change under scrutiny will go quiet or defensive. Draw them out gently — they hold the most context. “You were closest to this. What did it look like from where you sat?” gets better data than any interrogation.

Manage the loud room. Senior voices and executives can steamroll a retro. Your job is to make space for the people who were actually there. “Let’s hear from the on-call before we go to solutions” is a legitimate facilitator move.

Timebox the rabbit holes. When two people are deep in a debate that three others can’t follow, park it: “Good thread — let’s take it offline and keep moving.” The agenda is your friend here.

Convert vagueness to action items on the spot. When someone says “we should really fix the alerting,” stop and capture it: “Great — who owns that, and what specifically? Add an alert on what?” Don’t let good ideas evaporate.

Common mistakes

  • The responder facilitates their own review. Guaranteed defensiveness. Use a neutral facilitator.
  • No prep, so the hour is spent rebuilding the timeline. Do that before the meeting.
  • Jumping to solutions before understanding. Fixes proposed before the room agrees on what happened tend to solve the wrong problem.
  • Ending with no named owners. If people leave without knowing who does what by when, the meeting produced talk, not change.
  • Skipping the finalize step. Decide in the room who updates the doc and by when, or it stays a draft forever.

Wrapping up

The document is the artifact; the review meeting is the learning. Prep the timeline, circulate the draft, invite the right people, and give the room a neutral facilitator working a timed agenda. State the blameless frame out loud, redirect blame to systems in real time, and leave with every action item owned and dated. Do that and the meeting earns its calendar hour — and the next incident gets a little less likely.

Newsletter

Free: the DevOps AI Incident-Triage Cheat Sheet

Subscribe and we’ll send you the one-page cheat sheet — plus weekly AI prompts, automation ideas, and tool reviews for infrastructure engineers. One email a week. No spam, unsubscribe anytime.

  • AI Incident-Triage Cheat Sheet (PDF)
  • Access to 2,778 DevOps AI prompts
  • One practical workflow email per week
Free download · 368-page PDF

Get 500 Battle-Tested DevOps AI Prompts — Free

500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.

  • 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
  • Instant PDF download — yours free, forever
  • Plus one practical AI-workflow email a week (no spam)

Single opt-in · unsubscribe anytime · no spam.