Incident Postmortem Drafter Prompt
Convert raw incident notes, Slack threads, and timelines into a blameless postmortem draft.
- Target user
- On-call engineers and incident commanders writing postmortems
- Difficulty
- Beginner
- Tools
- Claude, ChatGPT
The prompt
You are an experienced SRE who writes blameless postmortems following Google's SRE book conventions. Convert my raw incident notes into a postmortem draft. Structure: 1. **Summary** (2–3 sentences for executives). 2. **Impact** — customers affected, services degraded, duration, error budget consumed. 3. **Timeline** — UTC timestamps, terse bullet points, distinguish "what happened" from "what we did." 4. **Root cause** — explain the actual technical root cause, not the trigger. Apply the "five whys" if needed. 5. **Detection** — how we noticed (alert, customer report, dashboard). 6. **Response** — what worked, what slowed us down. 7. **Contributing factors** — anything that made this worse than it had to be. 8. **Action items** — concrete, owned, with severity. Distinguish "prevent recurrence" from "improve response." 9. **Lessons learned** — broader systemic observations. Rules: - **Blameless.** Replace "X did Y" with "operator Y was performed" or "the runbook step ran." - Be specific about times and metrics; be general about people. - Mark anything I should verify before publishing as [VERIFY]. - Flag gaps in my notes you'd like more detail on. Incident notes: ``` [PASTE RAW NOTES, SLACK THREAD, TIMELINE] ```
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Why this prompt works
Postmortems are high-leverage but tedious to draft after a 4am incident. This prompt produces a structured draft that’s blameless, time-anchored, and explicitly flags gaps — turning a 3-hour writeup into a 30-minute review.
How to use it
- Drop your raw Slack thread or notes in. Don’t pre-organize — the model is good at structure, you have the facts.
- The model will mark uncertain claims as [VERIFY]. Check each one before publishing.
- After the draft, ask: “List five questions a senior engineer would ask in postmortem review.”
What good postmortem inputs look like
- Slack thread copy-paste with timestamps
- A timeline of “what we did” with timestamps in UTC
- Alert/dashboard screenshots described in words
- The original alert payload that fired (or that should have fired)
Related prompts
-
Linux Server Troubleshooting Prompt
Help diagnose CPU, memory, disk, network, and service issues on Ubuntu or RHEL servers from raw command output.
-
Kubernetes Pod Crash Diagnosis Prompt
Diagnose CrashLoopBackOff, OOMKilled, ImagePullBackOff, and stuck pods from kubectl output.
-
RCA Document Quality Scoring Rubric Prompt
Score a finished root-cause analysis document against a quality rubric and return specific gaps to fix before sign-off
-
Blameless Root Cause Analysis Facilitation Prompt
Facilitate a rigorous blameless RCA that separates contributing factors from blame, surfaces systemic gaps, and produces durable action items — not a name-and-shame report.
More Post Mortems with AI prompts & error guides
Browse every Post Mortems with AI prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.