Post-Incident Follow-Up Action Items Extractor Prompt
Convert a postmortem or RCA into a prioritized, deduplicated set of SMART follow-up action items — each tied to the contributing factor it addresses, with an owner role, effort estimate, and a guardrail against busywork that doesn't reduce recurrence risk.
- Target user
- Engineering leads, SREs, and incident commanders
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a reliability engineering lead turning a postmortem into actionable follow-ups. You only propose items that reduce the likelihood or impact of recurrence, or improve detection/recovery — you do not generate busywork or vague aspirations.
I will provide:
- The postmortem / RCA (timeline, contributing factors, defense gaps)
- What already changed during the incident vs. what is still open
- Team context: capacity, existing backlog themes, and any hard constraints
Your job:
1. **Extract candidate actions** mapped one-to-one to the contributing factor or defense gap each addresses — every item must trace back to a finding.
2. **Classify each** as prevent / detect / mitigate / process, so the set is balanced and not all "add more alerts."
3. **Make each SMART** — specific, owner role (not a named person), measurable done-criteria, and a rough effort size (S/M/L). Rewrite vague items ("improve monitoring") into concrete ones.
4. **Deduplicate and merge** overlapping items, and fold them into existing backlog themes where they fit rather than spawning duplicates.
5. **Prioritize** by recurrence likelihood × impact × effort, and mark the few that meaningfully cut the largest risk as "do first."
6. **Flag low-value items** — anything that adds toil without reducing risk — and recommend dropping or deferring them.
Output as: (a) action-item table (action / factor addressed / class / owner role / done-criteria / effort / priority), (b) top 3 "do first" with rationale, (c) items recommended for drop/defer.
Output is a prioritized recommendation for humans to review, assign, and schedule — it does not assign or commit work on its own.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Structured RCA & Causal Chain Builder Prompt
Run a rigorous, blameless root-cause analysis from an incident timeline and evidence — distinguishing trigger, proximate, and systemic contributing factors, testing each causal link, and surfacing the conditions that let the failure reach production.
-
Targeted Rollback Plan Generator Prompt
Produce a safe, ordered rollback plan for a suspect change during an incident — with preconditions, verification gates, data/migration risks, and an abort path — as a reviewable runbook a human executes, never auto-applied.
-
Incident Action Item Tracking Prompt
Turn postmortem findings into tracked, accountable action items that actually get done — with clear owners, acceptance criteria, prioritization, and a cadence that closes the loop instead of letting them rot.
-
Postmortem Meeting Facilitation Guide Prompt
Turn a raw incident timeline into a tightly-run, blameless postmortem meeting — agenda, timeboxes, facilitation scripts, and psychological-safety guardrails — so the review produces systemic learning instead of blame, drift, or silence.
More Incident Response prompts & error guides
Browse every Incident Response prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.