Postmortem Counterfactual Analysis Prompt
Rigorously explore what would have detected or prevented this incident sooner — testing each counterfactual against what was actually knowable in the moment, so you avoid hindsight-driven action items.
- Target user
- SRE / incident commander deriving prevention and detection improvements
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT, Cursor
The prompt
You are a staff SRE trained in counterfactual reasoning for post-incident reviews. You know the trap: hindsight makes every cause look obvious, so "we should have noticed" is usually a story, not a finding. You test each counterfactual against the information available at the time. I will paste: [INCIDENT TIMELINE: with timestamps for detection, mitigation, resolution] [WHAT WAS KNOWN WHEN: signals, dashboards, and alerts that existed and what they showed during the event] [CONSTRAINTS: tooling, access, on-call load, and time pressure responders were under] Do the following: 1. Build a "detect sooner" counterfactual set: list candidate signals, alerts, or checks that could have surfaced the problem earlier. For each, evaluate whether the data to fire it actually existed at the time. 2. Build a "prevent entirely" counterfactual set: changes upstream (design, guardrail, test, review gate) that would have stopped the trigger. Assess feasibility and cost honestly. 3. Apply the counterfactual test to each item: could a reasonable responder, with the information and tools available in the moment, realistically have known or done this? Discard or downgrade hindsight-only items and say why. 4. Rank surviving counterfactuals by leverage: how much earlier detection or how much prevention per unit of effort. Note which add prevent vs detect vs mitigate defense. 5. Flag any counterfactual that trades one risk for another (e.g. a tighter alert that would page constantly). Output format: two tables (Detect-sooner / Prevent), each with columns Counterfactual / Was-it-knowable-then / Feasibility / Leverage, then a short ranked shortlist of the strongest candidates. Guardrails: stay blameless — frame everything as system and signal gaps, never "the engineer should have seen it." Mark any assumption about what was knowable as [UNVERIFIED] until I confirm it. These are candidate improvements; I own the decision on what becomes an action item.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Why this prompt works
Counterfactual reasoning is the engine of a useful postmortem, but it is also where hindsight bias does the most damage. After the fact, every contributing factor looks like it was waving a flag, and “we should have caught this” feels self-evident. It usually is not. The signal may not have existed, the dashboard may not have shown it, or the responder may have been drowning in pages. Treating those stories as findings produces action items that punish the past instead of improving the future.
This prompt builds counterfactuals in two directions — detect sooner and prevent entirely — and then subjects each to an explicit knowability test: with the information and tools present in the moment, could a reasonable person actually have acted on it? Items that survive are real opportunities; items that fail are downgraded with a stated reason. That discipline is exactly what separates a mature review from a blame exercise dressed in process language.
Ranking by leverage keeps the output actionable rather than a wish list, and flagging counterfactuals that trade one risk for another (the alert that would page constantly, the gate that would block every deploy) prevents the classic overcorrection. Throughout, the framing stays on signals and systems, and the final call on what becomes an action item stays with the human.
Related prompts
-
Postmortem What-Went-Well Section Writer Prompt
Write a genuine 'what went well / strengths' section that captures the defenses and good calls that contained the incident — so the postmortem reinforces what to keep, not only what to fix.
-
Postmortem Detection-Gap Analyzer Prompt
Walk the incident timeline to measure exactly where detection failed — time-to-detect, the signals that should have fired, and the cheapest alert that would have shrunk the gap.
-
Postmortem Assumptions and Unknowns Extractor Prompt
Read a postmortem draft and surface every unstated assumption and open unknown that is being treated as settled fact, so the root-cause analysis and action items don't quietly rest on unverified claims.
-
Postmortem to Game-Day Scenario Generator Prompt
Convert a real incident postmortem into a runnable game-day or chaos-engineering exercise so you can prove the fixes actually work under realistic failure conditions instead of assuming they do.
More Post Mortems with AI prompts & error guides
Browse every Post Mortems with AI prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.