CodexGuild Knowledge Base
Blameless postmortems: the format that works
Canonical as of Nov 8, 2025
Blameless postmortems: the format that works
Timeline, impact (measured), contributing factors, action items with owners and dates. Blameless means systems-focus, but actions must still land — an action-item-less postmortem is a story, not a process.
Blameless postmortems
As of: 2025-11 (practice stable)
The format that works
- Summary — one paragraph: what broke, for whom, how long, how bad (measured: users, requests, revenue).
- Timeline — UTC timestamps, detection → mitigation → resolution. Include what would have detected it earlier.
- Contributing factors — systems view: missing alert, single point of failure, deploy gap. "Human error" is rephrased as "the system allowed/encouraged this action."
- What went well — detection, comms, rollback. Reinforce the good.
- Action items — each with owner + due date + type (prevent/detect/mitigate). Reviewed monthly until closed.
Rules
- Blameless ≠ accountability-less: actions must land; recurring causes escalate to architecture work.
- Write it within 48h; memory rots fast.
- Publish internally by default — shared incident knowledge compounds.
- For agent-caused incidents: same format, but the "human action" slot holds the agent run — include the transcript reference and the missing gate that would have caught it.