🎁 Get the FREE AI Skills Starter Guide β€” Subscribe β†’
BytesAgainBytesAgain
πŸ¦€ ClawHub

Incident Postmortem Framework

by @1kalin

Generates structured blameless incident postmortems from raw notes, producing summaries, timelines, root cause analyses, impacts, action items, and preventio...

Versionv1.0.0
Downloads855
TERMINAL
clawhub install afrexai-postmortem

πŸ“– About This Skill

Incident Postmortem Generator

Generate blameless incident postmortems from raw notes, Slack threads, or bullet points.

What It Does

Takes messy incident details and produces a structured postmortem document following Google/Atlassian SRE best practices.

Usage

Provide incident details in any format β€” timeline bullets, Slack copy-paste, verbal notes β€” and the agent will produce:

1. Executive Summary β€” What happened, impact, duration, severity 2. Timeline β€” Minute-by-minute from detection to resolution 3. Root Cause Analysis β€” 5 Whys format, no finger-pointing 4. Impact Assessment β€” Users affected, revenue impact, SLA breach 5. Action Items β€” Prioritized fixes with owners and deadlines 6. Lessons Learned β€” What worked, what didn't, what was lucky 7. Prevention Measures β€” Systemic changes to prevent recurrence

Instructions

When the user provides incident details:

1. Ask clarifying questions ONLY if critical info is missing (severity, duration, or resolution are the minimum) 2. Generate the full postmortem in markdown 3. Flag any gaps the team should fill in before publishing 4. Suggest 3-5 specific, actionable prevention measures ranked by effort/impact

Formatting Rules

  • Use ISO timestamps in timeline
  • Bold severity level (SEV1-SEV4)
  • Action items must have: description, owner placeholder, deadline placeholder, priority (P0-P3)
  • Keep language blameless β€” "the deploy process" not "Bob deployed"
  • Severity Guide

  • SEV1: Revenue-impacting, all users affected, >1hr
  • SEV2: Major feature down, >30% users, >30min
  • SEV3: Degraded performance, <30% users
  • SEV4: Minor issue, workaround available
  • Example Input

    prod went down at 2pm, bad deploy, rolled back at 2:45, ~500 users couldn't checkout, lost maybe $12k revenue
    

    Example Output Structure

    # Incident Postmortem: Checkout Service Outage
    Date: 2026-02-22 | Severity: SEV1 | Duration: 45 minutes
    Author: [Team Lead] | Status: Draft

    Executive Summary

    ...

    Pro Tip

    Run this after every incident, even small ones. The pattern recognition across postmortems is where the real value lives. Teams that write postmortems for SEV3+ incidents catch systemic issues 3x faster.


    Need help building incident response processes from scratch? Check out the AfrexAI Context Packs β€” pre-built operational frameworks for SaaS, healthcare, legal, and 7 more industries. Starting at $47.

    πŸ’‘ Examples

    Provide incident details in any format β€” timeline bullets, Slack copy-paste, verbal notes β€” and the agent will produce:

    1. Executive Summary β€” What happened, impact, duration, severity 2. Timeline β€” Minute-by-minute from detection to resolution 3. Root Cause Analysis β€” 5 Whys format, no finger-pointing 4. Impact Assessment β€” Users affected, revenue impact, SLA breach 5. Action Items β€” Prioritized fixes with owners and deadlines 6. Lessons Learned β€” What worked, what didn't, what was lucky 7. Prevention Measures β€” Systemic changes to prevent recurrence