Template Library
Blameless Postmortem Template
An Excel workbook for blameless postmortems: an incident summary that calculates response times and error budget use, a timeline, contributing factors, and tracked action items.
The Incident Summary tab holds the description and five timestamps, and it calculates time to detect, acknowledge, mitigate, and total duration in minutes. Enter your SLO and period and it calculates the error budget and how much of it the incident consumed. The Timeline tab is an Excel Table for the sequence of events, and the Contributing Factors tab records several factors by category with evidence.
The Action Items tab tracks each action's type (prevent, detect, mitigate, or learn), owner, due date, and status, with a Days Overdue formula. An example 90-minute checkout outage is included so you can see the formulas working before you replace it.
What Is Included in the Workbook
| Sheet | Purpose | What Teams Capture |
|---|---|---|
| How-To | Guidance and disclaimer | Steps, notes, and what blameless means |
| Incident Summary | Summary and response times | Description, severity, timestamps; time to detect, acknowledge, mitigate, total duration, and error budget consumed |
| Timeline | Event sequence (Excel Table) | Time, event, source, notes |
| Contributing Factors | Factors by category (Excel Table) | Factor, category, evidence, and what would have prevented or detected it |
| Action Items | Tracked actions (Excel Table) | Action, type, linked factor, owner, due date, status, days overdue |
Key Features Inside the Template
Response Times Calculated for You
Enter five timestamps and the workbook computes time to detect, acknowledge, mitigate, and total duration.
Error Budget Built In
Set your SLO and period and see how much of the budget the incident consumed.
Several Contributing Factors
The factors table encourages listing more than one cause across tooling, process, monitoring, and design, not a single person.
Actions That Get Closed
Each action has a type, an owner, a due date, and a Days Overdue flag, so the postmortem produces change.
Best Use Cases
- Reviewing a production incident within a few days of resolution
- Building a shared habit of blameless review across a team
- Tracking whether postmortem actions are actually completed
- Training on-call engineers in incident timelines and measures
How to Use the Template Effectively
- Gather logs, alerts, and chat, and fill in the timestamps and timeline while memories are fresh.
- Hold a review meeting to discuss what made each action reasonable and what would make the failure harder next time.
- List several contributing factors with evidence, and avoid naming individuals as the cause.
- Agree actions with owners and dates, and choose a mix of prevent, detect, and mitigate actions.
- Review open actions weekly until complete, and look for patterns across postmortems.
Who Should Use This Template
- On-call engineers, incident commanders, and service owners
- Site reliability and platform teams
- Engineering managers building a learning culture
Common Mistakes to Avoid
- Naming a person or "human error" as the root cause
- Writing the postmortem but never completing the actions
- Listing only one contributing factor
- Including sensitive customer data or credentials in the document
Important Notes
Blameless Postmortem Template Frequently Asked Questions
What do the response-time formulas measure?
Time to detect is from the impact start to detection, time to acknowledge is from detection to when someone owns the alert, time to mitigate is from detection to when customer impact stops, and total duration is from impact start to resolution. Definitions vary between teams, so state yours in the summary.
How is the error budget calculated?
The error budget in minutes is the period in days times 1,440 minutes times one minus the SLO as a fraction. For a 99.9% SLO over 30 days it is 43.2 minutes, and the workbook shows the share of that budget the incident used.
Can I use this for security incidents?
You can adapt it, but security incidents may have legal, regulatory, and confidentiality requirements that the template does not cover. Follow your organization's security incident process, and take care not to record sensitive details in a shared file.