Example data. Fieldnote is a fictional company used to fill all 61 boards, so the examples tell one consistent story.
Fieldnote, the blameless post-mortem after the March release that broke photo upload for two days: Tom, the two engineers on the release, Julien, and Karim as neutral facilitator.
What the team took away
The room expected 'who merged it'; the timeline showed the merge was fine and the device bench was the hole. Three actions, all about the bench and the calendar.
How to run it
Preparation
Everyone who touched the incident, plus a facilitator who was not involved. The facilitator is the only one who may interrupt.
Collect the raw timeline before the session: alerts, messages, deploys, with timestamps. Post it on the board as-is, no interpretation.
Four columns: Timeline, Causes, What went well, Actions. Write the blameless rule at the top of the board in large text.
Agenda
5 min
Read the rule Say it: we assume everyone acted with the best information they had. We are fixing the system, not the people. Anyone who names a culprit gets stopped.
25 min
Walk the timeline Read the timeline minute by minute. Each participant adds what they knew and saw at each point. Correct timestamps, add missing events.
25 min
Causes For each turning point, ask why up to five times. Stop at the first cause that is a process, a tool, or missing information. Never stop at a person.
10 min
What went well List what limited the damage: a fast alert, a good rollback, someone who called the right person. These become things to protect.
25 min
Actions Maximum four actions, each preventing a cause or shortening detection or recovery. Owner and date. Publish the report to the whole organization within 48 hours.
Pitfalls
Do not let the person closest to the incident write the timeline alone. They fill gaps with memory, and memory is kind to itself.
Do not stop the whys at 'X made a mistake'. Ask why the system let that mistake reach production.
Do not keep the report private. A post-mortem nobody outside the team reads teaches nobody outside the team.
Afterwards
The report is published and the actions tracked like any backlog item, with a check at 30 days. Recurring causes across post-mortems belong in the Inspect & Adapt or on the leadership OKRs.