Incident Review Report

Free template

A post-incident review (postmortem) report

For engineering, operations, and support teams

Free, no account required
Available formats

By clicking “Use this template” or downloading a file, you acknowledge that you have read and agree to be bound by the Revise Terms of Service and Privacy Policy, and that the template is provided “as is” without warranty of any kind and does not constitute legal, financial, or professional advice.

INCIDENT REVIEW

[Incident title: what failed, in plain words]

INCIDENT ID

[INC-0000]

SEVERITY

[SEV-1 / 2 / 3]

STATUS

[Resolved / Monitoring]

DATE

[Month DD, YYYY]

DURATION

[HH:MM]

AUTHOR

[Name]

This review describes what happened and how to prevent it. It focuses on systems and processes, not individuals.

Summary

[Two or three sentences: what failed, who was affected, how long it lasted, and how it was resolved.]

Impact

  • [Customers or users affected: number or share]
  • [Services or features affected]
  • [Data loss or corruption: none / describe]
  • [Financial or contractual impact, if known]

Timeline

All times in [UTC].

TIME

EVENT

[00:00]

[Change deployed / first error observed]

[00:00]

[Alert fired / issue reported by customer]

[00:00]

[Incident declared; responders engaged]

[00:00]

[Mitigation applied]

[00:00]

[Service fully restored]

Detection

[How the incident was detected, how long detection took, and whether monitoring would have caught it sooner.]

Contributing factors

  1. [Technical factor]
  2. [Process factor]
  3. [Factor that made the impact larger or longer]

What went well and what did not

Went well

  • [Item]
  • [Item]

Did not go well

  • [Item]
  • [Item]

Corrective actions

ID

ACTION

OWNER

DUE

STATUS

A1

[Action that prevents recurrence]

[Name]

[MM/DD]

[Open]

A2

[Action that improves detection]

[Name]

[MM/DD]

[Open]

A3

[Action that reduces impact]

[Name]

[MM/DD]

[Open]