spearhead-issue-response/docs/after/post_mortem_template.md

80 lines
3.9 KiB
Markdown
Raw Normal View History

2017-01-21 14:39:08 +02:00
This is a standard template for post-mortems. Each section describes the type of information you will want to put in that section.
2017-01-13 20:18:18 +02:00
---
!!! note "Guidelines"
This page is intended to be reviewed during a post-mortem meeting that should be scheduled within 5 business days of any event.
Your first step should be to schedule the post-mortem meeting in the shared calendar for within 5 business days after the incident.
Don't wait until you've filled in the info to schedule the meeting, however make sure the page is completed by the meeting.
** Post-Mortem Owner:** _Your name goes here._
** Meeting Scheduled For:** _Schedule the meeting on the "Incident Post-Mortem Meetings" shared calendar, for within 5 business days after the incident. Put the date/time here._
2017-01-21 14:39:08 +02:00
** Call Recording:** _Link to the incident call recording / slack transcript or DoIT card._
2017-01-13 20:18:18 +02:00
## Overview
2017-01-21 14:39:08 +02:00
_Include a **short** sentence or two summarizing the root cause, timeline summary, and the impact. E.g. "On the morning of August 99th, we suffered a 1 minute IN-3 due to a runaway process on our primary database machine. This slowness caused roughly 0.024% of alerts that had begun during this time to be delivered out of SLA."_
2017-01-13 20:18:18 +02:00
## What Happened
_Include a short description of what happened._
## Root Cause
_Include a description of the root cause. If there were any actions taken that exacerbated the issue, also include them here with the intention of learning from any mistakes made during the resolution process._
## Resolution
_Include a description what solved the problem. If there was a temporary fix in place, describe that along with the long-term solution._
## Impact
_Be very specific here, include exact numbers._
2017-01-21 14:39:08 +02:00
| Time in SR-3 | ?mins |
| Time in IN-3 | ?mins |
2017-01-13 20:18:18 +02:00
| Notifications Delivered out of SLA | ??% (?? of ??) |
| Events Dropped / Not Accepted | ??% (?? of ??) _Should usually be 0, but always check_ |
| Accounts Affected | ?? |
| Users Affected | ?? |
| Support Requests Raised | ?? _Include any relevant links to tickets_ |
## Responders
2017-01-21 14:39:08 +02:00
* _Who was the TL?_
2017-01-13 20:18:18 +02:00
* _Who was the scribe?_
* _Who else was involved?_
* _Who else was involved?_
## Timeline
2017-01-21 14:39:08 +02:00
_Some important times to include: (1) time the root cause began, (2) time of the page, (3) time that the status page was updated (i.e. when the incident became public), (4) time of any significant actions, (5) time the IN-3 ended, (6) links to tools/logs that show how the timestamp was arrived at._
2017-01-13 20:18:18 +02:00
| Time (UTC) | Event | Data Link |
| ---------- | ----- | --------- |
## How'd We Do?
### What Went Well?
* _List anything you did well and want to call out. It's OK to not list anything._
### What Didn't Go So Well?
* _List anything you think we didn't do very well. The intent is that we should follow up on all points here to improve our processes._
## Action Items
2017-01-21 14:39:08 +02:00
_Each action item should be in the form of a DoIT card respectiv GTD next actions principle: "a clear and concise single action to move things forward”. Include action items such as: (1) any fixes required to prevent the root cause in the future, (2) any preparedness tasks that could help mitigate the problem if it came up again, (3) remaining post-mortem steps, such as the internal email, as well as the status-page public post, (4) any improvements to our incident response process._
2017-01-13 20:18:18 +02:00
## Messaging
### Internal Email
_This is a follow-up for employees. It should be sent out right after the post-mortem meeting is over. It only needs a short paragraph summarizing the incident and a link to this wiki page._
> Briefly summarize what happened and where the post-mortem page (this page) can be found.
### External Message
2017-01-21 14:39:08 +02:00
_This is what will be included on the public facing status website (status.spearhead.systems) regarding this incident. What are we telling customers, including an apology? (The apology should be genuine, not rote.)_
2017-01-13 20:18:18 +02:00
> Summary
> What Happened?
> What Are We Doing About This?