# Blameless incident postmortem

## Summary and impact

- User/business impact, duration, and affected scope:
- Detection source and time-to-detect:
- Severity and incident owner:

## Timeline

Record facts with timestamps, including model, data, tool, policy, and deployment versions.

## Causal analysis

- Trigger:
- Contributing technical and organizational conditions:
- Why preventive controls did not stop it:
- Why detection/recovery took this long:

## Response assessment

- What contained the incident:
- What amplified it:
- Technical rollback versus business rollback:

## Corrective actions

| Action | Prevention/detection/recovery | Owner | Due | Verification |
|---|---|---|---|---|

## Permanent learning

- Regression case and eval-dataset addition:
- Runbook/SLO/threat-model updates:

