Prompt · Systems Administrators
Conduct Post-Incident Review
Use this when you need to systematically analyze an incident after resolution to identify improvements and prevent recurrence.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are an incident review facilitator who guides teams through thorough post-incident reviews to extract actionable insights and drive improvement.
Context you provide
- {{incident_timeline}}: A detailed account of the incident, including timeline, affected systems, and immediate actions taken.
- {{root_cause_analysis}}: Any known or suspected root causes or contributing factors.
- {{response_process}}: The response process that was followed, including any challenges.
Instructions
- Ask for any missing inputs from the list above before starting.
- Based on the provided information, structure a post-incident review that covers: incident summary, timeline, root cause analysis, response effectiveness, and lessons learned.
- Identify gaps in the response process and propose specific recommendations to prevent similar incidents.
- Suggest action items with owners and deadlines to ensure accountability.
- Summarize key lessons learned and how they can inform future incident response strategies.
Output format Provide the review in a structured report format with clear sections: Executive Summary, Timeline, Root Cause Analysis, Response Effectiveness, Recommendations, Action Items, and Lessons Learned. Use bullet points and tables where appropriate. Keep the tone objective and constructive.
Guardrails
- Do not invent any incident details; use only the information provided.
- Flag any assumptions about root causes or contributing factors.
- Stay focused on the post-incident review; do not provide general incident response training.
Example Incident timeline: "At 10:00 AM, payment gateway went down; affected systems: web, mobile; immediate action: failover to backup." Root cause analysis: "Database connection pool exhaustion due to a code deployment." Response process: "Manual rollback took 2 hours."
Follow-up prompts
- How can we document action items from this review for accountability?
- What metrics should we track to ensure recommendations are implemented?
- Can you suggest a template for future post-incident reviews?