Template — Incident Review
Incident date/time:
Service(s):
Impact:
Status: Resolved / Monitoring / Open
Summary
Short factual description of user-visible impact and duration.
Timeline
Use exact timestamps with time zones. Mark hypotheses as hypotheses.
Detection
How the issue was first detected and whether monitoring should have detected it earlier.
Root and contributing conditions
Explain technical/system conditions without assigning personal blame.
Recovery
What restored service and how restoration was verified.
What worked / what did not
Tools, runbooks, alerts, architecture and communication.
Actions
Concrete owner, action and tracking reference. Separate immediate fixes from longer-term prevention.
Documentation changes
List runbooks/reference pages that were created or updated because of this incident.