Information Technology / Incident Management Live
Incident Postmortem
Turn rough incident notes into a blameless postmortem with a timeline, contributing factors, and action items someone actually owns.
About the Agent
Challenges Incident Postmortem addresses
Done by hand, incident management means gathering incident notes and postmortem settings, working through 2 separate passes over the same material, then producing postmortem, timeline and action items. None of it is difficult and all of it is exacting, which is the combination people are worst at holding. The errors that matter are the ones a tired reader does not notice, and they surface later — in a reconciliation, or in somebody’s reply. It waits until someone remembers it, which is usually the point at which it has become urgent. As volume grows the work does not get harder, only longer, and the first thing to go is the checking.
Incident Postmortem runs that same sequence end to end and returns the result as structured artefacts. What it cannot settle it hands over rather than guesses at, and your correction is kept: it asks “Is this an accurate account?” after every run, and those answers become the set it is measured against. Nothing that moves money, alters a contract or reaches a customer executes without human approval, and every action is written to an audit log. The gain is in the volume that no longer has to be read, not in removing the judgement.
How it works
Step 1: Reconstructing what happened
First of 2. It works from incident notes and postmortem settings and feeds the step after it.
Key Tasks:
- Working from the run so far: This step takes incident notes and postmortem settings and carries it toward step 2.
- Following the same rules each time: The behaviour is configuration rather than judgement made fresh per run, so incident management is handled the same way every time.
- Surfacing what it cannot settle: Anything ambiguous is passed on as ambiguous rather than resolved silently.
Outcome:
- Passed on: The result passes to the next step, with anything unresolved carried forward as an open item rather than dropped.
Step 2: Writing the postmortem
Last of 2. It takes what step 1 produced and produces postmortem and timeline.
Key Tasks:
- Writing from the run, not from a template: The text is built from what this run actually found, so two incident management outputs differ where the underlying records differ.
- Leading with what needs a decision: The exceptions come first and the routine detail follows, because the reader is deciding rather than reading.
- Staying inside the evidence: Nothing appears in the text that is not supported by a record the run examined. Gaps are stated as gaps.
Outcome:
- Artefact ready: A finished artefact, traceable line by line to the records behind it, ready for a person to accept or correct.
Step 3: Your review, and what it changes
The run ends with a person, not with a result being filed.
Key Tasks:
- Asking a specific question: It asks “Is this an accurate account?” rather than for a rating. A question about this run is answerable; a score out of five is not.
- Keeping the correction: What you change is recorded against the case that produced it, so the disagreement is retrievable rather than absorbed.
- Building the evaluation set: Those cases become what the agent is measured on. It is scored against your judgement rather than against a general benchmark.
Outcome:
- A measured agent, not an assumed one: The cases Incident Postmortem handles well and the cases it does not are both visible, and the second list is the one that decides what changes. Nothing is retrained silently on the back of a single correction.
Why use Incident Postmortem?
- Checks are evidenced, not asserted: Each check records what was expected and what was found. A failure can be understood — and argued with — without re-running anything.
- A batch is one run, not a hundred: It works the whole set in a single pass and returns a row per item with its verdict, so the volume that needs no attention never has to be opened.
- Corrected by the people using it: After each run it asks “Is this an accurate account?”. Those answers become the evaluation set, which means it is measured against your judgement rather than ours.
- Reads and reports, does not act: It returns a result for review rather than writing changes back on its own. Anything that moves money, alters a contract or reaches a customer needs human approval first.
- Structured results, not prose: All 5 artefacts are structured — postmortem, timeline and action items — so a result can be scanned, sorted and acted on instead of read end to end.
Oversight
Runs under scoped, least-privilege credentials with every action written to an audit log. Anything that moves money, alters a contract or reaches a customer requires human approval before it executes.
Incident Management
Other agents in incident management
Service desk triage and incident summarisation
-
Classify an IT ticket, set its priority against your SLA, and draft either a fix or a routing note for approval. Nothing is sent.
View agent Book a call
Next Step
Deploy Incident Postmortem, or adapt it
It runs as-is. Most deployments diverge — a different source system, a different tolerance, a different approval path. A 30-minute technical call establishes which.