An incident review that changes nothing was theater
A short editorial on the incident review's only real deliverable, occasioned by a season of reading them.
A season of reading other people's postmortems earns the right to one blunt observation about our own industry habit: most incident reviews produce a document, and a document is not a change.
The test of a review is mechanical. Thirty days later, is there a control that did not exist before, a validation added, a permission narrowed, an alert deleted or created, a runbook line someone can point to? Amazon's response to its December incident, whatever else one thinks of it, passes this test: a mandatory review gate now exists that did not. Many internal reviews fail it. Action items are assigned, sprints intervene, the document joins its ancestors in the wiki's quiet cemetery.
The fix is unfashionable: fewer findings, harder ones. One structural change shipped beats nine learnings documented, and a review that ends with "no change needed, the system behaved as designed and the design is right" is more honest than a listicle of intentions nobody resourced.
The builder's read: put a thirty-day checkpoint on your last review's outputs, count what shipped, and let the number tell you which genre your organization has been writing.
tags: #postmortems #process #editorial