Turns workflows, data, causes, and improvements into a tangible result through defining the problem, asking why, and defining countermeasures.
Core question: Which controllable cause behind the symptom can the team fix with a concrete countermeasure?
Analysis methodMethod form: Analysis method. Describes how this method is used in practice.LowComplexity: low. Estimates preparation, facilitation effort, and method confidence needed.WorkshopFormat: workshop. Shows whether the method works in a workshop, asynchronously, or both.
15-30 min
2-6
Run sheet · visual · session plan
Details
DevOpsCategory: DevOps. Describes the method's domain of use.
Turns incident work, roles, and countermeasures into a tangible result by documenting the incident, describing impact and timeline, and sharing learnings.
Core question: Which system conditions and decision points made the incident possible, and which concrete measures prevent recurrence?
Operating practiceMethod form: Operating practice. Describes how this method is used in practice.MediumComplexity: medium. Estimates preparation, facilitation effort, and method confidence needed.Workshop + asyncFormat: workshop or async. Shows whether the method works in a workshop, asynchronously, or both.
30-90 min
3-12
Run sheet · visual · session plan
Details
OperationsCategory: Operations. Describes the method's domain of use.
Turns workflows, data, causes, and improvements into a tangible result by describing the problem precisely, collecting data and events, and deriving countermeasures and controls.
Core question: Which systemic causes caused or enabled the problem, and which countermeasures prevent recurrence instead of only treating symptoms?
Analysis methodMethod form: Analysis method. Describes how this method is used in practice.MediumComplexity: medium. Estimates preparation, facilitation effort, and method confidence needed.Workshop + asyncFormat: workshop or async. Shows whether the method works in a workshop, asynchronously, or both.
1-4 h
3-8
Run sheet · visual · session plan
Details
OperationsCategory: Operations. Describes the method's domain of use.
Hazards, targets, and failed barriers are mapped so controls can be strengthened at the point of exposure.
Core question: Which barriers were supposed to prevent the damage, which existed, functioned, and were effective enough, and which are missing or failed?
Analysis methodMethod form: Analysis method. Describes how this method is used in practice.MediumComplexity: medium. Estimates preparation, facilitation effort, and method confidence needed.Workshop + asyncFormat: workshop or async. Shows whether the method works in a workshop, asynchronously, or both.
2-4 h
2-6
Run sheet · visual · session plan
Details
OperationsCategory: Operations. Describes the method's domain of use.
Turns workflows, data, causes, and improvements into a tangible result by collecting event data, reconstructing the timeline, and deriving root causes and measures.
Core question: Which event factors and conditions actually shaped the incident, and which ones are root causes versus contributors?
Mapping toolMethod form: Mapping tool. Describes how this method is used in practice.HighComplexity: high. Estimates preparation, facilitation effort, and method confidence needed.Workshop + asyncFormat: workshop or async. Shows whether the method works in a workshop, asynchronously, or both.
2-6 h
3-10
Run sheet · visual · session plan
Details
DevOpsCategory: DevOps. Describes the method's domain of use.
Turns incident work, roles, and countermeasures into a tangible result by integrating tools, routing alerts, and improving the workflow.
Core question: Which recurring operational actions can be triggered safely, traceably, and across the team in chat instead of in scattered tools?
Operating practiceMethod form: Operating practice. Describes how this method is used in practice.MediumComplexity: medium. Estimates preparation, facilitation effort, and method confidence needed.Workshop + asyncFormat: workshop or async. Shows whether the method works in a workshop, asynchronously, or both.
Ongoing
2-20
Run sheet · visual · session plan
Details
DevOpsCategory: DevOps. Describes the method's domain of use.
Turns incident work, roles, and countermeasures into a tangible result by selecting a scenario, preparing environment and rules, and improving runbooks.
Core question: How do system, tools, and team react to realistically injected failures, and which gaps in runbooks, monitoring, or roles become visible?
Workshop methodMethod form: Workshop method. Describes how this method is used in practice.HighComplexity: high. Estimates preparation, facilitation effort, and method confidence needed.WorkshopFormat: workshop. Shows whether the method works in a workshop, asynchronously, or both.
Halber Tag
5-20
Run sheet · visual · session plan
Details
DevOpsCategory: DevOps. Describes the method's domain of use.
Turns incident work, roles, and countermeasures into a tangible result by collecting sources, ordering events chronologically, and deriving lessons and actions.
Core question: What happened when, which signals and decisions shaped the incident, and where are the learning points?
Mapping toolMethod form: Mapping tool. Describes how this method is used in practice.MediumComplexity: medium. Estimates preparation, facilitation effort, and method confidence needed.Workshop + asyncFormat: workshop or async. Shows whether the method works in a workshop, asynchronously, or both.
60-180 min
3-10
Run sheet · visual · session plan
Details
OperationsCategory: Operations. Describes the method's domain of use.
Turns workflows, data, causes, and improvements into a tangible result by clarifying scope and stance, reconstructing the timeline, and deriving learning actions.
Core question: Which conditions, assumptions, and decisions made this event possible, and which systemic improvements increase the learning rate?
Operating practiceMethod form: Operating practice. Describes how this method is used in practice.MediumComplexity: medium. Estimates preparation, facilitation effort, and method confidence needed.WorkshopFormat: workshop. Shows whether the method works in a workshop, asynchronously, or both.
1-3 h
3-10
Run sheet · visual · session plan
Details
OperationsCategory: Operations. Describes the method's domain of use.
A structured accident tree separates management controls, barriers, and events so serious incidents become auditable.
Core question: Which specific controls and which management oversight functions were involved in the incident, were effective, insufficient, or missing, and which systemic levers follow from this?
Analysis methodMethod form: Analysis method. Describes how this method is used in practice.HighComplexity: high. Estimates preparation, facilitation effort, and method confidence needed.Workshop + asyncFormat: workshop or async. Shows whether the method works in a workshop, asynchronously, or both.
Mehrere Tage bis Wochen
2-6
Run sheet · visual · session plan
Details
OperationsCategory: Operations. Describes the method's domain of use.
Clarifies workflows, data, causes, and improvements by framing the problem precisely, branching possible causes, and defining countermeasures.
Core question: Which causal paths lead from observed problem to controllable causes, and which actions address the most likely paths?
Mapping toolMethod form: Mapping tool. Describes how this method is used in practice.MediumComplexity: medium. Estimates preparation, facilitation effort, and method confidence needed.WorkshopFormat: workshop. Shows whether the method works in a workshop, asynchronously, or both.
1-3 h
2-8
Run sheet · visual · session plan
Details
OperationsCategory: Operations. Describes the method's domain of use.
A recurring incident pattern links related cases across time so systemic causes become visible beyond one event.
Core question: Which earlier or parallel incidents form a family with the target incident, and what systemic patterns become visible through that relationship?
Mapping toolMethod form: Mapping tool. Describes how this method is used in practice.MediumComplexity: medium. Estimates preparation, facilitation effort, and method confidence needed.Workshop + asyncFormat: workshop or async. Shows whether the method works in a workshop, asynchronously, or both.