methodatlas
Session Builder

Plan my session

Plan a concrete work block with agenda, roles, preparation, and a copyable result artifact.

Method session60-90 minWorkshop or asyncEvent Timeline

Session: Causal Factor Analysis

The plan translates the method into a concrete facilitated work block. Your inputs flow directly into the session brief and work artifact.

Derived automatically

Method session with 3-10. The plan uses the existing method logic and the runsheet.

Runsheet
Participation logic
Team round, shared work and alignment

Use the session for shared understanding. Contributions are collected visibly, assumptions are aligned, and open differences remain traceable in the artifact.

Outcome logic
Finish artifact

The session works directly toward Event Timeline. After the session, the artifact should be shareable, reviewable, or reusable.

  1. 1

    0-10 min

    10 min

    Collect the incident facts: timestamped events, alerts, decisions, and visible impact. Keep opinions out of the first pass. Hint: If the first notes already contain explanations, the group is skipping the evidence base. Start with what happened, not why it happened.

    FacilitatorEvent Timeline
  2. 2

    10-25 min

    15 min

    Reconstruct the timeline from trigger to stabilization. Add the events in order and mark gaps that still need evidence. Hint: A missing event is still a finding. Mark unknowns explicitly instead of filling them with memory.

    FacilitatorCausal Factor Chart
  3. 3

    25-40 min

    15 min

    Mark causal factors, contributing conditions, and decision points on the timeline. Distinguish triggers from deeper causes. Hint: Not every factor is a cause. If a note only explains context, move it out of the causal column.

    FacilitatorCause List
  4. 4

    40-55 min

    15 min

    Check each proposed factor against logs, metrics, or other evidence. Keep unverified items separate. Hint: Evidence checking is the heart of the method. A plausible story without evidence is still only a story.

    FacilitatorCorrective Actions
  5. 5

    55-90 min

    35 min

    Derive the root causes and the follow-up actions. Separate recurrence prevention from detection improvements and assign owners. Hint: Detection fixes are useful, but they do not replace cause fixes. Keep both lists visible so the team does not stop too early.

    OwnerEvent Timeline
  6. 6

    Publish artifact

    10 min

    Check the artifact for completeness, define location, set version or status, and name review recipients.

    OwnerEvent Timeline
Usable artifact

Session Brief

For invitations, boards, tickets, PR descriptions, or workshop notes.

session-brief.md

Session Brief: Causal Factor Analysis

Goal

Artifact: Event Timeline

Working Question

Which event factors and conditions actually shaped the incident, and which ones are root causes versus contributors?

Context

Incident ID, event window, affected systems, known signals, and any decisions or mitigations that happened during the incident.

Setup

  • Format: Method session
  • Duration: 60-90 min
  • Mode: Workshop or async
  • Participants: One facilitator; one scribe; two to five people with direct process or system knowledge; optionally one reviewer who checks evidence quality.
  • Owner: One facilitator
  • Participation mode: Team round, shared work and alignment
  • Outcome logic: Finish artifact

Participation Logic

Use the session for shared understanding. Contributions are collected visibly, assumptions are aligned, and open differences remain traceable in the artifact.

Outcome Logic

The session works directly toward Event Timeline. After the session, the artifact should be shareable, reviewable, or reusable.

Input

Timeline board or incident template; logs, metrics, and ticket history; sticky notes; markers; export or capture tool for the final timeline.

Preparation

Lay out the chronology first. Keep evidence, interpretations, and hypotheses on separate notes. Do not jump to causes before the timeline is visible.

Agenda

  1. 0-10 min (10 min) Owner: Facilitator Action: Collect the incident facts: timestamped events, alerts, decisions, and visible impact. Keep opinions out of the first pass. Hint: If the first notes already contain explanations, the group is skipping the evidence base. Start with what happened, not why it happened. Output: Event Timeline

  2. 10-25 min (15 min) Owner: Facilitator Action: Reconstruct the timeline from trigger to stabilization. Add the events in order and mark gaps that still need evidence. Hint: A missing event is still a finding. Mark unknowns explicitly instead of filling them with memory. Output: Causal Factor Chart

  3. 25-40 min (15 min) Owner: Facilitator Action: Mark causal factors, contributing conditions, and decision points on the timeline. Distinguish triggers from deeper causes. Hint: Not every factor is a cause. If a note only explains context, move it out of the causal column. Output: Cause List

  4. 40-55 min (15 min) Owner: Facilitator Action: Check each proposed factor against logs, metrics, or other evidence. Keep unverified items separate. Hint: Evidence checking is the heart of the method. A plausible story without evidence is still only a story. Output: Corrective Actions

  5. 55-90 min (35 min) Owner: Owner Action: Derive the root causes and the follow-up actions. Separate recurrence prevention from detection improvements and assign owners. Hint: Detection fixes are useful, but they do not replace cause fixes. Keep both lists visible so the team does not stop too early. Output: Event Timeline

  6. Publish artifact (10 min) Owner: Owner Action: Check the artifact for completeness, define location, set version or status, and name review recipients. Output: Event Timeline

Closeout

  • Update result artifact: Event Timeline
  • Define location, version, and review recipients.
  • Define owner, next step, and review date.
Usable artifact

Work artifact

Pre-filled starting point based on the matching template.

work-artifact.md

Event Timeline: Causal Factor Analysis

Working Question

Which event factors and conditions actually shaped the incident, and which ones are root causes versus contributors?

Context

Incident ID, event window, affected systems, known signals, and any decisions or mitigations that happened during the incident.

Participants

  • Owner: One facilitator
  • Participants: One facilitator; one scribe; two to five people with direct process or system knowledge; optionally one reviewer who checks evidence quality.

Input

Timeline board or incident template; logs, metrics, and ticket history; sticky notes; markers; export or capture tool for the final timeline.

Template

Causal Factor Analysis Working Template

Goal

Reconstructs events and contributing factors to understand the main causes of a problem.

Context

When and for what do we use this method?

Input

Which data, observations, decisions, or materials are available?

Execution

Short notes along the runsheet.

Output artifacts

  • Event Timeline:
  • Causal Factor Chart:
  • Cause List:
  • Corrective Actions:

Assumptions and open questions

  • ...

Decision / Next step

Owner, date, and success signal.

Completion Check

  • Event Timeline is complete enough for review:
  • Location:
  • Version / status:
  • Review by:
  • Next step:

Next Step

  • Review result
  • Mark open questions
  • Schedule review or decision
Template base

Causal Factor Analysis Working Template

View templateCompact working template for Causal Factor Analysis with context, input, output artifacts, and next step.
markdown

causal-factor-analysis-working-template.md

Compact working template for Causal Factor Analysis with context, input, output artifacts, and next step.

Causal Factor Analysis Working Template

Goal

Reconstructs events and contributing factors to understand the main causes of a problem.

Context

When and for what do we use this method?

Input

Which data, observations, decisions, or materials are available?

Execution

Short notes along the runsheet.

Output artifacts

  • Event Timeline:
  • Causal Factor Chart:
  • Cause List:
  • Corrective Actions:

Assumptions and open questions

  • ...

Decision / Next step

Owner, date, and success signal.

Ready to use when
  • Working question, owner, and target artifact are visible.
  • The result fits Event Timeline.
  • Store the incident ID, date, and version state together. Keep evidence updates as later revisions instead of overwriting the original causal chain.
  • Open questions are noted as follow-ups.
  • The next review or decision point is scheduled.