Plan my session
Plan a concrete work block with agenda, roles, preparation, and a copyable result artifact.
Session: Causal Factor Analysis
The plan translates the method into a concrete facilitated work block. Your inputs flow directly into the session brief and work artifact.
Method session with 3-10. The plan uses the existing method logic and the runsheet.
RunsheetUse the session for shared understanding. Contributions are collected visibly, assumptions are aligned, and open differences remain traceable in the artifact.
The session works directly toward Event Timeline. After the session, the artifact should be shareable, reviewable, or reusable.
- 1
0-10 min
10 minCollect the incident facts: timestamped events, alerts, decisions, and visible impact. Keep opinions out of the first pass. Hint: If the first notes already contain explanations, the group is skipping the evidence base. Start with what happened, not why it happened.
FacilitatorEvent Timeline - 2
10-25 min
15 minReconstruct the timeline from trigger to stabilization. Add the events in order and mark gaps that still need evidence. Hint: A missing event is still a finding. Mark unknowns explicitly instead of filling them with memory.
FacilitatorCausal Factor Chart - 3
25-40 min
15 minMark causal factors, contributing conditions, and decision points on the timeline. Distinguish triggers from deeper causes. Hint: Not every factor is a cause. If a note only explains context, move it out of the causal column.
FacilitatorCause List - 4
40-55 min
15 minCheck each proposed factor against logs, metrics, or other evidence. Keep unverified items separate. Hint: Evidence checking is the heart of the method. A plausible story without evidence is still only a story.
FacilitatorCorrective Actions - 5
55-90 min
35 minDerive the root causes and the follow-up actions. Separate recurrence prevention from detection improvements and assign owners. Hint: Detection fixes are useful, but they do not replace cause fixes. Keep both lists visible so the team does not stop too early.
OwnerEvent Timeline - 6
Publish artifact
10 minCheck the artifact for completeness, define location, set version or status, and name review recipients.
OwnerEvent Timeline
Session Brief
For invitations, boards, tickets, PR descriptions, or workshop notes.
session-brief.md
Session Brief: Causal Factor Analysis
Goal
Artifact: Event Timeline
Working Question
Which event factors and conditions actually shaped the incident, and which ones are root causes versus contributors?
Context
Incident ID, event window, affected systems, known signals, and any decisions or mitigations that happened during the incident.
Setup
- Format: Method session
- Duration: 60-90 min
- Mode: Workshop or async
- Participants: One facilitator; one scribe; two to five people with direct process or system knowledge; optionally one reviewer who checks evidence quality.
- Owner: One facilitator
- Participation mode: Team round, shared work and alignment
- Outcome logic: Finish artifact
Participation Logic
Use the session for shared understanding. Contributions are collected visibly, assumptions are aligned, and open differences remain traceable in the artifact.
Outcome Logic
The session works directly toward Event Timeline. After the session, the artifact should be shareable, reviewable, or reusable.
Input
Timeline board or incident template; logs, metrics, and ticket history; sticky notes; markers; export or capture tool for the final timeline.
Preparation
Lay out the chronology first. Keep evidence, interpretations, and hypotheses on separate notes. Do not jump to causes before the timeline is visible.
Agenda
-
0-10 min (10 min) Owner: Facilitator Action: Collect the incident facts: timestamped events, alerts, decisions, and visible impact. Keep opinions out of the first pass. Hint: If the first notes already contain explanations, the group is skipping the evidence base. Start with what happened, not why it happened. Output: Event Timeline
-
10-25 min (15 min) Owner: Facilitator Action: Reconstruct the timeline from trigger to stabilization. Add the events in order and mark gaps that still need evidence. Hint: A missing event is still a finding. Mark unknowns explicitly instead of filling them with memory. Output: Causal Factor Chart
-
25-40 min (15 min) Owner: Facilitator Action: Mark causal factors, contributing conditions, and decision points on the timeline. Distinguish triggers from deeper causes. Hint: Not every factor is a cause. If a note only explains context, move it out of the causal column. Output: Cause List
-
40-55 min (15 min) Owner: Facilitator Action: Check each proposed factor against logs, metrics, or other evidence. Keep unverified items separate. Hint: Evidence checking is the heart of the method. A plausible story without evidence is still only a story. Output: Corrective Actions
-
55-90 min (35 min) Owner: Owner Action: Derive the root causes and the follow-up actions. Separate recurrence prevention from detection improvements and assign owners. Hint: Detection fixes are useful, but they do not replace cause fixes. Keep both lists visible so the team does not stop too early. Output: Event Timeline
-
Publish artifact (10 min) Owner: Owner Action: Check the artifact for completeness, define location, set version or status, and name review recipients. Output: Event Timeline
Closeout
- Update result artifact: Event Timeline
- Define location, version, and review recipients.
- Define owner, next step, and review date.
Work artifact
Pre-filled starting point based on the matching template.
work-artifact.md
Event Timeline: Causal Factor Analysis
Working Question
Which event factors and conditions actually shaped the incident, and which ones are root causes versus contributors?
Context
Incident ID, event window, affected systems, known signals, and any decisions or mitigations that happened during the incident.
Participants
- Owner: One facilitator
- Participants: One facilitator; one scribe; two to five people with direct process or system knowledge; optionally one reviewer who checks evidence quality.
Input
Timeline board or incident template; logs, metrics, and ticket history; sticky notes; markers; export or capture tool for the final timeline.
Template
Causal Factor Analysis Working Template
Goal
Reconstructs events and contributing factors to understand the main causes of a problem.
Context
When and for what do we use this method?
Input
Which data, observations, decisions, or materials are available?
Execution
Short notes along the runsheet.
Output artifacts
- Event Timeline:
- Causal Factor Chart:
- Cause List:
- Corrective Actions:
Assumptions and open questions
- ...
Decision / Next step
Owner, date, and success signal.
Completion Check
- Event Timeline is complete enough for review:
- Location:
- Version / status:
- Review by:
- Next step:
Next Step
- Review result
- Mark open questions
- Schedule review or decision
Causal Factor Analysis Working Template
View templateCompact working template for Causal Factor Analysis with context, input, output artifacts, and next step.markdown
causal-factor-analysis-working-template.md
Compact working template for Causal Factor Analysis with context, input, output artifacts, and next step.
Causal Factor Analysis Working Template
Goal
Reconstructs events and contributing factors to understand the main causes of a problem.
Context
When and for what do we use this method?
Input
Which data, observations, decisions, or materials are available?
Execution
Short notes along the runsheet.
Output artifacts
- Event Timeline:
- Causal Factor Chart:
- Cause List:
- Corrective Actions:
Assumptions and open questions
- ...
Decision / Next step
Owner, date, and success signal.
- Working question, owner, and target artifact are visible.
- The result fits Event Timeline.
- Store the incident ID, date, and version state together. Keep evidence updates as later revisions instead of overwriting the original causal chain.
- Open questions are noted as follow-ups.
- The next review or decision point is scheduled.