Plan my session
Plan a concrete work block with agenda, roles, preparation, and a copyable result artifact.
Session: Incident Timeline Analysis
The plan translates the method into a concrete facilitated work block. Your inputs flow directly into the session brief and work artifact.
Method session with 3-10. The plan uses the existing method logic and the runsheet.
RunsheetUse the session for shared understanding. Contributions are collected visibly, assumptions are aligned, and open differences remain traceable in the artifact.
The session works directly toward Incident Timeline. After the session, the artifact should be shareable, reviewable, or reusable.
- 1
Fix scope
10-20 minDefine trigger, objective, and boundaries of the investigation. Capture off-topic topics on a parking lot. Hint: A tight scope creates better outcomes than a complete but diffuse sweep.
FacilitatorIncident Timeline - 2
Collect raw material
20-40 minGather and visualize facts, events, options, constraints, or assumptions. Hint: Keep facts and interpretations separate. Mark uncertain points instead of smoothing them over.
FacilitatorEvidence Log - 3
Build structure
30-60 minFill in the incident timeline step by step, clarify relationships between elements, and surface contradictions. Hint: Do not evaluate too early. Stabilize structure first, then draw conclusions.
FacilitatorDelay Analysis - 4
Review and distill
20-40 minMark gaps, weak assumptions, counterexamples, and critical paths. Check whether the result is understandable. Hint: If no one can explain the logic in two minutes, the artifact is not ready yet.
FacilitatorImprovement Actions - 5
Define next steps
15-20 minDocument decision, experiment, test, measure, or follow-up with owner and date. Hint: A high-quality artifact without a next action remains knowledge work without impact.
OwnerIncident Timeline - 6
Publish artifact
10 minCheck the artifact for completeness, define location, set version or status, and name review recipients.
OwnerIncident Timeline
Session Brief
For invitations, boards, tickets, PR descriptions, or workshop notes.
session-brief.md
Session Brief: Incident Timeline Analysis
Goal
Artifact: Incident Timeline
Working Question
What happened when, which signals and decisions shaped the incident, and where are the learning points?
Context
Scope, trigger, known facts, relevant constraints, prior options or events, and the desired outcome of the session.
Setup
- Format: Method session
- Duration: 60-180 min
- Mode: Workshop or async
- Participants: Facilitator; functional experts from the affected area; one owner for result and follow-up; a named decider for decisions.
- Owner: Facilitator
- Participation mode: Team round, shared work and alignment
- Outcome logic: Finish artifact
Participation Logic
Use the session for shared understanding. Contributions are collected visibly, assumptions are aligned, and open differences remain traceable in the artifact.
Outcome Logic
The session works directly toward Incident Timeline. After the session, the artifact should be shareable, reviewable, or reusable.
Input
Working board or document for incident timeline; existing notes, data, decisions, and assumptions; markers for uncertainty, owner, and next steps.
Preparation
Prepare an empty Incident Timeline template. Keep scope and work question visible at the top. Mark each assumption as assumption, not as fact.
Agenda
-
Fix scope (10-20 min) Owner: Facilitator Action: Define trigger, objective, and boundaries of the investigation. Capture off-topic topics on a parking lot. Hint: A tight scope creates better outcomes than a complete but diffuse sweep. Output: Incident Timeline
-
Collect raw material (20-40 min) Owner: Facilitator Action: Gather and visualize facts, events, options, constraints, or assumptions. Hint: Keep facts and interpretations separate. Mark uncertain points instead of smoothing them over. Output: Evidence Log
-
Build structure (30-60 min) Owner: Facilitator Action: Fill in the incident timeline step by step, clarify relationships between elements, and surface contradictions. Hint: Do not evaluate too early. Stabilize structure first, then draw conclusions. Output: Delay Analysis
-
Review and distill (20-40 min) Owner: Facilitator Action: Mark gaps, weak assumptions, counterexamples, and critical paths. Check whether the result is understandable. Hint: If no one can explain the logic in two minutes, the artifact is not ready yet. Output: Improvement Actions
-
Define next steps (15-20 min) Owner: Owner Action: Document decision, experiment, test, measure, or follow-up with owner and date. Hint: A high-quality artifact without a next action remains knowledge work without impact. Output: Incident Timeline
-
Publish artifact (10 min) Owner: Owner Action: Check the artifact for completeness, define location, set version or status, and name review recipients. Output: Incident Timeline
Closeout
- Update result artifact: Incident Timeline
- Define location, version, and review recipients.
- Define owner, next step, and review date.
Work artifact
Pre-filled starting point based on the matching template.
work-artifact.md
Incident Timeline: Incident Timeline Analysis
Working Question
What happened when, which signals and decisions shaped the incident, and where are the learning points?
Context
Scope, trigger, known facts, relevant constraints, prior options or events, and the desired outcome of the session.
Participants
- Owner: Facilitator
- Participants: Facilitator; functional experts from the affected area; one owner for result and follow-up; a named decider for decisions.
Input
Working board or document for incident timeline; existing notes, data, decisions, and assumptions; markers for uncertainty, owner, and next steps.
Template
Incident Timeline
Incident: ... Period: ... Sources: logs, alerts, chat, tickets
| Time | Event | Source | Confidence | Note |
|---|---|---|---|---|
| HH:MM | high/medium/low |
Observed delays
- ...
Open gaps
- ...
Learnings
- ...
Completion Check
- Incident Timeline is complete enough for review:
- Location:
- Version / status:
- Review by:
- Next step:
Next Step
- Review result
- Mark open questions
- Schedule review or decision
Incident Timeline
View templateChronological template for incident reconstruction with sources and uncertainty.markdown
incident-timeline-markdown.md
Chronological template for incident reconstruction with sources and uncertainty.
Incident Timeline
Incident: ... Period: ... Sources: logs, alerts, chat, tickets
| Time | Event | Source | Confidence | Note |
|---|---|---|---|---|
| HH:MM | high/medium/low |
Observed delays
- ...
Open gaps
- ...
Learnings
- ...
- Working question, owner, and target artifact are visible.
- The result fits Incident Timeline.
- Save artifact with date, scope, and participants. When new evidence appears, create a new version or change log so decision logic remains traceable.
- Open questions are noted as follow-ups.
- The next review or decision point is scheduled.