Plan my session
Plan a concrete work block with agenda, roles, preparation, and a copyable result artifact.
Session: Root Cause Tree Analysis
The plan translates the method into a concrete facilitated work block. Your inputs flow directly into the session brief and work artifact.
Method session with 2-8. The plan uses the existing method logic and the runsheet.
RunsheetUse the session for shared understanding. Contributions are collected visibly, assumptions are aligned, and open differences remain traceable in the artifact.
The session works directly toward Cause Tree. After the session, the artifact should be shareable, reviewable, or reusable.
- 1
Phase 1: Formulate problem precisely
10-15 minWrite problem as observable symptom in one sentence: what, when, how often, which effect. No cause in sentence. Formulate success picture for analysis. Hint: If sentence contains "because X", diagnosis is already made and tree no longer works. Reformulate.
FacilitatorCause Tree - 2
Phase 2: Branch causes
30-60 minOne branch per possible cause. On level 1, main categories (for example software, data, infrastructure, process). On levels 2 and 3, concrete hypotheses. Hint: Require at least three main branches, otherwise tree becomes one-sided. If a branch remains empty, explicitly mark as consciously empty with rationale.
FacilitatorEvidence Notes - 3
Phase 3: Add evidence
30-45 minStick yellow evidence note per hypothesis: log, graph, config line or test result. If no evidence available, red unverified note and spike task. Hint: Evidence is checked live during session where possible. With operator present, many hypotheses can be refuted or confirmed immediately.
FacilitatorGegenmaßnahmen - 4
Phase 4: Prioritize and actions
20-30 minRate paths by probability and leverage (for example traffic light). Concrete action with owner and date per top path. Explicitly separate detection actions from cause correction. Hint: Improving monitoring is detection, not cause correction. Note both, clearly separated.
OwnerCause Tree - 5
Publish artifact
10 minCheck the artifact for completeness, define location, set version or status, and name review recipients.
OwnerCause Tree
Session Brief
For invitations, boards, tickets, PR descriptions, or workshop notes.
session-brief.md
Session Brief: Root Cause Tree Analysis
Goal
Artifact: Cause Tree
Working Question
Which causal paths lead from observed problem to controllable causes, and which actions address the most likely paths?
Context
Problem sentence with timestamp and impact; known workarounds; available data sources; incident ID; list of suspected causes from group gut feeling.
Setup
- Format: Method session
- Duration: 1-3 h
- Mode: Workshop
- Participants: One facilitator who guides branching and asks for evidence; three to eight participants with system contact; one scribe for evidence column; if needed one data operator who runs live queries.
- Owner: One facilitator who guides branching and asks for evidence
- Participation mode: Team round, shared work and alignment
- Outcome logic: Finish artifact
Participation Logic
Use the session for shared understanding. Contributions are collected visibly, assumptions are aligned, and open differences remain traceable in the artifact.
Outcome Logic
The session works directly toward Cause Tree. After the session, the artifact should be shareable, reviewable, or reusable.
Input
Whiteboard or Miro board with root node at top (problem); pens; sticky notes in three colors (hypothesis, evidence, action); access to logs, metrics, configurations; timer.
Preparation
Fix problem sentence at top of board. Prepare three vertical zones (level 1, 2, 3) for branching depth. State rule: every hypothesis needs evidence, every path ends either at controllable cause or unverified assumption.
Agenda
-
Phase 1: Formulate problem precisely (10-15 min) Owner: Facilitator Action: Write problem as observable symptom in one sentence: what, when, how often, which effect. No cause in sentence. Formulate success picture for analysis. Hint: If sentence contains "because X", diagnosis is already made and tree no longer works. Reformulate. Output: Cause Tree
-
Phase 2: Branch causes (30-60 min) Owner: Facilitator Action: One branch per possible cause. On level 1, main categories (for example software, data, infrastructure, process). On levels 2 and 3, concrete hypotheses. Hint: Require at least three main branches, otherwise tree becomes one-sided. If a branch remains empty, explicitly mark as consciously empty with rationale. Output: Evidence Notes
-
Phase 3: Add evidence (30-45 min) Owner: Facilitator Action: Stick yellow evidence note per hypothesis: log, graph, config line or test result. If no evidence available, red unverified note and spike task. Hint: Evidence is checked live during session where possible. With operator present, many hypotheses can be refuted or confirmed immediately. Output: Gegenmaßnahmen
-
Phase 4: Prioritize and actions (20-30 min) Owner: Owner Action: Rate paths by probability and leverage (for example traffic light). Concrete action with owner and date per top path. Explicitly separate detection actions from cause correction. Hint: Improving monitoring is detection, not cause correction. Note both, clearly separated. Output: Cause Tree
-
Publish artifact (10 min) Owner: Owner Action: Check the artifact for completeness, define location, set version or status, and name review recipients. Output: Cause Tree
Closeout
- Update result artifact: Cause Tree
- Define location, version, and review recipients.
- Define owner, next step, and review date.
Work artifact
Pre-filled starting point based on the matching template.
work-artifact.md
Cause Tree: Root Cause Tree Analysis
Working Question
Which causal paths lead from observed problem to controllable causes, and which actions address the most likely paths?
Context
Problem sentence with timestamp and impact; known workarounds; available data sources; incident ID; list of suspected causes from group gut feeling.
Participants
- Owner: One facilitator who guides branching and asks for evidence
- Participants: One facilitator who guides branching and asks for evidence; three to eight participants with system contact; one scribe for evidence column; if needed one data operator who runs live queries.
Input
Whiteboard or Miro board with root node at top (problem); pens; sticky notes in three colors (hypothesis, evidence, action); access to logs, metrics, configurations; timer.
Template
Root Cause Tree Analysis Working Template
Goal
Trace a problem into branching causes until the most likely root causes become visible.
Context
Which problem should the group analyze, and what evidence is available?
Input
- Problem statement:
- Observations:
- Data or logs:
- Known constraints:
Working area
- Branch 1:
- Branch 2:
- Branch 3:
- Evidence and uncertainties:
- Likely root causes:
Output artifacts
- Cause tree:
- Evidence notes:
- Countermeasures:
Open questions
- ...
Decision / next step
Owner, date, and success signal.
Completion Check
- Cause Tree is complete enough for review:
- Location:
- Version / status:
- Review by:
- Next step:
Next Step
- Review result
- Mark open questions
- Schedule review or decision
Root Cause Tree Analysis Working Template
View templateCompact working template for Root Cause Tree Analysis with branching causes, evidence, and countermeasures.canvas
root-cause-tree-analysis-working-template.md
Compact working template for Root Cause Tree Analysis with branching causes, evidence, and countermeasures.
Root Cause Tree Analysis Working Template
Goal
Trace a problem into branching causes until the most likely root causes become visible.
Context
Which problem should the group analyze, and what evidence is available?
Input
- Problem statement:
- Observations:
- Data or logs:
- Known constraints:
Working area
- Branch 1:
- Branch 2:
- Branch 3:
- Evidence and uncertainties:
- Likely root causes:
Output artifacts
- Cause tree:
- Evidence notes:
- Countermeasures:
Open questions
- ...
Decision / next step
Owner, date, and success signal.
- Working question, owner, and target artifact are visible.
- The result fits Cause Tree.
- Own entry per incident with date and incident ID. Later findings as update section at end; do not delete falsified paths, mark as refuted with evidence.
- Open questions are noted as follow-ups.
- The next review or decision point is scheduled.