Simulation After-Action Report
Purpose: Document lessons learned and prevention plans after mock incident response drills. Close the loop and improve future response.
Simulation Summary
Basic Information
- Simulation ID:
simulation-[YYYY-MM-DD]-[id] - Simulation title: [scenario name]
- Simulation date: YYYY-MM-DD
- Simulation start time: HH:MM
- Simulation end time: HH:MM
- Simulation duration: ____ hours
- Simulation observer: @username
- Simulation team: [list of team members]
- Simulation score: ____/5 (out of 5 success criteria)
Scenario Summary
- Simulation trigger: What caused the simulation?
- Expected impact: What should the team see?
- Actual impact: What actually happened?
- Resolution: Was resolution achieved?
- Status: Resolved / Escalated / Aborted
Performance Assessment
Success Criteria Evaluation
| Success Criterion | Expected | Actual | Met | Notes |
|---|---|---|---|---|
| Playbook selected correctly | Yes | ____ | ⬜ / ✅ | [notes] |
| Escalation triggered on time | Yes | ____ | ⬜ / ✅ | [notes] |
| Communications up-to-date | Yes | ____ | ⬜ / ✅ | [notes] |
| No major errors | Yes | ____ | ⬜ / ✅ | [notes] |
| Post-mortem documented | Yes | ____ | ⬜ / ✅ | [notes] |
Overall Rating
- Playbook Selection: Excellent / Good / Needs Improvement
- Escalation Process: Excellent / Good / Needs Improvement
- Communication: Excellent / Good / Needs Improvement
- Team Performance: Excellent / Good / Needs Improvement
- Overall Simulation: Excellent / Good / Needs Improvement
What Went Well
Strengths
1. [Strength 1]: - Example: First responder acknowledged within 2 minutes - Impact: Reduced initial response time
2. [Strength 2]: - Example: Playbook selected correctly without confusion - Impact: Clear path to resolution
3. [Strength 3]: - Example: Slack updates consistent and timely - Impact: Stakeholders informed
4. [Strength 4]: - Example: Team communicated clearly and concisely - Impact: Reduced confusion
5. [Strength 5]: - Example: Root cause identified quickly - Impact: Faster resolution
What Needs Improvement
Gaps Identified
1. [Gap 1]: - Example: Escalation to Tier 2 delayed by 5 minutes - Impact: Prolonged initial response time - Severity: Minor / Medium / Major
2. [Gap 2]: - Example: Customer comms plan not prepared before resolution - Impact: Delayed customer notification - Severity: Minor / Medium / Major
3. [Gap 3]: - Example: Timeline documentation incomplete - Impact: Post-mortem harder to write - Severity: Minor / Medium / Major
4. [Gap 4]: - Example: Tools not accessible during simulation - Impact: Delayed investigation - Severity: Minor / Medium / Major
5. [Gap 5]: - Example: Team unclear about roles during Tier 2 - Impact: Confusion, slower resolution - Severity: Minor / Medium / Major
Root Cause Analysis
Why These Gaps Occurred
#### Gap 1: Escalation Delayed Root Cause: [identify root cause]
- Contributing factors:
- [list contributing factors]
- Evidence: [document evidence]
- Pattern: [is this recurring?]
#### Gap 2: Customer Comms Not Prepared Root Cause: [identify root cause]
- Contributing factors:
- [list contributing factors]
- Evidence: [document evidence]
- Pattern: [is this recurring?]
#### Gap 3: Timeline Incomplete Root Cause: [identify root cause]
- Contributing factors:
- [list contributing factors]
- Evidence: [document evidence]
- Pattern: [is this recurring?]
#### Gap 4: Tools Not Accessible Root Cause: [identify root cause]
- Contributing factors:
- [list contributing factors]
- Evidence: [document evidence]
- Pattern: [is this recurring?]
#### Gap 5: Role Confusion Root Cause: [identify root cause]
- Contributing factors:
- [list contributing factors]
- Evidence: [document evidence]
- Pattern: [is this recurring?]
Prevention Plan
Action Items
#### Action 1: [Immediate Fix]
- Issue: [gap summary]
- Prevention plan: [what will you do to prevent this?]
- Owner: @username
- Deadline: [date]
- Status: Pending / In Progress / Complete
#### Action 2: [Immediate Fix]
- Issue: [gap summary]
- Prevention plan: [what will you do to prevent this?]
- Owner: @username
- Deadline: [date]
- Status: Pending / In Progress / Complete
#### Action 3: [Immediate Fix]
- Issue: [gap summary]
- Prevention plan: [what will you do to prevent this?]
- Owner: @username
- Deadline: [date]
- Status: Pending / In Progress / Complete
#### Action 4: [Immediate Fix]
- Issue: [gap summary]
- Prevention plan: [what will you do to prevent this?]
- Owner: @username
- Deadline: [date]
- Status: Pending / In Progress / Complete
#### Action 5: [Immediate Fix]
- Issue: [gap summary]
- Prevention plan: [what will you do to prevent this?]
- Owner: @username
- Deadline: [date]
- Status: Pending / In Progress / Complete
Future Simulation Planning
Next Simulation
- Recommended interval: [weeks/months]
- Scenario recommendation: [scenario to simulate]
- Objectives: [focus on identified gaps]
- Team: [same team or new team]
Process Improvements
- ☐ Playbook selection process: Review and update playbooks based on findings
- ☐ Escalation process: Adjust escalation thresholds or communication paths
- ☐ Communication cadence: Update Slack update frequency
- ☐ Tools: Improve tool accessibility or documentation
- ☐ Training: Schedule training based on identified gaps
Documentation Improvements
- ☐ Incident timeline template: Update based on gaps
- ☐ Post-mortem template: Refine based on gaps
- ☐ Simulation preparation checklist: Update based on gaps
- ☐ On-call rotation: Adjust if role confusion occurred
Lessons Learned
Key Takeaways
1. [Lesson 1]: - What happened: [summary] - What it means: [implication] - How to apply: [action]
2. [Lesson 2]: - What happened: [summary] - What it means: [implication] - How to apply: [action]
3. [Lesson 3]: - What happened: [summary] - What it means: [implication] - How to apply: [action]
4. [Lesson 4]: - What happened: [summary] - What it means: [implication] - How to apply: [action]
5. [Lesson 5]: - What happened: [summary] - What it means: [implication] - How to apply: [action]
Recommendations
For Team
- ☐ Improve role clarity: Review and clarify roles and responsibilities
- ☐ Faster response: Reduce initial response time to ≤ 5 minutes
- ☐ Better communication: Ensure updates every 15 minutes (Tier 1)
- ☐ Enhanced playbooks: Add missing playbooks, clarify ambiguous ones
- ☐ Tool access: Ensure tools are accessible during incidents
For Process
- ☐ Escalation process: Review and adjust escalation thresholds
- ☐ Communication plan: Create customer comms plans before resolving incidents
- ☐ Documentation: Improve timeline and post-mortem quality
- ☐ Simulation frequency: Schedule more simulations (e.g., monthly)
- ☐ Continuous improvement: Use simulation data to drive process improvements
For Management
- ☐ Resources: Allocate resources for tooling, training, documentation
- ☐ Time: Allocate time for post-mortems and prevention plan
- ☐ Training budget: Budget for training sessions based on gaps
- ☐ Process changes: Approve and implement process improvements
Appendices
Appendix A: Simulation Observations
[Full observation log]
Appendix B: Timing Log
[Full timing documentation]
Appendix C: Decision Log
[Full decision log]
Appendix D: Error Log
[Full error log]
Distribution
- Created by: @username
- Date: YYYY-MM-DD
- Reviewed by: @username
- Approved by: @username
- Action items tracked in: [project management tool]
Usage: Use after every simulation to document findings, identify gaps, and create prevention plan. Share with team and track action items.
Product links: /l/ops-starter-kit-vol-2 | /l/ops-starter-kit | /l/automation-starter-pack
From the HIVE80lab kit
- The First 30 Minutes — free incident quick-start
- Ops Starter Kit — full incident-response kit for small teams — $14
- Ops Mega Bundle — all 5 kits in one download — $29
- Small-Team Ops Audit — prioritized findings + fix plan, five-day turnaround — $149
- Custom Incident Runbook — done-for-you, built from your estate, 48h — $249
Part of the five-pillar incident-response set: see the pillars overview and the blameless post-incident review template.