Validated in Zero · Reliability engineering
Incident Analysis
Blameless production-incident analysis with sourced timelines, competing hypotheses, response review, and verifiable corrective actions.
Load
./scripts/load-crew.sh --restart ../CrewDefine/crews/incident-analysis Sample prompt
Analyze the supplied alerts, logs, deployment records, tickets, transcripts, and runbooks. Reconstruct a sourced timeline, compare causal hypotheses, quantify detection and response intervals, and audit corrective actions for ownership and verifiability.
Outputs
- Incident Brief
- Review Memo
- Full Incident Analysis
- Corrective Action Plan
- Reliability Roadmap
Tools
validate information sufficiency · generate followup questions · document · knowledge base · web search · scrape website · calculator · visualizer · extract citations structured · event timeline builder · causal hypothesis matrix · action item validator
Roster
- Incident Analysis Director director — Scope, sufficiency checks, blameless constraints, and coordination
- Timeline Analyst specialist — Ordered events, timestamp conflicts, gaps, and source coverage
- Telemetry Analyst specialist — Metrics, logs, alerts, anomalies, and impact quantification
- Change Analyst specialist — Deployments, configuration changes, and external dependencies
- Systems Analyst specialist — Architecture conditions and evidence-linked causal hypotheses
- Response Analyst specialist — Detection latency, escalation, response timing, and runbook performance
- Corrective Action Reviewer specialist — Ownership, verifiability, duplication, and failure-mode coverage
- Incident Report Synthesizer synthesizer — Blameless report with evidence, uncertainty, and structured actions
Generated by CrewDefine · validated and instantiated in Zero
Scope
The configuration analyzes production software and infrastructure incidents from supplied operational artifacts. Its prompts prohibit inference about individual intent or competence and require causal statements to remain hypotheses unless the evidence supports a stronger conclusion.
Deterministic tools
event_timeline_builder orders ISO-8601 events and reports invalid timestamps, conflicts,
duplicates, gaps, and source coverage.
causal_hypothesis_matrix records supporting and contradicting evidence for each hypothesis. It
does not select or label a root cause.
action_item_validator checks required ownership and verification fields, duplicate candidates,
and coverage by failure mode. Completeness is not presented as proof of risk reduction.
Validation
The package was produced through a CrewDefine interview, passed crewdefine validate, passed Zero’s
crew validator with all three plugins loaded, and instantiated through Zero’s AgentRegistry as
eight agents with five output modes.
Load
cd Zero
./scripts/load-crew.sh --restart ../CrewDefine/crews/incident-analysis