← Crews

Validated in Zero · Reliability engineering

Incident Analysis

Blameless production-incident analysis with sourced timelines, competing hypotheses, response review, and verifiable corrective actions.

Load

./scripts/load-crew.sh --restart ../CrewDefine/crews/incident-analysis

Sample prompt

Analyze the supplied alerts, logs, deployment records, tickets, transcripts, and runbooks. Reconstruct a sourced timeline, compare causal hypotheses, quantify detection and response intervals, and audit corrective actions for ownership and verifiability.

Outputs

  • Incident Brief
  • Review Memo
  • Full Incident Analysis
  • Corrective Action Plan
  • Reliability Roadmap

Tools

validate information sufficiency · generate followup questions · document · knowledge base · web search · scrape website · calculator · visualizer · extract citations structured · event timeline builder · causal hypothesis matrix · action item validator

Roster

  • Incident Analysis Director director — Scope, sufficiency checks, blameless constraints, and coordination
  • Timeline Analyst specialist — Ordered events, timestamp conflicts, gaps, and source coverage
  • Telemetry Analyst specialist — Metrics, logs, alerts, anomalies, and impact quantification
  • Change Analyst specialist — Deployments, configuration changes, and external dependencies
  • Systems Analyst specialist — Architecture conditions and evidence-linked causal hypotheses
  • Response Analyst specialist — Detection latency, escalation, response timing, and runbook performance
  • Corrective Action Reviewer specialist — Ownership, verifiability, duplication, and failure-mode coverage
  • Incident Report Synthesizer synthesizer — Blameless report with evidence, uncertainty, and structured actions

Generated by CrewDefine · validated and instantiated in Zero

Scope

The configuration analyzes production software and infrastructure incidents from supplied operational artifacts. Its prompts prohibit inference about individual intent or competence and require causal statements to remain hypotheses unless the evidence supports a stronger conclusion.

Deterministic tools

event_timeline_builder orders ISO-8601 events and reports invalid timestamps, conflicts, duplicates, gaps, and source coverage.

causal_hypothesis_matrix records supporting and contradicting evidence for each hypothesis. It does not select or label a root cause.

action_item_validator checks required ownership and verification fields, duplicate candidates, and coverage by failure mode. Completeness is not presented as proof of risk reduction.

Validation

The package was produced through a CrewDefine interview, passed crewdefine validate, passed Zero’s crew validator with all three plugins loaded, and instantiated through Zero’s AgentRegistry as eight agents with five output modes.

Load

cd Zero
./scripts/load-crew.sh --restart ../CrewDefine/crews/incident-analysis