AI toolkit · free download
Your only record of the incident is a chat thread
Paste the thread, the alerts and the deploy log. Get a numbered timeline and a postmortem you can send.
The incident retro pack is a free prompt pack that turns an incident chat thread into a postmortem. Paste the thread, the alerts and the deploy log into any AI assistant. You get a numbered timeline, the trigger separated from the contributing factors, and the three questions the retro is about to skip.
Who this is for
- SREs and on-call engineers who own the write-up.
- Engineering managers presenting a retro to people who were not there.
- Anyone rebuilding a timeline from a chat thread, because no tool recorded one.
Before you download. This pack runs in your environment, on your data. Nothing is sent to Perform, and Perform receives no data from it at any point. It is provided free and as is, with no warranty of any kind. It is not legal, tax, security or accounting advice, not an audit and not an attestation, and no professional relationship is created by downloading or using it. You are responsible for reviewing it before you run it and for any decision you make with its output. Licensed under Apache-2.0, which includes a disclaimer of warranties and a limitation of liability.
Anything you point it at should be treated as untrusted input, because a document, a repository or a chat thread can carry instructions aimed at a model.
Version 1.0, 28 August 2026. Security contact: privacy@totalperform.com, acknowledged within five business days.
A markdown file. Paste it into any assistant. Nothing to install.
The same pack, installed once and there every time.
The problem
- Three people were typing at once. Two timestamps are somebody remembering later.
- Fifteen quiet minutes in the middle were one person in a terminal, and the thread shows nothing.
- The cause got named at minute forty, the rollback worked, and that became a fact.
- Eight action items now inherit a story nobody tested.
What it does about it
- Numbers every timeline row: so the analysis can point at row 14 and mean it.
- Separates events from beliefs: the gap between them is usually the finding.
- Finds five moments, not four: including when the person who could fix it learned an incident was running.
- Records how the cause was confirmed: if the only evidence is that the rollback worked, the write-up says so.
- Names the three skipped questions: the near miss, the blast radius nobody checked, the decision nobody made.
Two minutes to first output
- Strip customer names from the thread.
- Paste the pack, the thread, the alerts and the deploy log.
- Check the timeline before the analysis.
What it will not do
- Invent a time. Where the thread is silent, the timeline says unknown.
- Fetch the earlier write-up when the thread says this happened before. It makes that an action.
- Agree the actions for you. The table ships as proposed, with owners you still have to confirm.
| What you paste | Chat thread, alerts, deploy log |
|---|---|
| What comes back | Numbered timeline, trigger with its confidence, contributing factors, three skipped questions, proposed actions |
| Time | Under two minutes |
| Where it runs | Your assistant, on your machine |
| Tested against | A real-shape 44-minute incident thread. Four rounds of practitioner testing. |
30 minutes with the engineer who would do the work.