Prompts / Operations & Project Management

ChatGPT prompt for an incident report template

This prompt produces a factual incident report that helps people understand what happened and what changes next. Use it after stabilizing an operational, service, or workplace incident.

PromptOpen ChatGPTOpen Claude
Write a factual incident report from the verified materials below. Use a learning-oriented, non-blaming tone. Do not identify fault, infer intent, disclose sensitive personal information, or state a root cause as confirmed unless the evidence supports it. This report supports follow-up; it does not replace legal, safety, HR, security, or medical reporting requirements.

Incident scope and audience: [INCIDENT SCOPE]
Verified timeline, including time zone: [VERIFIED TIMELINE]
Impact and affected people, systems, or operations: [IMPACT]
Response actions and communications already taken: [RESPONSE ACTIONS]
Evidence, contributing factors, and unresolved questions: [EVIDENCE AND QUESTIONS]

Produce a 700–1,000 word report with these sections: Incident summary; impact; detection; timeline; response and recovery; contributing factors; root-cause status; corrective and preventive actions; communications; and open questions. Start with a concise summary stating what happened, when, current status, and the known impact. Build the timeline from timestamped events in chronological order, separating observed events from decisions and actions.

For contributing factors, distinguish confirmed factors from hypotheses requiring investigation. For every action item, give the action, owner, due date only if supplied, verification method, and status. Include immediate containment separately from longer-term prevention. State which stakeholders were notified and when, but do not draft legal conclusions or external statements unless provided.

Before answering, check that the timeline has no unexplained gaps or conflicting times and that every corrective action has an owner or is explicitly marked unassigned. Flag missing severity criteria, evidence gaps, and unconfirmed root-cause claims. Ask up to three clarifying questions only if a required input is missing.

Fill in

PlaceholderWhat to enterExample
[INCIDENT SCOPE]Describe the incident type, report audience, location or system, and current status.Customer portal outage for Operations leadership; web application; service restored and monitoring continues.
[VERIFIED TIMELINE]List timestamped, verified events in one time zone.09:07 ET error rate increased; 09:12 alert fired; 09:18 on-call acknowledged; 09:34 traffic shifted; 09:46 portal recovered.
[IMPACT]Describe confirmed effects on people, systems, customers, operations, or data.Portal login failed for approximately 38 minutes; no evidence of data loss; support received 17 related tickets.
[RESPONSE ACTIONS]List containment, recovery, communications, and decisions already completed.On-call shifted traffic to the prior deployment, posted a status-page update at 09:26, and notified Support at 09:29.
[EVIDENCE AND QUESTIONS]Provide logs, observations, contributing factors, action owners, and unresolved questions.Logs show errors began after deployment 482. Database latency was normal. Priya owns rollback validation; root cause is still under investigation.

How to use

  1. Collect timestamps from logs, tickets, and responders, then normalize them to one time zone.
  2. Paste only verified facts and distinguish observations from hypotheses.
  3. Check that action items have a verification method and that the impact is bounded by evidence.
  4. Send: “Convert these open questions into an investigation plan with evidence needed, owner, and decision date: [QUESTIONS].”

Variations

Incident timeline

Use when you need a clean chronology before the full report.

Variation
Build a verified incident timeline from [RAW EVENTS] for [INCIDENT]. Normalize all entries to [TIME ZONE]. Return a table with timestamp, source, observed event, action or decision, owner, and confidence. Keep observed facts separate from inferred links between events. Identify duplicate, contradictory, or missing timestamps and list the exact question needed to resolve each. Do not fill a gap with a likely event. Check that entries are in chronological order and that every stated time includes its source or is marked unverified.

Action plan

Use after an incident review to manage corrective work.

Variation
Create an incident corrective-action plan from [FINDINGS]. Known owners and capacity constraints are [OWNERS AND CONSTRAINTS]. Return a table with action, incident risk addressed, owner, due date if supplied, priority, dependency, verification evidence, and status. Separate immediate containment, remediation, and prevention. For actions without an owner or measurable verification, mark them incomplete rather than inventing details. Add a weekly review agenda that closes actions only when verification evidence is recorded. Check for actions that duplicate one another or do not address a stated finding.

Customer update

Use when customers need a factual service-incident update.

Variation
Draft a customer incident update about [INCIDENT] using these confirmed facts: [VERIFIED FACTS]. The audience is [AUDIENCE], and the current status is [STATUS]. Return a subject line and a 120–180 word message stating impact, time window, current status, and any action customers need to take. State only confirmed cause information, and avoid blame, legal conclusions, and promised prevention work that has not been approved. Check that every time, scope, and recovery claim is supported by the supplied facts.

Tips

  • Capture the first alert, acknowledgment, mitigation, recovery, and customer-notification times before memory changes the chronology.
  • State impact as a bounded fact, such as affected service and observed duration, rather than an unverified count of all affected users.
  • A corrective action is incomplete without evidence that proves the risk was reduced or the control works.
  • Keep individual performance discussion out of the incident narrative unless a formal process requires it.

FAQ

Can AI determine the root cause from an incident timeline?

It can identify plausible hypotheses and missing evidence, but a timeline alone does not prove causation.

What belongs in an incident report?

Include verified impact, chronology, response, confirmed and unconfirmed factors, action owners, and open questions.

Can I use this for a safety or workplace incident?

It can help organize factual notes, but follow your organization’s safety, HR, legal, and regulatory procedures.

Related prompts

All Operations & Project Management prompts →

Get a few prompts like this every week

Something Big is a free AI newsletter read by 50,000+ professionals. One email a week with prompts and tools that work, plus what changed in AI and what to do about it.