What problem does it solve? After an incident or failed outcome, teams often produce postmortems that assign blame, assert unsupported root causes, or list corrective actions nobody can verify. This Skill reconstructs the event strictly from evidence, separates observation from interpretation, and produces a defensible report whose corrective actions map to causal findings with observable verification signals. ## Core Features & Use Cases - Evidence-linked timeline and source audit: Inventories every log, record, interview, and policy with coverage gaps and conflicts, then builds a timeline where each event carries a stable ID, source locator, and confidence level. - Rigorous causal and safeguard analysis: Distinguishes observations, interpretations, contributing factors, and root causes; analyzes detection, response, and safeguards that succeeded, failed, were bypassed, or were absent; returns "no defensible root cause established" when evidence is inadequate. - Verifiable corrective-action ledger: Maps every action to causal findings with verification signals, windows, expected risk reduction, and residual risk, while refusing to invent owners, dates, or approvals. - Use Case: After a production outage, supply the incident window, timezone, and authorized log sources; receive a blameless report with a sourced timeline, competing accounts preserved, safeguard failures explained, and corrective actions each tied to a finding and a verification signal. ## Quick Start Run a postmortem on last Tuesday's payment-service outage using the attached logs and incident channel export, with window=2024-06-11T14:00 to 2024-06-12T02:00, timezone=UTC, and sensitivity=restricted.