---
title: Incident Postmortems
description: >-
  Generate and manage postmortems to document incidents and drive continuous
  improvement.
breadcrumbs: >-
  Docs > Incident Response > Incident Management > Post Incident > Incident
  Postmortems
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Incident Postmortems

## Overview{% #overview %}

A postmortem is a structured document that captures what happened during an incident, why it happened, and what actions to take to prevent recurrence. Generating a postmortem after an incident helps your team:

- Document root cause and impact for future reference
- Drive accountability for remediation work
- Build organizational knowledge to reduce the frequency and severity of future incidents

Datadog automatically populates postmortems with incident data using templates you define. You can generate postmortems to [Datadog Notebooks](https://docs.datadoghq.com/notebooks.md), [Confluence](https://docs.datadoghq.com/integrations/confluence.md), or [Google Drive](https://docs.datadoghq.com/integrations/google_drive.md). Postmortems generated as Datadog Notebooks embed directly in the Post-Incident tab, where you can view, edit, and track their status and ownership without leaving the incident.

## Permissions{% #permissions %}

- To generate a postmortem, you need the **Incidents Write** permission.
- To view a generated postmortem in Datadog Notebooks, you need the **Notebooks Read** permission.

{% alert level="danger" %}
For private incidents, postmortems generated in Datadog Notebooks are accessible to any user with Notebooks read permission, regardless of whether they have access to the private incident. Take this into consideration when generating postmortems for incidents that contain sensitive data.
{% /alert %}

## Generate a postmortem{% #generate-a-postmortem %}

{% image
   source="https://docs.dd-static.net/images/incident_response/incident_management/post_incident/postmortems/post_incident_tab_generate_postmortem.9ff49d439dc0659e0cd26ad7a4628d9a.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/incident_response/incident_management/post_incident/postmortems/post_incident_tab_generate_postmortem.9ff49d439dc0659e0cd26ad7a4628d9a.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="The Post-Incident tab showing the Generate Postmortem button, template preview, and Follow-Ups sidebar." /%}

After an incident is resolved, you can generate a postmortem from the incident's **Post-Incident** tab.

To generate a postmortem:

1. Open the incident and go to the **Post-Incident** tab.
1. Select a postmortem template.
1. Click **Generate Postmortem**. Datadog creates the postmortem in the destination configured in the template and links it to the incident.

### Generate a postmortem with Workflow Automation{% #generate-a-postmortem-with-workflow-automation %}

You can also generate a postmortem from a [workflow](https://docs.datadoghq.com/actions/workflows.md) using the **Generate postmortem** action. The action takes an incident and a postmortem template, and attaches the resulting postmortem to that incident. Use this path to create postmortems as part of an automated post-incident process, such as after an incident is resolved.

{% alert level="warning" %}
The AI-generated variables available to postmortem templates, such as `{{incident.ai_summary}}`, populate only for postmortems generated from the **Post-Incident** tab. A postmortem generated through the **Generate postmortem** workflow action renders these variables empty. To include AI-generated content, generate the postmortem from the **Post-Incident** tab.
{% /alert %}

For the full list of variables available to postmortem templates, see [Templates](https://docs.datadoghq.com/incident_response/incident_management/setup_and_configuration/templates.md) and [Incident variables](https://docs.datadoghq.com/incident_response/incident_management/setup_and_configuration/variables.md#incident-variables).

## View and edit a postmortem{% #view-and-edit-a-postmortem %}

View and edit your postmortem based on its destination:

- **Datadog Notebooks**: Embedded in the **Post-Incident** tab. Read and edit without leaving Datadog. Multiple users can edit simultaneously with cursor markers. Add inline comments. Changes are reflected in the underlying notebook.
- **Confluence**: Edit in Confluence (click the link in the **Post-Incident** tab to open your Confluence workspace).
- **Google Drive**: Edit in Google Docs (click the link in the **Post-Incident** tab to open Google Docs).

## Convert timestamps to date chips{% #convert-timestamps-to-date-chips %}

Postmortems often record times as plain text, such as `Jul 23, 4:30 pm UTC`. You can convert this text into [date chips](https://docs.datadoghq.com/notebooks.md#smart-chips), which display the time in each reader's own time zone.

Times in a postmortem are often recorded in different time zones by different responders. Conversion makes them uniform. As long as each time states its time zone, you do not need to standardize times by hand while drafting.

This option is available on notebooks with the **Postmortem** notebook type.

To convert timestamps in a postmortem:

1. Open the postmortem notebook.
1. Click the kebab menu in the upper right and select **Convert timestamps**.
1. Review the detected timestamps. Each entry shows the original text and the resolved time. If a timestamp has no explicit offset, Datadog interprets it in the time zone of the person performing the conversion. If it has no year, Datadog infers one.
1. Clear the checkbox for any timestamp you want to leave as plain text.
1. Click **Convert**.

{% image
   source="https://docs.dd-static.net/images/incident_response/incident_management/post_incident/postmortems/convert_timestamps.107b628bb5fef1f5b36f06c72f19fd0e.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/incident_response/incident_management/post_incident/postmortems/convert_timestamps.107b628bb5fef1f5b36f06c72f19fd0e.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="The Convert timestamps dialog listing detected timestamps with checkboxes, each showing the time it resolves to." /%}

**Note**: Datadog doesn't convert datetime text that's part of a link, such as a link to an event in the incident timeline. A date chip cannot also be a link.

## Postmortem status and owner{% #postmortem-status-and-owner %}

Postmortems have two fields to help track completion and drive accountability:

| Field      | Description                                           | Default                               |
| ---------- | ----------------------------------------------------- | ------------------------------------- |
| **Status** | The current completion state of the postmortem.       | Draft                                 |
| **Owner**  | The person responsible for completing the postmortem. | The user who generated the postmortem |

The postmortem status values are:

| Status        | Description                         |
| ------------- | ----------------------------------- |
| **Draft**     | The postmortem is in progress.      |
| **In Review** | The postmortem is ready for review. |
| **Completed** | The postmortem is finished.         |

The postmortem owner can be reassigned to any user in your Datadog organization. The owner is a system role that appears in the incident's response team alongside Incident Commander and Responder.

## Configure postmortem templates{% #configure-postmortem-templates %}

To create or manage postmortem templates, including save location and template variables, see [Templates](https://docs.datadoghq.com/incident_response/incident_management/setup_and_configuration/templates.md).

## Attach an existing postmortem{% #attach-an-existing-postmortem %}

If a postmortem for an incident already exists outside of Datadog, or was created before the incident was opened, you can link it directly from the **Post-Incident** tab without generating a new one. The linked postmortem can be any URL—a Datadog Notebook, a Confluence page, a Google Doc, or any external document.

To attach an existing postmortem, open the **Post-Incident** tab and use the **Attach existing post-mortem** option to add the link.

## Remove a postmortem{% #remove-a-postmortem %}

To remove a postmortem from an incident, open the **Post-Incident** tab, find the postmortem entry, and select the option to remove it. Removing the link does not delete the underlying document.

## Further reading{% #further-reading %}

Additional helpful documentation, links, and articles:

- [Configure postmortem templates](https://docs.datadoghq.com/incident_response/incident_management/setup_and_configuration/templates.md)
- [Incident variables reference](https://docs.datadoghq.com/incident_response/incident_management/setup_and_configuration/variables.md)
- [Manage incident follow-up tasks](https://docs.datadoghq.com/incident_response/incident_management/post_incident/follow-ups.md)
- [Datadog Notebooks](https://docs.datadoghq.com/notebooks.md)
