# Write the postmortem from the record

Builds the timeline from the investigation record, the Datadog queries and the GitHub history, then drafts the cause, impact and follow-ups.

## The prompt

```
I want to do this: Write the postmortem for yesterday's incident: timeline, root cause, and the follow-ups.

## Setup (skip if Polylane is already set up)

Read and follow https://polylane.com/auth.md for non-interactive signup and setup. Start by checking whether I am already signed in; reuse my account and workspace.

If the CLI is missing, bootstrap it without starting the interactive wizard:

curl -fsSL 'https://polylane.com/setup?ref=prompts' | bash -s -- --install-only

Then follow the guide through email verification, workspace selection, source connections, and MCP authentication. Ask me for an email code or OAuth consent only when needed. Verify each step; report pending setup instead of claiming success from installation alone.

## How to work

Over MCP: searchTools lists what this workspace exposes, with each tool's schema; call it first. runTool runs one tool, runCode chains several in one call and returns just the answer. search and execute cover the full Polylane REST API: threads, issues, investigations, autofixes, memories.
From the terminal: the polylane CLI wraps the same API, with structured output and non-interactive flags everywhere.
Reads always work. Write tools appear only if I have opted in, and every write is screened.

## Task: Write the postmortem from the record

Steps:
1. Pull the issue and its investigation: detection time, verdicts, evidence
2. Rebuild the timeline from the recorded events, not recollection
3. State the root cause with its evidence, and what ended the incident
4. List the follow-ups the investigation surfaced, each tied to a finding
5. Deliver the postmortem draft, every claim linked to its source

Ground every claim in data you actually pulled: the query, the log line, the change record. If the data is inconclusive, say so. Ask me before anything that writes.
```

## What it replaces

**The postmortem is homework nobody marks.** Reconstructing an incident a day later means scrolling Slack, re-running queries, and trusting memories that are already wrong. So the write-up slips, and the lessons slip with it.

- Rebuilding the timeline from Slack scrollback
- "When did it actually start?" answered three different ways
- Follow-ups that never leave the document

## What the agent does

1. Pull the issue and its investigation: detection time, verdicts, evidence
2. Rebuild the timeline from the recorded events, not recollection
3. State the root cause with its evidence, and what ended the incident
4. List the follow-ups the investigation surfaced, each tied to a finding
5. Deliver the postmortem draft, every claim linked to its source

## What you get

**The write-up writes itself from the record** A postmortem grounded in what was actually recorded, done while the incident is still warm. The review meeting argues about actions, not timestamps.

Every prompt: https://polylane.com/prompts/

Get started with one command: `curl -fsSL https://polylane.com/setup | bash` installs the CLI, connects your coding agents, and creates the account.
