skip to content

How would you tell whether a team's postmortem process is genuinely blameless rather than blameless only on paper?

level: seniorimportance: should knowfreq 42%

answer

  1. policy is free, behaviour is not
  2. who writes the document
  3. fear shows up as latency
  4. retrain the engineer is laundered blame
  5. did blame move or disappear

basics

~20 s

Watch behaviour under cost, not policy. Do people volunteer that they were the one who acted, write their own postmortems, and declare incidents early? Do remediations target systems rather than individuals? Blame that has moved out of the document and into private conversations is the usual tell.

solid answer

~50 s

I look at what people do when honesty is expensive. Four signals carry most of the weight. First, does the person who took the triggering action say so unprompted, and often write the postmortem themselves? Second, how fast do people declare incidents — hesitation to raise a hand is almost always fear of attention, and it shows up as minutes of delay you can actually measure. Third, do near-misses and self-caught mistakes get written up at all, or only outages that were impossible to hide? Fourth, read the remediation list: if it contains "retrain the engineer" or "add a reminder", blame is being laundered as process. Then I check the counter-signal — whether the document says no names while a private conversation with a manager happens afterwards. Teams learn the real rule within one incident, so declared policy is worth almost nothing next to what happened last time.

go deeper

for a junior

Be able to name a couple of observable signs — people saying openly that they made the change, and fixes aimed at the system rather than at a person.

for a middle

Contrast declared policy with behaviour, and explain why remediation items like "retrain the engineer" reveal that blame has been relabelled as process.

for a senior

Bring measurable signals — latency before escalation, whether near-misses get written up, who authors the document — and name the counter-signal of blame relocating into private management conversations.

for a principal

Own the levers that set the culture at scale: publication scope, whether names appear, who attends expensive reviews and what they say first, and how you keep safety unconditional when an outage is costly.

## Why you cannot read this off the policy Every engineering organisation with a wiki claims to run blameless postmortems. The claim is free. What a team actually believes is set by the most recent expensive incident: what happened to the person at the centre of it, and whether anyone paid a price for candour. So the question is empirical, and the evidence is behavioural. ## The signals worth trusting **People self-identify without being asked.** In a healthy review, the sentence "that was me, I ran it, here's what I was looking at" arrives early and casually. Where the culture is nominal, the timeline uses the passive voice throughout and nobody quite owns any action. Passive voice covering every consequential step is one of the most reliable smells in a draft. **The person closest to the action often writes the document.** This is a strong signal precisely because it is costly if the culture is fake. Where blame is real, that assignment is a punishment and everyone knows it. **Speed of raising a hand.** Fear shows up as latency. If people spend twenty minutes trying to quietly fix something before telling anyone, part of that delay is usually reluctance to attract attention. This is measurable — the gap between the first internal signal and the moment someone escalated — and it tends to shorten when candour stops being risky. **Small and near-miss events get written up.** A corpus containing only large, undeniable outages means the process is triggered by visibility rather than by learning. Voluntary write-ups of things that were caught in time are the clearest evidence that reporting feels safe. **Remediations point at systems.** Scan the action list. Items like "retrain the engineer", "add a reminder to the runbook", "remind the team to be careful" are blame laundered into process language: they name a person's future behaviour as the control. A healthy list is dominated by guardrails, defaults, detection and reversibility. **Language survives review.** Someone in the review actively strikes "should have", "failed to", "neglected to". If nobody ever edits for this, either the drafts are unusually good or nobody is reading them as a blameless document. ## The counter-signals **Blame that relocated rather than disappeared.** The document is scrupulously anonymous, and then the person's manager has a quiet word, or it surfaces at their next performance review. This is worse than open blame, because the team learns both that blame is real and that the process lies about it. **Attendance changes when the incident is expensive.** If a senior leader attends only the costly reviews and the room goes quiet when they do, the safety is conditional — and conditional safety is what you get during exactly the incidents that matter most. **Vagueness treated as kindness.** A document that avoids saying what actually happened, to protect someone, has sacrificed the learning to save the feelings. Blameless writing is more specific about actions and conditions, not less; it simply describes situations rather than character. **One-way flow.** Postmortems that are written but never read, never reviewed and never referenced in later work indicate a compliance ritual, whatever the tone of the language. ## Decisions that actually set the culture Three recurring choices, each with a real cost, do more than any statement of values: 1. **Do names appear in documents?** Naming with the person's consent normalises ownership when the culture is strong; enforced anonymity is the safer default when it is not — but anonymity chosen for safety should be understood as a symptom, not an achievement. 2. **How widely is the document published?** Org-wide publication maximises learning and raises the personal stakes. Many teams start narrow and widen as trust grows; the widening itself is a measurable milestone. 3. **Who is in the room, and what do they say first?** The single highest-leverage intervention is a senior person opening a review by describing their own past mistake. It costs them status and buys the room permission. ## What to say in an interview Avoid the trap of listing cultural virtues. Give the interviewer observable, ideally measurable evidence: who writes the document, whether small events appear at all, the shape of the remediation list, the latency before someone raises a hand, and the counter-signal of blame relocating into private conversations. Then name the intervention you would make first — usually funding the small write-ups and having a leader model self-disclosure — and be honest that the true test only arrives with the next expensive outage.

  • Which single intervention would you make first in a team that is blameless only on paper?
    Have a respected senior engineer or leader open a review by walking through a mistake of their own — what they saw, what they assumed, what it cost. It transfers status to candour rather than to appearing infallible, and it is the cheapest credible signal available. Policy statements from the same person achieve almost nothing by comparison.
  • Should individuals be named in postmortem documents?
    It depends on the culture you actually have. Naming with consent normalises ownership where trust is high; role-based anonymity is the safer default where it is not. Treat enforced anonymity as a symptom rather than a goal — if people would be harmed by being named, the underlying problem is what happens to named people, not the document.
  • Is a rising count of postmortems a bad sign?
    Not by itself, and early on it is usually good: it means smaller events and near-misses are now being written up instead of quietly absorbed. What matters is the mix and the trend in impact — more small learning events with flat or falling customer-visible impact is a healthy pattern, while more large outages is not.

saying these in an interview costs you the question

  • Our policy says blameless, so we are blameless
  • Nobody complained, so people must feel safe
  • No names in the doc, then a chat with the manager
  • Fewer postmortems means the culture improved
  • Being vague about what happened protects people

context