Tell me about a time a post-incident review started looking for someone to blame.
answer
- the incident and who was in the room
- the moment it turned personal
- the reframe you said aloud
- mechanism questions, not names
- actions owned, trust measured later
basics
~20 sTests whether you can hold a review on mechanisms rather than people. Name the moment it turned personal, the reframe you said out loud, the system questions you asked instead, and the trust that showed up afterwards.
how to answer
6 beats- the incident and who was in the roomOne or two sentences on what broke and which groups were present, because the politics of the room is the whole difficulty here. Keep setup to about a fifth of your airtime.
- the moment the review turned personalGive the specific turn: a question asked, a name floated, a demand for someone to be removed. Report it neutrally rather than characterising the person who asked.
- the reframe you said out loudQuote yourself roughly. A reframe you only thought is not evidence of anything, and this sentence is the single most valuable thing in the answer.
- the mechanism questions you asked insteadThis beat carries most of the airtime with the previous one. Give two or three actual questions about conditions, guards and defaults, and the answer that landed hardest with the room.
- the commitments and how they were written upName owned actions with dates, and say who wrote the review, who it went to, and whether individuals were named in it. The write-up decision is where senior judgement shows.
- what changed in later incidentsClose in the last fifth with evidence: a restore-time change if you have one, and a behavioural change such as people escalating earlier. The behavioural proof is usually the stronger of the two.
your answer
5 story prompts- Pick a review you facilitated or steered, not one you merely attended.
- Have the exact sentence you said when the room turned toward a person.
- Name one guardrail that came out of it, with the person who owned it.
- Prefer an incident where you or your team were at least partly the cause.
- Bring one behavioural change from afterwards, not only a restore-time number.
draft and rehearse your own answer in a learn session
go deeper
The axis is trust-building and systems thinking under group pressure. Interviewers use this to see whether you can protect people in a room that wants a culprit while still leaving with real accountability. A strong answer shows a reframe said out loud, mechanisms surfaced instead of names, owned follow-up actions, and behaviour that visibly changed afterwards.
We shared a platform with a client's networking group. Our consultancy owned the compute side, they owned the fabric. A routing change during a maintenance window took out an availability zone for their internal services, and the joint review the next morning opened with their manager asking, twice, who had typed the drain command. I was facilitating, so I said it out loud. The person who ran that command ran a documented procedure on a cluster that let it succeed, and if we spend this hour on the name we will not spend it on the guard. Then I asked three questions about conditions instead: why the procedure never checked for a second failure domain, why the dashboard stayed green for eleven minutes after the drain, and who else could have run the same command that week without knowing any better. The answer to the last one was nine people. That landed harder in the room than any name would have. We left with three actions, each with an owner and a date. I wrote the review up with roles rather than names, sent it to their manager first, and asked him to circulate it himself so it read as a joint document rather than as a vendor defending itself. Restore time on that class of outage fell from 74 minutes to 29 over the next quarter. Their networking lead started inviting our engineers to reviews we had no part in, which was the part I actually wanted.
The reframe is quoted aloud, which is what makes this a facilitation answer rather than a description of blameless culture. The nine-people question converts a person into a system in one move. Lecturing the room about blamelessness while changing nothing would downlevel it.
I was responsible for how seventeen consultants ran incident reviews across five client accounts. The pattern was not that people were cruel. It was that our reviews went to the client as a deliverable, so every one of them was quietly written as a defence of the invoice, and defences need someone else to be at fault. I changed three things. Reviews are facilitated by someone from a different account, so the facilitator has no stake in the conclusion. The person closest to the trigger writes the timeline and never writes the conclusion. And nothing that leaves the room names an individual on either side, only roles. I took that last one to the client leads myself, before it was a rule rather than after, because a rule like that looks like cover if you announce it once you need it. The expensive part was going first. On an outage where we genuinely were the cause, I published a review that named our missing guardrail in plain terms and softened nothing. That bought me the standing to ask their groups for the same. Across nine engagements, median restore time went from 68 minutes to 27, mostly because reviews started producing guardrails instead of promises to be more careful. Client attendance at joint reviews went from two accounts to eight. The test I use now is whether someone who caused an outage pages us early next time. People used to wait an hour hoping it would clear. That hour was what blame actually cost us.
Principal signal: a mechanism other people run without him, an incentive identified as the root cause, and a cost paid first to make the rule credible. The early-paging test is a real trust metric rather than a slogan. A policy with no evidence of changed behaviour would downlevel it.
Rarely aimed at this level, but a participant's view answers it: you gave an honest account of your own actions and asked a question that pulled the room back to what the system allowed.
Show that you noticed the turn and did something small and concrete: restating the trigger as a condition, offering your own part first, asking what would have stopped anyone else doing the same thing.
You are expected to have facilitated. Name the reframe you used, the mechanism questions that followed it, and the owned actions with dates that came out of the room, plus what you saw change in later incidents.
Scope is the review practice itself across teams: the standard, who facilitates, what gets written about individuals in anything client- or exec-facing, and the incentive that made blame attractive in the first place.
saying these in an interview costs you the question
- Describing blameless culture as a belief with no action attached
- Letting the room hunt and reporting it as a lesson learned
- Blameless used as a shield against any follow-up or accountability
- No owned actions or dates coming out of the review
- Quietly protecting your own team while leaving the other side exposed
- A reframe you thought but never actually said in the room
- What if the person pushing for a name had kept pushing?Do not claim a reframe always works. Show the escalation you actually have: take the naming conversation out of the room and into a one-to-one, agree that individual performance is a management topic and not a review topic, and keep the review's output about mechanisms. If the pressure comes from an executive or a client, say how you protected the person while still giving that person something real.
- Where is the line between blameless and no accountability?Answer with the distinction rather than a slogan. Blameless means the timeline is reconstructed without punishment, so people tell the truth quickly. Accountability lives in the actions: named owners, dates, and follow-up that someone chases. Repeated behaviour after a clear guardrail is a management conversation, not a review conversation. Interviewers are listening for whether you have both halves.
- How do you know the follow-up actions actually got done?Be concrete. Actions with a single named owner, tracked where the team already looks, a standing review of open incident actions, and a willingness to reopen the review when nothing moved. If your honest answer is that some actions rotted, say so and say what you changed. Interviewers hear the perfect version often enough to distrust it.
## What the prompt separates This prompt separates people who have read about blameless post-mortems from people who have run one when the room did not want to be blameless. Everyone can recite the principle. The interviewer is listening for a sentence you actually said out loud while someone senior was asking for a name. ## Common wordings - *Tell me about a difficult post-mortem you ran* - *how do you keep a review blameless when leadership wants accountability* - *tell me about a review where the conclusion was wrong* - and in vendor or partner contexts *how do you run an incident review with another organisation in the room*. The cross-organisation version is the hardest and the most revealing, because the incentives to blame outward are strongest there. ## What the strong answer contains that the weak one does not Three things. 1. **First, a quoted reframe:** the words you used to move the room from the person to the condition. 2. **Second, mechanism questions**, which are the practical form of the principle. The most powerful one is usually a variant of *how many other people could have done exactly this, this week, without knowing any better* — the answer is never one, and the number does the argument for you. 3. **Third, evidence that behaviour changed later**, which is what distinguishes a facilitation skill from a facilitation opinion. ## The subtle failure: blameless as a shield A meaningful minority of candidates use this prompt to explain that they never assign responsibility, and their answer has no owners, no dates and no follow-through. That reads worse than a blame-hunting review, because it looks like an organisation where nothing gets fixed and nobody may say so. Keep the two halves explicit: - the **timeline** is blameless so that it is true; - the **actions** are owned so that they happen. Repeated behaviour after a clear guardrail exists is a management conversation held elsewhere, and saying that plainly reassures interviewers who worry blameless means consequence-free. ## Writing is part of the answer Who writes the review, who it is sent to, and whether individuals are named in it are all decisions with consequences, especially when the document leaves the team. Reviews written with **roles instead of names** travel better and get read by people who were not there. A candidate who mentions handing the write-up to the other side to circulate, rather than publishing it themselves, is telling you they understand that a review can read as a defence of your own position no matter how honest it is. ## How the bar moves - **Middle-band engineers** are credited for noticing the turn and interrupting it in a small way. - **Senior engineers** are expected to have facilitated, to have produced owned actions, and to be able to point at a metric or a behaviour that moved afterwards. - **Principal candidates** are expected to have changed the practice rather than one meeting: who facilitates, what may be written, how actions are tracked, and what incentive was making blame attractive. ## The best closing evidence is behavioural, not numeric Restore time falling is good. People paging earlier, admitting the change they made without being asked, or volunteering to write the timeline is better, because it is the thing blame actually costs an organisation and the thing you cannot fake in a meeting.