Post-Incident Review (Hotwash)¶
After-action review — instantiates Acute Stabilization Command
Convenes responders while the incident is still fresh for a blameless walk-through that converts the just-lived event into durable, shareable lessons under explicitly non-punitive ground rules.
An incident that ends without a review teaches nothing and will happen again; a review that assigns blame teaches people to hide, and teaches even less. Post-Incident Review (Hotwash) is the debrief that avoids both — held while the event is still "hot" and memory is sharp, it walks the responders through what happened under an explicit no-blame, learning-only ground rule. The defining feature is that this psychological safety is not a nicety but the working part of the mechanism: candor is the raw material, and the blameless frame is what produces it. It is not the technical root-cause analysis (a separate, deeper track), and it is not the live decision log — it is the ritual that turns a survived incident into organizational learning.
Example¶
Shortly after a wildfire response de-escalates, the agencies involved hold a hotwash. Everyone from dispatch to field crews sits together while the timeline is walked end to end: what worked, what nearly failed, what surprised people. The ground rule, stated up front, is that this is for learning, not fault — so a dispatcher can safely volunteer that two agencies were on conflicting radio frequencies for the first hour without it becoming a disciplinary matter. Because it is held immediately, people still remember the small decisions that a week later would blur. The output is not a fat report but a short list of concrete changes — fix the frequency-assignment step, add a checklist item — each with an owner.[1] The value came from the candor, and the candor came from the ground rules.
How it works¶
What distinguishes a hotwash from a formal investigation is timing, framing, and output:
- Held hot. It runs immediately after de-escalation, while perishable detail — the near-misses, the judgment calls — is still recoverable.
- Blameless facilitation is the mechanism. The non-punitive ground rules are not decoration; they are the thing that lets people tell the truth, and enforcing them is the facilitator's main job.
- Timeline-based, everyone present. The group reconstructs the sequence together, surfacing what one person saw and another didn't.
- A few real changes, with owners. The product is a short set of actionable improvements someone owns — not a document filed and forgotten.
Tuning parameters¶
- Timing — an immediate hotwash vs. a later, more considered review; immediacy preserves detail, delay adds perspective. Often both, in sequence.
- Attendee scope — just the core responders vs. every touchpoint; broader surfaces more but is harder to keep candid.
- Blameless strictness — how firmly fault is kept out of the room, including any legal-privilege stance; stricter protects candor but can feel evasive if overdone.
- Facilitation — a neutral facilitator vs. the commander leading; neutrality protects openness, especially where a hierarchy was involved.
- Output format — a handful of tracked actions vs. a full written report; actions drive change, reports drive record.
When it helps, and when it misleads¶
Its strength is capturing perishable lessons before they fade and building a culture where people surface problems instead of burying them — the blameless frame is exactly what makes that possible.
It misleads when it becomes theater: a review that generates a document and no change, run because the process requires one. If blame leaks in even once, candor collapses and may not return for a long time. Teams sometimes confuse the hotwash with root-cause analysis and skip the deeper technical diagnosis because "we did the review." And legal caution can be dialed so high that no one says anything useful. The classic misuse is running it backwards — convening the review to build a case against someone rather than to learn. The discipline that guards against it is enforced blameless ground rules, neutral facilitation, follow-through that tracks the actions to done, and keeping the hotwash structurally separate from any accountability or HR process.
How it implements the components¶
Post-Incident Review (Hotwash) fills the learning-and-safety components — what an after-action review operates:
after_action_learning_trigger— the hotwash is the trigger that fires the learning loop the moment the acute phase closes, converting the event into owned improvements.psychological_safety_and_fatigue_guard— the blameless, non-punitive ground rules are the mechanism's engine, protecting the candor on which the whole review depends.
It does not perform or hand off the technical root-cause diagnosis — that is the Root-Cause Analysis Handoff — and it does not run the live coordination space or its on-the-record constraints during the incident, which is the War Room / Incident Channel.
Related¶
- Instantiates: Acute Stabilization Command — the hotwash is the regime's learning exit, closing the loop the acute phase opened.
- Consumes: the Incident Action Log for the timeline it walks, and the Root-Cause Analysis Handoff register, which it checks was actually worked.
- Sibling mechanisms: Root-Cause Analysis Handoff · War Room / Incident Channel · Incident Action Log · Common Operating Picture Board · Containment or Rollback Action · Deactivation Checklist · Incident Command System · Incident Response Runbook · On-Call Rotation Activation · Reversible Service Degradation · Severity Matrix Activation · Status Update Cadence · Triage & Prioritization Protocol
Notes¶
The hotwash and the root-cause analysis are complementary, not substitutes. The hotwash is broad, human, and immediate — how did we respond, what should change. The RCA is deep, technical, and slower — what actually failed and why. Doing one does not discharge the other; treating the review as if it settled the technical cause is how the same root cause returns.
References¶
[1] The "hot wash" is the immediate after-action debrief drawn from military and emergency-management practice; the "blameless postmortem" — reviewing an incident to learn without assigning individual fault — is its widely adopted counterpart in site-reliability engineering culture. Both rest on the same premise: candor requires safety from punishment. ↩