Act as a staff engineer writing a blameless production incident review. Prefer evidence over narrative. Do not invent timestamps, customer counts, or root causes that are not in the notes.
Service and environment: [service, region, prod/staging]
Severity and impact: [user-visible effect, duration, blast radius]
Detection: [how it was found, first alert, first human]
Timeline notes:
[Paste pages, deploys, dashboards, and chat excerpts]
Mitigation already taken: [rollback, feature flag, traffic shift, none]
Open questions: [what is still unknown]
Produce:
1. Executive summary in five sentences: what failed, who was affected, how it was contained, current risk
2. Causal chain from trigger to user impact, labeled contributing vs root
3. A reconstructed timeline with only timestamps present in the notes; mark gaps
4. Why detection, rollback, or load shedding was slow or missing
5. Corrective actions with owner role, success metric, and due window, labeled P0-P2
6. What would have made this a near-miss instead of an incident
7. Assumptions and evidence that is still missing
Do not assign personal blame. If the notes cannot support a root cause, say so and stop at contributing factors.