For two years our postmortems opened with a name. Then we noticed everyone had started writing shorter, vaguer incident reports.
The first question in every retro used to be "who pushed the change." It felt efficient. It was also quietly training every engineer at Helix to write postmortems that said as little as possible.
"I stopped mentioning that I'd ignored the staging warning, because the last time someone admitted that, it ended up in their performance review." — anonymous engineer, internal culture survey, 2025
The question that trained us to lie
Blame doesn't show up as shouting in a meeting. It shows up as omission. We pulled eighteen months of postmortems and found a pattern: the ones written within 24 hours of an incident were on average 40% shorter than the ones written a week later, and they contained far fewer first-person sentences like "I assumed" or "I didn't check." People were writing to protect themselves, not to help the next on-call engineer.
What we ask instead
We rewrote the retro opener. It no longer asks who did what. It asks what the system made easy to get wrong.
## Retro opener (read aloud before any discussion)
1. What did the system make it easy to do, that turned out to be wrong?
2. What information was available but not visible at decision time?
3. What would a reasonable, well-rested engineer have done with what
they knew, at that moment?
No names in step 1-3. Names only appear in the timeline, factually,
without judgment words attached.
The shift sounds cosmetic. It wasn't. Within two quarters, the average postmortem grew from 620 words to 1,400, and the number of concrete follow-up actions per incident nearly doubled, from 2.1 to 3.9. People will tell you the truth about a system. They will not volunteer the truth about themselves if it's going to be used against them.
The one exception we still enforce
Blameless does not mean action-less. If someone bypassed a guardrail deliberately, repeatedly, or without telling anyone, that's a conversation with their manager — outside the retro, never inside it. Keeping those two conversations physically and procedurally separate is the whole trick. The retro exists to fix the system. The manager conversation exists to support the person. Mixing them destroys both.
- Blameless postmortems fail the moment blame becomes implicit in the questions you ask first.
- Separate "fix the system" conversations from "support the person" conversations — different rooms, different owners.
- Track postmortem word count and first-person language as a leading indicator of psychological safety; it's cheap to measure and hard to fake.