How to Write an After-Action Report
The exercise is only half the value. The after-action report is what turns a good discussion into an actual improvement to your organization.
Why most after-action reports fail
The most common failure mode isn't a badly written report — it's no report at all, or one so vague ("communication could be better") that nobody can act on it. A good after-action report is specific enough that someone who wasn't in the room could read it and understand exactly what happened and what needs to change.
Write it within a week
Memory of a two-hour exercise fades fast. If you kept a live decision log during the exercise (you should), write the report within a few days while the details and the log both still make sense together.
A structure that works
1. Exercise summary
Scenario, date, duration, and who participated. Two or three sentences — this is context, not the content.
2. What happened (timeline)
A short, factual timeline built directly from your decision log: the injects introduced and the key decisions made, in order. Resist the urge to editorialize here — just the sequence of events.
3. What went well
Be specific. "The team escalated quickly" is weaker than "The incident lead was notified within 5 minutes and had assembled the right people within 15." Specific praise is also more credible, and more useful as a pattern to repeat.
4. What needs improvement
Same rule: specific and tied to what actually happened, not general assumptions about what's usually wrong. "It took 20 minutes to determine who had authority to suspend vendor access" is actionable. "Our processes need work" is not.
5. Root causes
For each gap, ask why it happened. Was it a missing process, a training gap, a tooling limitation, or unclear authority? Different root causes need different fixes — a training problem and an authority problem are not solved the same way.
6. Recommendations and owners
Every recommendation needs a named owner and a target date, or it won't happen. This section should feed directly into your remediation tracker — treat the after-action report as the source, and the tracker as the place where progress actually gets tracked over time.
Keep it short
A one- or two-page after-action report that gets read and acted on beats a ten-page report that doesn't. Save the exhaustive detail for the decision log itself, which can serve as an appendix if anyone needs it.
Close the loop
Schedule a follow-up — even a quick one — to check whether the recommended actions actually happened. An after-action report with no follow-up tends to accumulate the same findings, exercise after exercise.
Want this done for you, tailored to your organization?
Build Your Exercise