Artifacts · 03

Customer-Facing RCA

A customer-facing RCA is the sanitised, external version of a root-cause report that a B2B vendor sends to the enterprise customer it owes one to after a Sev1: no internal hostnames, no employee names, no raw logs, no unnecessary architectural disclosure, written to survive the recipient's vendor-risk and procurement review, and delivered inside the contractual window.

Who it's for: VP Customer Success, Support leadership, account teams at B2B software companies that owe enterprise customers a written RCA in 3–5 business days.

Contents

What does the Customer-Facing RCA contain?

For every B2B software prospect this single artifact is the whole pitch: they owe these documents on a contractual clock, and today a senior engineer writes them by hand, late. No competing tool produces it.

01 Incident summary and customer impact (their tenants, their duration)
02 Timeline in customer-relevant terms
03 Root cause, stated without internal system names
04 What has been done to prevent recurrence, with dates
05 SLA / credit position, if applicable
06 Contact and follow-up commitments
How-to

How to write a customer-facing RCA

Seven steps that survive a customer's procurement review.

  1. Step 1

    Start from the evidence-linked internal RCA

    Never write the customer version first. Derive it from the internal Root Cause Report so the facts match if the customer's engineers ask follow-ups.

  2. Step 2

    State impact in the customer's terms

    Which of their tenants or users, for how long, with what degradation. Not your global error rate.

  3. Step 3

    Sanitise

    Remove hostnames, IPs, employee names, raw logs, credentials, and architecture the customer doesn't need.

  4. Step 4

    State the cause plainly

    One or two sentences. Trigger, propagation, failure, in language a non-engineer buyer can repeat to their boss.

  5. Step 5

    List corrective actions with dates

    What you have already done, what you will do, and by when. Vague 'we are reviewing' language fails vendor-risk review.

  6. Step 6

    State the SLA position

    Whether credits apply and how they will be issued. Silence here generates a second ticket.

  7. Step 7

    Deliver inside the contractual window

    Track time-to-RCA against the SLA exhibit. Late is a breach even when the content is perfect.

Template

Customer-facing RCA template

The nine sections an enterprise customer's procurement and security teams expect. Copy it, or let Onepane generate it from the investigation.

1. Incident reference and classification
Your incident ID, severity, and the date/time window (in the customer's timezone).
2. Customer impact
Affected services, tenants/regions, duration, and the nature of degradation. Specific to this customer.
3. Summary
Two or three sentences a non-technical stakeholder can forward.
4. Timeline
Detection, mitigation, resolution, customer notifications, customer-relevant events only.
5. Root cause
Trigger → propagation → failure, sanitised. No internal system names.
6. Contributing factors
Anything that widened impact or slowed recovery, kept distinct from the cause.
7. Corrective and preventive actions
Completed and planned, each with a target date.
8. SLA and service-credit position
Whether the SLA was breached and how credits will be handled.
9. Contact and follow-up
Named contact and any scheduled review call.

Want it generated from the evidence instead of typed at 11pm? Run the replay, the customer-facing version ships with every accepted RCA.

FAQ

Customer-Facing RCA, questions.

How do I write an RCA for a customer after an outage?

Start from the internal Root Cause Report, then remove everything the customer doesn't need: hostnames, employee names, raw logs, architecture detail. Keep the impact statement specific to their tenants, state the cause in plain terms, list corrective actions with dates, and note the SLA position. Deliver it inside the contractual window, usually 3–5 business days after the Sev1, because a late RCA is itself a breach.

How many business days do we have to deliver an RCA to a customer?

It depends on the MSA. The most common enterprise clause commits the vendor to a written RCA within 5 business days of a Sev1; some contracts say 3, some 10, and many pair it with a 24–48 hour preliminary notice. Check your SLA exhibit, the number is there, and it is enforceable.

What must a customer-facing RCA never contain?

Internal hostnames and IPs, employee names, raw log excerpts, credentials or tokens, unnecessary architectural detail, and speculation. Include only what the customer needs to understand impact, cause and prevention.

Can Onepane produce the customer-facing RCA automatically?

Yes. It is generated from the same evidence-linked investigation as the internal report, sanitised by policy, and reviewed by our engineers before it ships. Many customers send it directly; others route it through Customer Success first.

Send us your last 90 days of Sev1s.We'll show you what we would have found.

Not a demo. A replay on your own incidents, scored against the RCA a human actually wrote. Two weeks, no cost.