For B2B software and digital infrastructure

The customer-facing RCA, delivered inside the contractual window.

B2B software vendors owe enterprise customers a written RCA within a contractual window, usually 3–5 business days, plus SLA credits. Onepane investigates every Sev1 inside your VPC, across every monitoring stack you own, and delivers the finished, sanitised customer-facing RCA under an SLA, so a senior engineer stops writing it by hand, late.

The forcing function

Why does the post-incident report to customers always slip?

Every B2B vendor selling to large enterprises has signed an MSA with an SLA exhibit. Somewhere in it is a clause that says a written root-cause analysis is due within a fixed number of business days after a Sev1, and that credits apply. That clause is real, dated and painful, and almost no engineering organisation has tooling for it.

What actually happens: the incident closes, three engineers spend four hours reconstructing what happened across five tools, and then one of them spends another day writing the document Customer Success has already promised. If the estate came together through acquisitions, the investigation crosses monitoring stacks nobody owns end to end, and the clock runs out.

We do that work. Agents investigate inside your VPC; our engineers sign off; the customer-facing document arrives inside the SLA. See how it works.

Fit signals

How do you know this is you?

The first question we ask on a call is simple: do you owe your customers an RCA document after a Sev1, and what is the contractual window? If yes, these four signals almost always follow.

01

A named person writes the RCA by hand

Usually a senior engineer or the Director of Problem Management, at 11pm, from Slack scrollback and five dashboards. Nobody sells to that person, and they get blamed when it is late.

02

A committed window you sometimes miss

Enterprise MSAs commonly specify a written root-cause analysis within three to five business days of a Sev1, alongside SLA credits. A late RCA is a breach even when the content is perfect.

03

Evidence gathered by asking five teams

The investigation is a chain of Slack messages: 'did anyone deploy?', 'who owns checkout-api?', 'can someone pull the CloudWatch logs?'. The answers arrive slower than the clock runs.

04

Three monitoring stacks, no service map

The single highest-precision fit signal we have is acquisition history. A company that bought three or four others runs Datadog and New Relic and CloudWatch and an inherited Nagios box, and nobody has one topology across them.

Contract versus reality

What your MSA says, what happens today, and what changes.

What your MSA says What happens today With Onepane
Written RCA within 3–5 business days of Sev1 resolution A senior engineer starts writing after the fire is out; the draft slips into the following week; Customer Success chases engineering daily. Investigation starts automatically at Sev1 closure. The Customer-Facing RCA is delivered inside the committed window, measured from closure, or we credit.
Root cause and corrective actions stated Cause is often 'a configuration change' with no evidence trail; corrective actions are aspirational and unowned. Causal chain stated as trigger → propagation → failure, every claim linked to evidence, corrective actions with named owners and dates in the CAPA Tracker.
No unnecessary disclosure of internal systems The engineer copy-pastes from the internal postmortem, then someone in legal redlines hostnames and names out under deadline pressure. The customer version is generated from the internal report and sanitised by policy: no hostnames, no employee names, no raw logs, no architecture the customer does not need.
Same facts if the customer's engineers ask follow-ups Internal and external documents drift because they were written separately, days apart. One evidence-linked investigation produces both the internal Root Cause Report and the external RCA. The facts cannot diverge.
Recurrence tracked; repeat incidents escalate Nobody links this incident to the one in March. The customer's TAM does. The Known Error and Recurrence Register links each new incident to prior ones, and the Monthly Problem Review shows repeat rate by service.

Sources: 3–5 business days is the market-standard RCA clause in enterprise SLA exhibits; individual vendors publish windows from 3 to 10 business days. See our Time to RCA benchmarks.

Post-acquisition estates

Why is M&A history the strongest fit signal?

When you integrate two or three acquired companies, you inherit their monitoring. Two years later you are running Datadog for the core product, New Relic for one acquisition, CloudWatch for another, and a Nagios box someone is afraid to switch off. Each is fine on its own. None of them can see a Sev1 that starts in one and lands in another.

The observability vendors' own investigation features investigate their own data. Nobody's investigates the join. So when a Sev1 spans stacks, the work is manual, the service map is in three people's heads, and the customer RCA slips past the contractual window.

Onepane connects to all of it read-only, builds one service-and-ownership map from what is actually running, and follows the causal chain across stacks. You keep the map. It is usually the first unified topology the company has had.

FAQ

B2B software, the questions.

How fast can Onepane deliver a customer-facing RCA after a Sev1?

Inside a committed SLA window measured from Sev1 closure, agreed after the replay shows what your estate supports. Most enterprise MSAs specify three to five business days; the service is designed to land the document well inside that so Customer Success is never chasing engineering for it. Miss the window and we credit.

What does an RCA owed to a customer under an SLA need to contain?

Incident reference and classification, the customer's impact in their terms, a plain-language root cause, contributing factors kept distinct from the cause, corrective and preventive actions with dates, and the SLA credit position. It must not contain internal hostnames, employee names, raw logs or unnecessary architecture. Our Customer-Facing RCA page has the full section-by-section structure.

We run Datadog, New Relic and CloudWatch after acquisitions, can one RCA span all three?

Yes. That is the estate we are built for. Onepane connects read-only to whatever you already own, builds one service-and-ownership map across all of it, and investigates the causal chain wherever it leads, including the inherited stack nobody has migrated yet.

Does the customer version stay consistent with the internal postmortem?

Yes, because both are derived from the same evidence-linked investigation. The internal Root Cause Report carries the evidence index; the customer version is sanitised by policy and reviewed by our engineers before it ships. If the customer's engineers ask follow-ups, the facts match.

Who inside a software company usually brings Onepane in?

The Director or Senior Manager of Problem Management, who writes the RCA today; the VP of IT Operations or SRE, who thinks in FTEs; and, more often than people expect, the VP of Customer Success or Support, who promised the customer an RCA in five days and has no way to make engineering deliver it.

Send us your last 90 days of Sev1s.We'll show you the customer RCA we would have sent.

Scored against the document your engineer actually wrote, with time-to-RCA against your contractual window. Two weeks, no cost, no pricing conversation first.