I am deeply suspicious of "blameless" post mortems. I agree that we should work in ways that minimize fear. We should, to some degree, celebrate the learning we glean from our failures. But I keep seeing "blameless" being construed as lying about why something happened. It's construed in such as way that anyone can hide from their misdeeds. People screw up, and we need to hold them accountable, and THEY need to hold…
Accountability under Dekker's restorative justice model means providing a complete record of what happened, so the justice system can focus on who was harmed and who needs to repair that harm. In some ways I think they can end up mirroring the typical punitive justice system, when the person who needs to repair harm matches what we would call a guilty party in other circumstances. But the idea is not to lie about what happened! It's to expand the network of causality beyond a simple thought terminating "Bob did it" so we can address the systemic problems that led to Bob doing the wrong thing.
> Not necessarily with "punishment" (what does that even mean in a professional context)
A few options depending on profession:
1. Demotion 2. Pay cuts or fines 3. Firing 4. Loss of certification, thus preventing this person from ever working in the field again 5. Jail time, preventing this person from even being in society for some time, perhaps forever.
Dekker's book is full of examples of professionals facing all of the above consequences. If you don't think these punishments are applied to the SRE community Allspaw addressed when originally describing "blameless postmortems" then you probably want to read the all time highest upvoted post to /r/cscareerquestions, "Accidentally destroyed production database on first day of a job, and was told to leave, on top of this i was told by the CTO that they need to get legal involved, how screwed am i?"[1]
[1]: https://www.reddit.com/r/cscareerquestions/comments/6ez8ag/a...