A root cause is the thing that, if it had been different, would have stopped this happening. "Operator error" is almost never one - it is where the analysis stops when nobody wants to look further. Normiq gives you two structured ways to keep going.
Recording an analysis needs manage_capa_root_causes.
Five whys
Ask why the problem happened, then why that happened, and keep going. Five is a convention, not a rule: you have gone far enough when the next answer would be outside your control.

If your fifth why is a person, go back to the third. A process that depends on nobody ever making a mistake is the root cause.
Ishikawa
When the cause is not a single chain, the fishbone spreads the search across six categories - machine, method, material, people, measurement, environment - so a team can fill it in together without arguing about ordering first.

Use five whys for a clear sequence of events, Ishikawa when several things had to line up.
Whichever you use, the confirmed root cause is a single sentence on the CAPA itself.
The analysis stays on the record - an auditor reads how you concluded, not just what you concluded.
Next: plan and complete actions.