write / . A monitor has one open incident at a time, so a still-down check does not open a second one while the first is open.
How it works
When an incident opens, the alert goes to the monitor’s . The incident then moves through three states:- Open. Nobody has taken it yet. The policy pages according to its notify steps.
- Acknowledged. A human is on it. Acknowledging does not change whether the monitor is up or down. Alerts can take up to about 30 seconds.
- Resolved. Closed automatically after regions agree the monitor is healthy (about a three-minute hold), or by hand from the incident page. After a manual resolve, there is a five-minute cooldown before a new incident can open for that monitor.
@mention in a comment does not notify anyone. After resolve, you can write a post-mortem (including an AI draft from incident evidence). If generation fails, write it by hand.
Public status copy is separate from the post-mortem. Use the Customer comms panel on the incident to notify customers when you are ready.
Acknowledge and resolve also work with a write or .
Work an incident
1
Open the incident
Load it in the or via the API. You get the timeline, per-region evidence, and dispatch history.
2
Acknowledge
Acknowledge when you are looking at it. That marks a human as on it and stops later notify steps. It does not change up/down.
3
Resolve
Wait for auto-resolve after the healthy hold, or resolve by hand. Manual resolve starts the five-minute cooldown before a new incident can open.
4
Write the post-mortem
After resolve, draft a post-mortem from the evidence (or write it yourself). Publish public status copy separately if you use a status page.
You can only delete a resolved incident.