Incidents
Declare and coordinate incidents in ilert to organize your response, page responders, track a timeline, and keep stakeholders informed.
What is an incident?
An incident is the coordination record for a significant, business-impacting event. It is the place where your team comes together to respond: you link the alerts that contributed to it, page the people you need, track a timeline of everything that happened, and—when it is time—communicate with your customers.
Where an alert is a machine-generated signal designed to page on-call responders, an incident is a deliberate, human-declared record designed for coordination. Declaring an incident does not depend on an alert firing—you can declare one whenever you need to mobilize a response.
Availability
Incidents are available for ilert accounts created after May 18, 2026. We are rolling the feature out to existing accounts over the coming weeks and months. To opt in sooner, contact support@ilert.com.
Alerts, incidents, and status updates
ilert separates the technical signal, the internal coordination, and the public communication into three distinct entities. Understanding how they relate is key to using incidents effectively.
Alert
Monitoring tools (automatically)
On-call responders
A technical signal that pages the right people.
Incident
Declared manually or from an alert
Your response team (internal)
The coordination record that organizes the response.
Status update
Posted from an incident
Customers & stakeholders (public)
The public message shown on your status pages.
An incident is internal. Nothing about an incident is visible to your customers until you deliberately post a status update. This lets you investigate and coordinate before deciding what—if anything—to communicate publicly.
What ilert previously called an "incident" is now a status update. The name Incident now refers to the coordination record described on this page.
The incident lifecycle
A typical incident follows this path:
You declare an incident
When the issue needs coordinated response, you declare an incident—from the alert, or from scratch. The triggering alert is linked, and its responders join the incident.
You coordinate the response
You page additional responders, open an incident channel for real-time discussion, and keep a timeline of decisions and findings.
You communicate publicly
If the incident affects customers, you post status updates to your status pages, keeping severity and internal detail private.
Severity
Every incident has a severity that communicates its business impact. ilert uses five fixed levels:
SEV1
Critical — major service disruption, highest priority
SEV2
High — significant impact, urgent response
SEV3
Medium — limited impact, partial degradation
SEV4
Low — minor degradation, no service impact
SEV5
Informational
New incidents default to SEV3. You can change the severity at any time from the incident view.
Status
The status reflects where an incident is in its lifecycle. It is internal to ilert and separate from the public status shown on a status update.
Declared
The incident has just been created.
Investigating
The team is actively investigating the root cause.
Identified
The root cause has been found and a fix is underway.
Monitoring
A fix is in place and the team is watching for recurrence.
Resolved
The impact has ended and the incident is closed.
The incidents list
Open Incidents in the main navigation to see every incident your teams own. Each row shows the severity, affected services, duration, how many responders have joined, the number of linked alerts, and the current status.

The incident view
Opening an incident brings everything about the response onto one screen:

Header — the incident title, its
INC-number, severity, and status. Severity and status are editable here.Summary — an internal description of what is known so far.
Affected services — the services impacted by the incident, each with an impact level.
Responders and subscribers — the people working the incident and watching it.
Linked alerts — the alerts that contributed to the incident.
Incident channel — the chat channel connected to the incident, if one exists.
Timeline — an append-only log of everything that happened, plus comments and status updates.
Next steps
Last updated
Was this helpful?