For the complete documentation index, see llms.txt. This page is also available as Markdown.

Incidents

Declare and coordinate incidents in ilert to organize your response, page responders, track a timeline, and keep stakeholders informed.

What is an incident?

An incident is the coordination record for a significant, business-impacting event. It is the place where your team comes together to respond: you link the alerts that contributed to it, page the people you need, track a timeline of everything that happened, and—when it is time—communicate with your customers.

Where an alert is a machine-generated signal designed to page on-call responders, an incident is a deliberate, human-declared record designed for coordination. Declaring an incident does not depend on an alert firing—you can declare one whenever you need to mobilize a response.

Availability

Incidents are available for ilert accounts created after May 18, 2026. We are rolling the feature out to existing accounts over the coming weeks and months. To opt in sooner, contact support@ilert.com.

Alerts, incidents, and status updates

ilert separates the technical signal, the internal coordination, and the public communication into three distinct entities. Understanding how they relate is key to using incidents effectively.

Entity
Created by
Audience
Purpose

Alert

Monitoring tools (automatically)

On-call responders

A technical signal that pages the right people.

Incident

Declared manually or from an alert

Your response team (internal)

The coordination record that organizes the response.

Status update

Posted from an incident

Customers & stakeholders (public)

The public message shown on your status pages.

An incident is internal. Nothing about an incident is visible to your customers until you deliberately post a status update. This lets you investigate and coordinate before deciding what—if anything—to communicate publicly.

What ilert previously called an "incident" is now a status update. The name Incident now refers to the coordination record described on this page.

The incident lifecycle

A typical incident follows this path:

1

An alert pages the on-call responder

A monitoring tool fires an alert, and ilert pages whoever is on call. The responder begins investigating.

2

You declare an incident

When the issue needs coordinated response, you declare an incident—from the alert, or from scratch. The triggering alert is linked, and its responders join the incident.

3

You coordinate the response

You page additional responders, open an incident channel for real-time discussion, and keep a timeline of decisions and findings.

4

You communicate publicly

If the incident affects customers, you post status updates to your status pages, keeping severity and internal detail private.

5

You resolve the incident

Once the impact has ended, you set the incident to Resolved. Linked alerts resolve with it.

Severity

Every incident has a severity that communicates its business impact. ilert uses five fixed levels:

Severity
Meaning

SEV1

Critical — major service disruption, highest priority

SEV2

High — significant impact, urgent response

SEV3

Medium — limited impact, partial degradation

SEV4

Low — minor degradation, no service impact

SEV5

Informational

New incidents default to SEV3. You can change the severity at any time from the incident view.

Status

The status reflects where an incident is in its lifecycle. It is internal to ilert and separate from the public status shown on a status update.

Status
Meaning

Declared

The incident has just been created.

Investigating

The team is actively investigating the root cause.

Identified

The root cause has been found and a fix is underway.

Monitoring

A fix is in place and the team is watching for recurrence.

Resolved

The impact has ended and the incident is closed.

The incidents list

Open Incidents in the main navigation to see every incident your teams own. Each row shows the severity, affected services, duration, how many responders have joined, the number of linked alerts, and the current status.

The incidents list
The incidents list

The incident view

Opening an incident brings everything about the response onto one screen:

The incident view
The incident view
  • Header — the incident title, its INC- number, severity, and status. Severity and status are editable here.

  • Summary — an internal description of what is known so far.

  • Affected services — the services impacted by the incident, each with an impact level.

  • Responders and subscribers — the people working the incident and watching it.

  • Linked alerts — the alerts that contributed to the incident.

  • Incident channel — the chat channel connected to the incident, if one exists.

  • Timeline — an append-only log of everything that happened, plus comments and status updates.

Next steps

Last updated

Was this helpful?