Skip to content
Firewatch
Get started
Site

Incidents and alert response

Every incident belongs to one service and receives a stable reference such as INC-000142. Its severity is SEV1, SEV2, or SEV3, and its status moves through:

triggered → acknowledged → resolved

A resolved incident can be reopened. Reopening starts another response cycle without removing the earlier history.

Incidents can be declared manually or created from alert ingestion. Alert events retain their provider source, identity, labels, source link, occurrence time, and ingestion outcome.

The incident list supports server-side search, pagination, and filters for:

  • status;
  • severity; and
  • service.

The dashboard summarizes open, unacknowledged, and open-SEV1 counts along with recent activity.

Open an incident to:

  • acknowledge ownership;
  • change severity;
  • resolve it with an optional reason and actual resolution time;
  • reopen a resolved incident; and
  • add responder notes.

A responder can edit their own note. Firewatch appends a new revision rather than replacing history, and the UI can display prior revisions.

Acknowledgement or resolution causes any not-yet-delivered escalation work to be recorded as skipped.

The lifecycle records incident creation, status and severity transitions, correlated alerts, escalation stages, delivery successes and failures, skipped notifications, and responder-note revisions.

Delivery attempts store the channel, recipient, outcome, and error. Provider failure does not erase the incident or its other channel attempts.

Firewatch scores active runbooks using their service associations and matching words from the incident title, description, and service name. Suggestions are assistive, not an automated safety decision; responders should verify that a procedure applies before following it.

An incident can be exported as:

  • a PDF operational record; or
  • CSV containing its lifecycle and note revisions.

Exports reflect the current stored record. Protect them like other incident data because they can contain alert descriptions, responder identities, and notes.