Incidents and alert response
Incident identity
Section titled “Incident identity”Every incident belongs to one service and receives a stable reference such as
INC-000142. Its severity is SEV1, SEV2, or SEV3, and its status moves
through:
triggered → acknowledged → resolvedA resolved incident can be reopened. Reopening starts another response cycle without removing the earlier history.
Incidents can be declared manually or created from alert ingestion. Alert events retain their provider source, identity, labels, source link, occurrence time, and ingestion outcome.
Find an incident
Section titled “Find an incident”The incident list supports server-side search, pagination, and filters for:
- status;
- severity; and
- service.
The dashboard summarizes open, unacknowledged, and open-SEV1 counts along with recent activity.
Respond
Section titled “Respond”Open an incident to:
- acknowledge ownership;
- change severity;
- resolve it with an optional reason and actual resolution time;
- reopen a resolved incident; and
- add responder notes.
A responder can edit their own note. Firewatch appends a new revision rather than replacing history, and the UI can display prior revisions.
Acknowledgement or resolution causes any not-yet-delivered escalation work to be recorded as skipped.
Timeline and delivery audit
Section titled “Timeline and delivery audit”The lifecycle records incident creation, status and severity transitions, correlated alerts, escalation stages, delivery successes and failures, skipped notifications, and responder-note revisions.
Delivery attempts store the channel, recipient, outcome, and error. Provider failure does not erase the incident or its other channel attempts.
Suggested runbooks
Section titled “Suggested runbooks”Firewatch scores active runbooks using their service associations and matching words from the incident title, description, and service name. Suggestions are assistive, not an automated safety decision; responders should verify that a procedure applies before following it.
Export
Section titled “Export”An incident can be exported as:
- a PDF operational record; or
- CSV containing its lifecycle and note revisions.
Exports reflect the current stored record. Protect them like other incident data because they can contain alert descriptions, responder identities, and notes.