Skip to main content

What is @incident?

You can tag @incident in any incident channel in Slack, chat from the incident tab in Microsoft Teams, or chat via the incident dashboard. It can be used to draft updates, create follow-ups, pause incidents and more. Essentially, any action you currently do via a command, you can do via the agent instead. @incident can also answer questions about the incident you’re in, connected alerts, and attachments. The examples below are relevant for Slack only. In Microsoft Teams, chat to the agent in the embedded tab, or in the dashboard or mobile app.

What @incident can do

Ask @incident to change something and it makes the change, then tells you what it did. Every action runs with your own permissions and is recorded against your name. Run the incident
  • Accept an incident out of triage, or decline it
  • Move it between statuses, including resolving and closing it
  • Pause it until a date and time you give, then unpause it
  • Cancel it
  • Change the severity
  • Rename it, or rewrite the summary
  • Assign and reassign roles, including lead
  • Set or clear incident timestamps
  • Set custom field values
  • Post an internal update into the channel
  • Merge another incident into this one, or unmerge one that was merged in
Track the work
  • Create, update, reassign, and delete actions
  • Create follow-ups, owned by a person or a team
  • Change an existing follow-up’s owner, status, priority, or title
Page people and manage on-call
  • Raise an escalation to a person or an escalation path
  • Look up who’s on call, and read escalations that are already running
  • Add and remove people from a rota using schedule overrides
  • Raise cover requests, and respond to other people’s
  • View, edit, cancel, or end maintenance windows early
@incident drafts escalations by default. It posts the draft for someone to accept, edit, or decline. It pages immediately only when you name one person and ask for them to be paged. Investigate
  • Start an investigation, or steer one that’s heading down the wrong path
  • Mute an investigation’s heads-up messages while it keeps running in the background
  • Query connected telemetry: logs, metrics, traces, and dashboards
  • Add or remove Scribe from the incident call
Communicate outward
  • Draft a status page update for you to publish. @incident never publishes one.
  • Draft customer messages, emails, and stakeholder briefings
  • Post a finding into the incident channel, attributed to you
Answer questions
  • Explain the incident you’re in, its alerts, its attachments, and the conversation so far
  • Search your incident history for similar incidents
  • Query your catalog for ownership and service data
  • Search runbooks and other documents you’ve connected
  • Check whether a third-party service is reporting problems
  • Answer questions about incident.io itself
  • Search the web
Work with your code
  • Answer questions about any repository you’ve connected
  • Open and revise a code change. Slack only.

Examples to get started

Handle incident admin You can ask @incident to handle anything you’d do as a responder during an incident. That means pausing, renaming, declining, or keeping your incident up to date with changes.
  • @incident pause this till monday
  • @incident rename this to reflect that it was a misconfiguration problem
  • @incident can you decline this and create a follow up to stop it paging?
Draft updates across stakeholders Draft rich updates for different scenarios with @incident. You don’t have to be prescriptive about what to include - @incident will use the information available in the channel to reflect the current situation.
  • @incident write an update describing the fix that we've implemented
  • @incident draft a customer facing message explaining the workaround described above
  • @incident write up a handover summarizing where we're at and next steps - then assign the lead to Rory
  • @incident draft an update for my status page, make it clear that the issue is resolved
Dive into your codebase You can ask questions of any of your connected repositories, to summarize code or provide more clarity.
  • @incident can you find where this function is used? I want to understand the potential impact
  • @incident can you check our timeline code - when a notification errors, do we surface it?
Query telemetry If you’ve connected any telemetry sources for Investigations you can ask natural language questions of your logs or metrics
  • @incident show me 5 example log entries of SMS notification failures from the last 24 hours. Include any error codes, organization names, and country codes.
  • @incident look at the telemetry for web pod CPU usage during this incident to see if the >75% usage was isolated to a single pod
Answer general engineering questions: Ask @incident general engineering questions whenever you need it.
  • @incident what does 'skip locked' mean in postgres?
  • @incident can you rewrite this query to group by customer_id
  • @incident draft me a SQL query to determine how many payments are currently in 'error' state for this organization. Their ID is [ID]
Search past incidents Search across your incident history to find patterns or similar issues.
  • @incident have we seen incidents like this before?
  • @incident did we have an incident about high database CPU in February?
  • @incident what other incidents have affected ACME?

Who can use @incident & how to enable it in your account?

  • Available to all Pro and Enterprise customers on Slack and Microsoft Teams (on the tab for the incident, or in the dashboard). It is not available for Basic, Team plan, on-call–only participants, or workspaces that opted out of AI features/required sub-processors.
  • If it isn’t working for you, it’s probably because your account doesn’t have message storage enabled. You’ll need to update your message storage settings to ‘All’ at Settings → AI governance.
Some groups of actions appear only when you have the product behind them:

Privacy, Permissions & Data Use

What permissions does @incident use?

Yours. Every action runs with the permissions of the person who asked for it, and is recorded against their name. @incident checks those permissions before each change, so it can’t do anything you couldn’t do yourself from the dashboard. If you can’t change severity, @incident won’t change it for you.

Can we stop @incident doing something?

Yes. We can switch an individual group of actions off for your organization, so @incident keeps answering questions but stops making that kind of change. Reach out to support and tell us which group.

Do you train models based on our data?

No, we never train or fine tune AI models based on your data. Additionally, we have zero data retention agreements in place with the sub-processors we use to provide our AI features, including OpenAI, Anthropic, and Google Vertex. You can read more detail in our AI Privacy Guidance in our trust centre. More generally, all of the same controls outlined in our Trust Centre and Privacy Policy apply here, such as encryption.

Do you use data from private incidents?

By default, all AI features are disabled in private incidents. Optionally, you can opt-in to AI features in private incidents in Settings → AI governance. This is available to all Pro and Enterprise customers.