Docs
Console

Incidents

Every incident from alert to outcome, with the evidence behind each step.

Incidents lists every episode, newest first: when it opened, the service, the alerts, the confirmed root cause, the decision and the outcome. Filter by service at the top.

An incident

PartWhat it shows
SummaryThe incident note, the proposed fix (with risk and whether it can be undone), the evidence that proved the cause, and advice when a person must act
Root causes checkedEvery cause 3AM considered: confirmed (green), refuted (struck through), inconclusive
TimelineEach step with its time: opened, searched, every verdict, the policy decision, the dry run, the approval, the action, the verification. Open any step to see its full record

Tick show every check to see each individual check, with the query it ran and the raw result.

Decisions and outcomes

DecisionMeaning
shadowA cause was confirmed and a fix proposed; in shadow mode nothing was changed
actThe fix was approved and made
ask_humanA cause was confirmed but the fix needs a person (the advice says what to do)
abstainNothing could be proven, even after looking again; the evidence is handed over
deniedPolicy refused the fix (the reason is shown)
OutcomeMeaning
mitigatedAfter the fix, the checks show the cause has cleared
unresolvedThe fix was made but the cause is still confirmed
escalatedHanded to people
rejectedThe approver said no
shadowRecorded only

A recurrence label means the same cause came back soon after an earlier incident on the service cleared.

On this page