Incident response

Own the response.Keep the evidence together.

Give an incident an owner, a timeline and a place for its evidence. Your agent sets up the routing and opens the case. You check the case file on a read-only page.

Example: an agent session and its proofIncident case files / On-call and escalation / Monitoring
  • Give the case an owner

    Coordinate response with an incident and its recorded timeline.

  • Route the signal

    Connect alerting, schedules, escalation and service ownership.

  • Keep the context

    Follow attached Issues, service evidence and affected customers.

01The incident case

One place to follow the response.

Your agent opens the incident and attaches the Issues and alerts that anchor it. The case file shows the state, the owner, the attached evidence and the response timeline.

  • Keep response ownership and lifecycle state visible.
  • Attach the Issues and alerts that anchor the investigation.
  • Follow the recorded response timeline and customer context.
Explore incident case files

02The evidence behind the alert

Keep investigating after the signal fires.

An alert brings attention to the problem. Traces, logs, Issues and customer-linked evidence help your team understand it. Your agent brings those findings into the response rather than leaving them between tools.

  • Inspect the captured service and request evidence.
  • Follow person-linked impact into customer stories.
  • Ask your agent to read the customer impact of the incident.
Explore incident investigations

The workflow, connected

From the signal to an owned investigation.

Connect operational routing with the evidence and communication around the response.

  1. Route attention

    Your agent connects the alert or monitor to service ownership and the configured escalation path.

  2. Own the case

    It assigns the incident, attaches the relevant signals and keeps the response timeline together.

  3. Communicate and review

    Use status updates and response reports to carry the investigation into the follow-up.

The capabilities behind it

Before, during and after the incident.

Preparation, investigation and communication belong to the same response workflow.

Put it to work

For the operational moments that need ownership.

A service starts failing

Route its alert, open an owned incident and follow the attached technical evidence.

Explore this workflow

An external dependency goes quiet

Use HTTP, certificate, domain or heartbeat monitoring and its configured response route.

Explore this workflow

The team needs an incident follow-up

Read the response timeline and use reports to review the recorded handling of the case.

Explore this workflow

Your first useful workflow

Prepare the route before the next alert.

A configured route is useful when you have verified who it reaches and the evidence your team will use.

  1. Define ownership

    Add the service, its escalation policy and useful runbook context.

    Read the guide
  2. Connect the signal

    Choose a telemetry alert or external monitor for the condition you follow.

    Read the guide
  3. Test the route

    Verify the configured notification and escalation behavior.

    Read the guide

A few useful answers

A few useful details.

Which plans include incident response?

Creating and changing incidents, on-call schedules and escalation is included in Pro and Scale. Alerts to email, Slack, Telegram, PagerDuty and webhooks are on every plan.

What can external monitoring watch?

HTTP endpoints, TLS certificate expiry, domain registration expiry and scheduled-job heartbeats share the monitoring and response workflow.

Can my agent work an incident?

Yes. Your agent can read incident evidence and open or update an incident through MCP and the CLI. Changes preview first and apply only after you confirm.

Can I monitor things outside instrumented services?

Yes. HTTP endpoints, TLS certificates, domain expiry and scheduled-job heartbeats have external-monitoring workflows that connect to configured response routing.

Can my agent investigate an incident?

Yes. An incident case can anchor an investigation of its lifecycle state, attached Issues or alerts, customer evidence and response timeline. Your agent reads it, and you open the case file to check.

Anectico / Private preview

Bring the incident workflow.Keep your team in context.

Explore coordinated response and connected investigation with your agent in private preview.