Skip to main content

Incidents

The Incidents dashboard (/incidents) gives operators a durable response workflow for grouped alerts, sessions, affected agents, containment actions, communications, and post-incident reviews.

Status

CapabilityStatusNotes
Incident list and filtersLiveReads persisted incidents from store-svc; no fixture rows are injected in production paths.
Create from alert/sessionLiveAlert and session detail pages can open an incident with related evidence already attached.
War room timelineLiveTimeline, notes, containment events, communication events, and review events are stored per tenant.
Bulk containmentLiveAdmin-only action that records incident-scoped containment and audit entries.
Slack/email communicationLiveUses configured alert_channel integrations. Delivery failures are written to the incident timeline and do not block status transitions.
Post-incident reviewLiveManual trigger after resolved; stores root cause, impact summary, remediation, and recommendations.

Operator workflow

  1. Open Incidents to filter by severity or status.
  2. Create an incident from an alert, a session, or the incident list.
  3. Open the war room to review timeline evidence and append notes.
  4. Draft Slack or email updates from the incident context.
  5. Admins can execute bulk containment for affected agents after confirmation.
  6. Move the incident to resolved, then generate and export the review.

Roles

RoleIncident access
AdminCreate/update incidents, add notes, draft/send communications, execute containment, generate reviews.
AnalystCreate/update incidents, add notes, draft/send communications, generate reviews.
ViewerRead incidents and reviews.

All incident reads and writes are scoped by tenant through X-Org-ID.