Skip to content
IncidentBot

Incident management tool setup in four steps

IncidentBot is built to be useful the same week you connect it. You point your monitoring at it, bring in the schedules you already have, respond to the next incident in Slack and publish the status update from the incident itself. Here is what each step involves and what your team sees afterwards.

Workspace setup, Payments team

StepSettingState
1. Monitoring Datadog, service checkout-api, owner Payments Connected
2. Schedules Payments primary, weekly rotation, handoff Monday 10:00 Saved
3. Slack /incident in #payments, incident channels on Installed
4. Status page Checkout, API and Dashboard components Published

Step 1. Connect your monitoring

Each service in IncidentBot gets an integration endpoint. You add it to Datadog, Prometheus Alertmanager, Grafana, CloudWatch or Sentry the same way you would add any notification target, or you send alerts by email or webhook from anything else.

The routing and noise controls are covered in detail on the incident alerting page.

  • Create a service, for example checkout-api, and choose its alert sources.
  • Paste the integration URL into your monitoring tool, or forward alert email to the service address.
  • Add routing rules if one source feeds several services, for example by tag or payload field.
  • Turn on grouping and deduplication so a noisy check opens one incident, not fifty.
  • Set maintenance windows for scheduled work so deploys do not page anyone.

Step 2. Import or build your on-call schedules

If you already run on-call in Opsgenie or PagerDuty, IncidentBot imports schedules and escalation policies, so rotations and tiers carry over without retyping. If you are starting from a spreadsheet, you build the rotation in the schedule editor in a few minutes.

Each engineer installs the mobile app and verifies a phone number for SMS and voice. Paging does not depend on Slack. More on on call scheduling software and on call management.

  • Rotations by day, week or custom length, with handoff time and time zone per layer.
  • Follow-the-sun layers for teams across regions.
  • Overrides and swaps that engineers request and accept themselves.
  • Calendar sync so every shift shows up next to meetings.
  • Escalation policies with tiers, timeouts and repeats, ending in a fallback that always reaches someone.

Step 3. Respond with /incident in Slack

Install the IncidentBot app in your Slack workspace. When an alert pages someone, or when a person spots a problem first, anyone types /incident and IncidentBot opens a dedicated channel such as #inc-2481-checkout-api-latency.

Business plan teams can run the same flow in Microsoft Teams. The full flow is on the incident response tools page.

  • The on-call responders for the affected service are invited automatically.
  • The commander, communications lead and scribe roles are assigned with one command.
  • Severity is set from SEV1 to SEV4 and can change as you learn more.
  • The runbook attached to the service is posted into the channel.
  • Pinned messages, role changes and status changes are recorded on the live timeline.

Step 4. Publish status and review

While the team works the problem, IncidentBot drafts a status page update from the incident: affected component, impact level and a short customer-facing summary. The communications lead reviews it and publishes in one click. Subscribers are notified by email.

  • Public or private status pages, with a custom domain on Team and above.
  • Updates as the incident moves from investigating to identified, monitoring and resolved.

After resolution, the postmortem draft is waiting: the timeline, the impact window, time to acknowledge and time to resolve. The team adds contributing factors and action items, which sync to Jira or Linear.

  • Blameless postmortem template with timeline pre-filled.
  • MTTA and MTTR reports by service and severity.
  • On-call load report so managers see who carries the weight.

What the incident management tool changes for your team

The work itself does not get easier, but the coordination around it does. The first minutes of an incident stop going into finding people and picking a channel.

  • The right engineer is paged the first time, through a channel they cannot miss.
  • Everyone knows where the incident lives and who is in charge.
  • Customers get an update while engineers keep working.
  • The postmortem is written from recorded facts, days sooner.

Questions

How long does setup take?

A single team with one monitoring source and an existing rotation is usually connected and paging within an afternoon. Importing from Opsgenie or PagerDuty shortens the schedule step further.

What Slack permissions does the app need?

It needs permission to create channels, invite members, post messages and read messages in incident channels it created, so it can build the timeline. It does not read your other channels.

Can we run IncidentBot next to our current tool during migration?

Yes. Many teams send alerts to both for a short period, compare paging, then switch the integration endpoint. Enterprise plans include onboarding and migration from Opsgenie or PagerDuty.

What does it cost?

Pricing is per responder seat, from 49 USD per user per month on Starter, or 24 USD billed annually. Read-only stakeholder viewers are not billed. See pricing for every plan.

Try it before you connect anything

The incident simulator runs a full incident in your browser: alert, paging, Slack channel, status page draft and postmortem skeleton. When you are ready, create your account.