Skip to content
IncidentBot

Incident management system software for IT teams

IT operations teams are responsible for the network, the servers, the identity provider, the VPN and dozens of business applications, and every one of them fails at an inconvenient hour. IncidentBot connects infrastructure monitoring to the right on-call technician, escalates when nobody answers, coordinates the fix and keeps employees informed through an internal status page, so the service desk is not flooded with the same ticket two hundred times.

INC-3107 VPN gateway unreachable, EU office

SEV2 Resolved
TimeActorEvent
08:14:02Email integrationAlert "vpn-gw-eu unreachable" received
08:14:03IncidentBotPaged network on-call technician (push)
08:16:40Network on-callAcknowledged
08:18:10CommsInternal status page: "VPN, EU office: partial outage" published
09:02:11CommanderResolved, failover to the secondary gateway

IT incident management software that starts with the alert

IncidentBot receives alerts from Datadog, Prometheus Alertmanager, Grafana, CloudWatch and Sentry, and from any tool that can send an email or call a webhook. Legacy systems and appliances that only send email are covered by a dedicated inbound address per service.

The details of routing and noise reduction are on the incident alerting page.

  • Routing rules send each alert to the right team by source, host, tag or text.
  • Grouping and deduplication on Team and above turn an alert storm into one incident.
  • Maintenance windows silence alerts during patching and scheduled changes.
  • Low-urgency alerts wait for business hours instead of waking someone.

On-call schedules and escalation for technicians

Build rotations for each team (network, infrastructure, end-user services) with overrides for holidays and swaps between technicians. Escalation policies decide who is paged first, how long they have to acknowledge and who is next.

See on call scheduling software for rotations and overrides in detail.

  • Paging by mobile push, SMS, voice call, email and Slack.
  • Tiers with timeouts, ending with a team lead or IT manager.
  • Follow-the-sun schedules for teams in more than one time zone.
  • Calendar sync, so technicians see their shifts next to their meetings.

A single place to work the incident

Technicians coordinate in a dedicated Slack channel opened with /incident, or in the web app. Roles, severity from SEV1 to SEV4, the runbook for the affected service and a live timeline keep a major incident orderly even when several teams are involved. Microsoft Teams is supported on Business for organizations that work in Teams.

An internal status page instead of a flooded service desk

When email or the VPN is down, every employee wants to know if IT is aware. A private status page, visible to signed-in employees, answers that question before they open a ticket.

More on public and private pages on the status page app page.

  • Components for your business services: email, VPN, Wi-Fi, ERP, file shares.
  • Updates drafted from the incident and published in one click.
  • Employees subscribe to the services they use.
  • Stakeholder viewers, such as department heads and service desk agents, are included on every plan and are not billed.

Incident management for managed service providers

MSPs run on-call for many clients at once. IncidentBot keeps each client separated by service and routing, while one rotation of technicians covers them all.

  • Route alerts per client to the right team and escalation policy.
  • Audience-specific status pages per client on Business.
  • SLA and uptime reporting per service on Business, for monthly client reviews.
  • MTTA and MTTR per client service from incident tracking.

Alongside your ITSM tool

IncidentBot handles the urgent part of an incident: detection, paging, coordination and communication. Your service desk keeps requests, changes and asset records. Action items from postmortems go to Jira or Linear, and webhooks let you send incident updates to other systems your team uses.

Plans for IT operations teams

You pay per responder seat, meaning a technician who can be on call or act on incidents. Viewers are free on every plan. Team is the usual starting point for IT operations, because it includes unlimited schedules and escalation policies, grouping and deduplication, maintenance windows and three status pages. Business adds the service catalog, SSO/SAML, audit log and Microsoft Teams. See the pricing page.

Questions

Do technicians need Slack?

No. Paging does not depend on Slack. Technicians receive pages by push, SMS, voice and email, and can acknowledge and work the incident from the mobile app or web app.

Can we move from Opsgenie?

Yes. Schedules and escalation policies can be imported from Opsgenie and PagerDuty. Atlassian has announced the end of Opsgenie as a standalone product, and the Opsgenie alternative page explains the migration steps.

Can we use SSO?

Yes. SSO/SAML is part of Business, and SCIM provisioning is part of Enterprise.

Put your IT incidents on one system

Connect monitoring, set up technician rotations and give employees a status page they can check first. Walk through a sample incident in the incident response platform demo before you create an account.

Run a sample incident