Skip to content
IncidentBot

Slack incident management app and Slack incident response bot

IncidentBot is a Slack incident management app that also pages your on-call engineer and runs your status page, priced from 24 USD per user a month billed annually. Your engineers already talk in Slack when production breaks. IncidentBot turns that conversation into a structured incident: one command opens a dedicated channel, names the commander, sets the severity, pulls in the runbook and records every decision on a live timeline. Nobody has to remember the process at 3 a.m., because the process is the command.

#inc-2481-checkout-api-latency

SEV2 Resolved
TimeActorEvent
14:09:02IncidentBotChannel opened, severity SEV2, commander assigned
14:09:03IncidentBotRunbook for checkout-api attached
14:10:15Commander/incident role comms assigned to the support lead
14:12:30Comms/incident status published "Degraded performance: Checkout"
14:41:05Commander/incident resolve with rollback of release 2026.09.3
14:41:06IncidentBotPostmortem draft created with 8 timeline events

One command opens the incident channel

Type /incident in any channel, give it a title and a service, and IncidentBot creates a dedicated channel such as #inc-2481-checkout-api-latency. The on-call engineer who acknowledged the page is invited, the reporter becomes the first commander, and a pinned summary shows the service, severity, roles, status and links in one place.

  • The channel name carries the incident number and a short slug, so it is easy to find in search months later.
  • The alert that triggered the page is posted into the channel with its source, labels and graph link.
  • The runbook attached to the service is posted as a checklist, so the first steps are on screen before anyone asks.
  • Stakeholders who only need to follow along join as read-only viewers and are not billed.

Slack incident bot commands

Every command works from the incident channel. The bot answers in the thread or channel, updates the pinned summary and writes the action to the timeline with the name of the person who ran it.

CommandWhat it does
/incidentOpens a new incident with a title, service and severity, and creates the dedicated channel.
/incident severityRaises or lowers the severity between SEV1 and SEV4 and notifies the people your policy names for that level.
/incident roleAssigns or hands over commander, communications lead or scribe, and announces the change in the channel.
/incident updatePosts a status update to the channel and starts a status page draft you can publish in one click.
/incident pagePages another person, schedule or escalation policy into the incident, by push, SMS, voice, email or Slack.
/incident runbookPosts the runbook for the affected service, or a different one you name.
/incident noteAdds a note to the timeline without posting it to the whole channel.
/incident resolveMarks the incident resolved, stops the escalation, records the resolution time and opens the postmortem draft.

Timeline capture without a scribe typing everything

The timeline records commands, role changes, severity changes, pages, acknowledgements, status updates and messages you mark with a reaction. The scribe curates instead of transcribing, and the incident postmortem starts from facts with timestamps rather than from memory.

From the first message to the archived channel

An incident channel moves through the same stages every time, which is what makes Slack incident response predictable across teams.

  • Open: the channel is created, responders are invited and the pinned summary appears.
  • Investigating and identified: status changes are posted and reflected on the pinned summary and the incident record.
  • Monitoring: the fix is out and the team watches the service before closing.
  • Resolved: escalation stops, MTTA and MTTR are recorded in incident tracking and the postmortem draft is linked in the channel.
  • Archived: the channel is archived after a period you choose, and the full record stays in IncidentBot.

Slack is where you coordinate, not the only way you get woken up

Paging does not depend on Slack. If Slack is slow or down, the on-call engineer is still reached by mobile push, SMS, voice call or email according to the escalation policy described on the on call management page. When Slack recovers, the incident channel picks up where the record is.

What the Slack app can and cannot do

A Slack workspace admin installs the app once from the standard Slack approval screen. In plain terms, the app asks for the access it needs to run incidents and nothing broader.

  • Add slash commands, so /incident and its subcommands work in your workspace.
  • Create channels and invite people, so it can open the incident channel and bring in responders.
  • Post, pin and update messages, so it can keep the summary, status updates and checklists current.
  • Read messages in incident channels it created or was added to, so it can capture the timeline.
  • Read basic member profiles (name and email), so it can match Slack users to their IncidentBot on-call accounts.
  • It does not read direct messages, and it does not read channels it is not a member of.
  • You can remove the app at any time from your Slack workspace settings, and the incident records stay in IncidentBot.

Microsoft Teams

Teams that coordinate in Microsoft Teams get the same incident channel, roles and timeline on the Business plan. The details are on the pricing page.

Slack incident response on every plan

Starter includes Slack incident channels with /incident, the live timeline and a basic postmortem template. Team adds incident roles, severity levels, custom fields, runbooks and postmortem drafts with action items synced to Jira and Linear. Business adds workflow automation and Microsoft Teams. There is no free plan: every plan is a subscription per responder seat, and you can try the flow first in the incident response platform demo.

Questions

What are the best Slack apps for incident management?

The best known Slack apps for incident management are incident.io, Rootly, FireHydrant, Datadog Incident Management, PagerDuty and IncidentBot. All of them open incident channels and track a timeline; they differ in whether paging, status pages and postmortems are in the same price. IncidentBot includes paging, the Slack workflow and a status page on every plan. Prices for each are in our incident.io alternative and Rootly pricing comparisons.

Does IncidentBot replace our Slack incident bot and our pager?

Yes. The same product pages the on-call engineer, opens the Slack channel, updates the status page app and drafts the postmortem, so you do not stitch together a separate bot and a separate paging tool.

Can we keep our own channel naming convention?

Yes. The prefix and slug format are configurable, for example inc-, incident- or a team prefix, followed by the incident number and title.

Who can run /incident?

Anyone in the workspace can open an incident, so the person who notices a problem first can raise it. Actions such as paging or changing roles are available to responder seats, and viewers can read along.

What happens if someone opens an incident by mistake?

The commander resolves it with a short note or marks it as not an incident, and it is excluded from MTTA and MTTR reports.

Run your next incident from one command

Connect your Slack workspace, attach runbooks to your services and let /incident carry the process for you. You can see the whole flow in a sample incident in your browser before you create an account.

Run a sample incident