- Open the incidentGo to Incidents and open the incident, or follow the link in the alert.
- AcknowledgeChoose Acknowledge to tell your team you are on it. This stops reminders and escalation.
- Assign an ownerUnder Assignee, choose a member or "Assign to me", then "Save assignee".
- Link a runbookEnter a Runbook URL and choose "Save runbook".
- Add notes and public updatesUnder "Add to the timeline", choose Internal note or Public update. For public updates pick a Public status and confirm the text is safe.
An incident opens automatically when a monitor's failure is confirmed, and resolves automatically when the monitor recovers. The incident page is where your team coordinates the response and tells customers what is happening.
Acknowledge
Choose Acknowledge at the top of the incident page as soon as someone is looking at the problem. Acknowledging:
- stops repeat reminders from routing rules,
- cancels all later steps of a running escalation policy,
- records who acknowledged and when on the timeline.
You can also acknowledge from the command line with monctl incidents ack <incident-id>.
Assign and link a runbook
Under Assignee, pick a member in Assign to or choose Assign to me, then Save assignee. Under Runbook, enter a Runbook URL so responders know what to check, and choose Save runbook.
The timeline
The Timeline records everything that happened: when the incident opened, alerts, acknowledgement, notes, updates and recovery. It is append-only, so entries cannot be edited or removed. Entries marked Public are shown on status pages; Internal entries are visible only to workspace members.
Internal notes
Under Add to the timeline, choose Internal note — only workspace members see it, write your note and choose Add internal note. Use notes for findings, commands you ran and decisions.
Public updates
Choose Public update — shown on status pages, pick a Public status and write the Update text. The statuses are:
- Investigating: you know about the problem and are looking into it.
- Identified: you found the cause and are working on a fix.
- Monitoring: a fix is in place and you are watching the results.
- Resolved: the problem is over.
A Safe public preview shows exactly what visitors will see. The update is visible on every published status page that shows this monitor and may be emailed to that page's subscribers, so do not include internal details, customer data or credentials. Tick I have checked this text is safe to show publicly and choose Publish public update.
Recent deployments
On Starter and Team, deployment markers sent from your CI appear under Recent deployments when they happened in the hour before the incident and targeted this monitor, its tags or project, or the whole workspace. They are labeled "possibly related", a hint to check, not a confirmed cause.
History
Incident history is kept for 7 days on Free, 90 days on Starter and 365 days on Team. You can export incidents as CSV from Settings → Data export.
Viewers and guests have read-only access. Owners, admins and operators can acknowledge, assign and add notes.
Frequently asked questions
Do I have to open incidents manually?
No. Incidents open automatically when downtime is confirmed and resolve automatically when the monitor recovers.
Can I edit or delete a public update?
No. The timeline is append-only. Post a new update to correct or clarify a previous one.
Does acknowledging stop alerts?
Yes. It stops repeat reminders and cancels the remaining escalation steps. Recovery notifications are still sent when the monitor comes back.