INCIDENT COMMAND

One place to run the incident.

Keep ownership, responders, timeline, notes and action items together from first alert to resolution.

WHAT IT SOLVES

One incident, with the context to act.

An incoming signal belongs to a service. Priority, urgency, ownership and related alert context give the responder a place to begin instead of another isolated notification.

Understand the capability
01Create and acknowledge incidents
02Assign responders and track ownership
03Keep a timeline and action items
OPEN · P1The incoming signal is correlated to its service and enters incident response; ownership and escalation resolve from the service configuration.
OpsKnight incident lifecycle view: Triggered
OpsKnight Incident Command — Triggered state: The incoming signal is correlated to its service and enters incident response; ownership and escalation resolve from the service configuration.

HOW IT WORKS

A concrete operational path, not a feature list.

INCIDENT STATE MACHINEOne incident record moves through response without losing ownership or evidence.
01TRIGGERED
02ACKNOWLEDGED
03RESOLVED
Service contextResponder ownershipTimeline + follow-up

EXPLORE A WORKFLOW

  1. 01Incoming signal
  2. 02Service context
  3. 03Priority & urgency
  4. 04Incident owner

Start with the signal, attach it to the affected service, classify the incident and make ownership explicit before the response fragments across tools.

OPERATIONAL DEPTH

Incident command, beyond the happy path.

The details below are the parts teams need when evaluating how the capability behaves during real response, failure, and handoff.

01

Acknowledge. Assign. Investigate.

Acknowledge the incident, assign a responder and record the investigation. Keep notes, watchers and the operational timeline together so the next person can understand the response.

Read the operational guide
02

Response timing with a policy behind it.

Use the documented response-policy and SLA workflow to inspect acknowledgement and resolution timing. Review the applicable policy and support-hours context before interpreting a breach.

Read the operational guide
03

Coordinate without losing the record.

Create a provider-backed war room when collaboration is needed. OpsKnight remains authoritative for incident state while Slack or Teams projects the response into the conversation.

Read the operational guide
04

Recovery is the beginning of learning.

Resolve the incident, preserve the response timeline and carry follow-up work into a postmortem with accountable owners.

Read the operational guide

KNOW BEFORE PRODUCTION

Validate the boundary, not just the happy path.

Use a test service and representative provider configuration before treating incident command as production incident infrastructure.

  1. 01Verify service ownership and responder permissions on a test service.
  2. 02Confirm response-policy and support-hours context before interpreting SLA timing.
  3. 03Exercise acknowledgement, assignment, resolution and postmortem handoff end to end.
DOCUMENTATIONSetup, authorization, limits, and troubleshooting.
Explore incident command documentation

Your incidents should belong to you.

Run OpsKnight on infrastructure you control.

v2.0.0 · AGPL-3.0-only · Self-hosted · 28 inbound integrations