/incidents) is your full list view of every incident — open, closed, and in-progress — across your environment. You can search, filter, and drill into any incident from here.
What is an incident?
An incident is opened automatically when an alert fires and sureops determines it meets the threshold for agent-driven response. Each incident tracks the full lifecycle from first detection through root-cause diagnosis, fix execution, metric verification, and formal closure. Incidents are scoped to an environment. Use the context switcher in the sidebar to view incidents for a different environment.Lifecycle stages
Every incident progresses through up to six stages:Severity levels
The severity is set by the agent during the triage stage based on the alert payload, error rate, affected service tier, and blast radius. You can override it from the Incident Hub.
Status badges
Each incident in the list has a status badge showing its current stage and health:- Open — actively in progress
- Resolved — fix applied and metrics verified
- Closed — formally closed with a summary
- Cancelled — dismissed without action (e.g., a proactive detection that self-healed)
- Held / Flapping — agent has paused due to a pattern it treats as flapping or self-healing; will resume if the anomaly persists
Filtering incidents
Use the filter bar to narrow the list:- Status — open, resolved, closed, cancelled
- Severity — P1 through P4
- Stage — detection, triage, diagnosis, resolution, verification, closure
- Search — full-text search on incident title and service name
Creating an incident manually
In most cases incidents are opened automatically by incoming alerts. You can also open an incident manually:- Click New incident in the top-right of the Incidents page.
- Enter a title and select the environment and severity.
- Optionally link the incident to an affected service from your service catalog.
- Click Create — the Incident Commander agent picks it up immediately.
Manually created incidents follow the same lifecycle as alert-triggered ones. The difference is that the detection stage context will be minimal until the agent queries telemetry.