Skip to content

How alerting works

1 · ALERT — machine Detected by the engine DOWN PARTIAL kept for the plan’s retention, even with no channel attached

2 · INCIDENT — human What you communicate severity · status · updates published on the status page created from an alert in one click

3 · ESCALATION Who, in what order 1 · now→ Slack 2 · +10 min→ PagerDuty 3 · +30 min→ Email until someone acknowledges

4 · CHANNELS Slack Email PagerDuty Webhook +14 more

Dashboard › Alerting: Alerts (history, acknowledge, CSV) · Incidents · Escalation · Channels · Maintenance One rule: a piece of information lives in one place. The bell in the top bar carries product notifications only, never monitoring alerts. The org status pill in the top bar and the “Alerts” badge in the sidebar are the permanent signals.

The Alerting section of the dashboard is built around five objects, each with its own page — and one rule: a piece of information lives in exactly one place.

PageWhat it holds
AlertsEvery event the engine detected — down, partial outage, degraded, recovered, SSL expiry — notified or not.
IncidentsWhat you declare and communicate: severity, status, updates, publication on the status page.
EscalationWho gets notified, in what order, after how long without an acknowledgement.
ChannelsThe destinations: Slack, email, PagerDuty, webhooks… (eighteen of them, see below).
MaintenancePlanned windows that silence alerts for the monitors they cover.

The bell in the top bar is for product notifications (visitor reports on your status pages, billing) — never for monitoring alerts. The permanent monitoring signal is the status pill in the top bar and the Alerts badge in the sidebar.

  1. Detection — an agent’s check fails. The engine applies the retry window and, for multi-region monitors, the majority rule (see Status & uptime). Only a confirmed state change raises an alert.
  2. Alert — one row in the Alerts log: what, when, which monitor, with the evidence. Acknowledging it there is what “someone is on it” means to OKStatus.
  3. Notification — the alert is pushed to every channel attached to the monitor, filtered by the alert kinds each channel accepts. What was sent, and whether it was delivered, is stored on the alert.
  4. Escalation — on Max and Enterprise, an escalation policy keeps going after level 1: more channels after N minutes without acknowledgement, optionally repeated, until someone acknowledges.
  5. Communication — you decide what the outside world sees: an incident on the status page, a scheduled maintenance window that silences alerts ahead of planned work, and subscriber emails that go out on their own.
SituationAlerts raised?Channels called?Status page
Monitor pausedNo — no checks runNoShown as paused
Monitor mutedYes, loggedNoReal status
Inside a maintenance windowNoNo“Under maintenance”
Alert acknowledgedAlready raisedEscalation stops; recovery still sentUnchanged
No channel attachedYes, with a “no channel” badgeNothing to callUnchanged