Incidents
An incident represents a single open problem raised by a rule for a specific resource. Incidents open when a rule’s condition is breached, recover automatically when things return to normal, and can be muted to suppress notifications during known work.
The Incident Lifecycle
- Open — a rule’s condition is breached, an incident opens, and the rule’s channels are notified.
- Ongoing — repeated breaches while the incident is open increment its occurrence count rather than sending a new notification, so you are not flooded while a problem persists.
- Recovered — on the next clean run for that resource, the incident recovers automatically and a recovery notification is sent.
You are notified only on a state change — when the incident opens and when it recovers — never repeatedly in between.
A Run success rule is the exception: it notifies its channels and raises nothing, so it never appears here.
Viewing Incidents
Navigate to Alerts → Incidents. Open incidents are listed first, then recovered ones. You can filter by state (all, open, or recovered).
Each incident shows:
- The rule that raised it
- The severity (critical or warning)
- The resource it concerns
- Its state (open or recovered)
- When it opened
- How many times it has occurred
From the Resource Itself
Journeys, loaders, identity graphs, audience syncs and store feeds each carry an Alerts tab showing the rules watching that resource and the incidents they have raised, with a New alert button that opens the rule form already scoped to it. It is the quickest way to answer “is anything watching this, and has it fired?” without leaving the thing you are looking at.
Muting
Muting suppresses notifications for an incident without closing it — useful during known maintenance or while you work on a fix. Mute an open incident for:
- 1 hour
- 1 day
- Indefinitely
A muted incident is clearly marked. You can unmute it at any time to restore notifications. Muting requires the alerting.write permission.
Permissions
alerting.read— view incidents.alerting.write— mute and unmute incidents.
Endpoints
GET /api/v1/workspaces/{id}/alert-incidents
POST /api/v1/workspaces/{id}/alert-incidents/{incidentId}/mute
POST /api/v1/workspaces/{id}/alert-incidents/{incidentId}/unmuteThe mute call takes a duration of 1h, 1d or forever.
Next Steps
- Rules — Tune what raises incidents
- Channels — Where incident notifications go
- In-Warehouse Log — Query the full history behind incidents in SQL