Incidents
Incident Lifecycle
Four states only. Forward motion through investigation — no reopen after resolve.
States
- investigating — incident opened; team is diagnosing.
- identified — cause understood enough to act.
- monitoring — fix applied; watching recovery.
- resolved — closed; optional RCA fields may be filled.
Transitions
Operators move forward along investigating → identified → monitoring → resolved. Illegal transitions are rejected by the server — including any attempt to leave resolved back into an open state.
Resolve
Resolve from the incident detail (/app/incidents). Public updates written before resolve can appear on status pages when publish is enabled; internal notes stay workspace-only.
Limitations
- There is no supported reopen. A new outage opens a new alert and incident path.
- Lifecycle labels are investigation state — not a substitute for monitor severity.