Skip to content

Incidents & Escalation

A trigger is one HTTP call. Everything that follows - who is alerted, in what order, for how long, and when it stops - is the incident. This page is that lifecycle, start to finish.

When a trigger arrives, two things can hold it before anyone hears about it:

  • The false alarm delay, if the mode sets one. A disarm inside the delay cancels the trigger outright - no incident ever opens, though the trigger is still recorded. See Arming.
  • An incident already open on that alarm. The trigger folds into it - recorded against the incident, alerting nobody new. This is why three sensors tripping in one break-in produce one incident and one escalation, not three phone calls each.

Otherwise the incident opens and the mode’s policy starts running.

Escalation Runs Until Someone Acknowledges

Section titled “Escalation Runs Until Someone Acknowledges”

A policy is ordered levels, each naming specific people - and for each person, the channel to reach them on (SMS, voice, or email) - plus how long to wait before moving on. When the incident opens, level 1 is alerted. If nobody acknowledges before the level’s wait runs out, the next level is alerted, and so on. A policy set to repeat starts over at level 1 when the last level’s wait expires, up to its configured number of rounds.

Every alert carries an acknowledgment link. The moment any contact taps it, escalation stops - no further levels, no further rounds. The incident records who acknowledged and when, which is the question you will actually have at 3am: did anyone see this?

Acknowledgment stops the alerting. It does not end the incident.

An incident distinguishes three things that are easy to collapse:

State Meaning
Acknowledged Someone saw it and said so. Escalation stops.
Unanswered Every level and round ran and nobody acknowledged. Alerting is over; the incident stays open.
Ended The event has been dealt with. The alarm can raise a fresh incident again.

The distinction exists because an open incident is the alarm’s memory: something happened here and nobody has closed it out. Real alarm panels keep that memory after the siren stops, and so does this.

  1. clear - the deliberate path, from the API or the console.
  2. A configured disarm - each alarm chooses whether disarming also ends an open incident. On by default; turn it off and disarming silences nothing.
  3. The 24-hour auto-close - a day after escalation ends with no clear, the incident closes on its own, marked as expired rather than cleared. A forgotten incident must never suppress the alarm forever - while an incident is open, new triggers fold instead of alerting.

Ending an incident never changes the arming state. An alarm armed Away when it fired is still armed Away after the incident ends, and alerts again on the next trigger.

Every alert on an incident is its own row - who, on which channel, with a status that walks its channel’s ladder and wears one of four colors:

Color Meaning Statuses
Blue in flight Sent, Calling…
Green confirmed Delivered, Opened, Connected, Acknowledged
Red failed Bounced, Undelivered, No Answer, Busy
Grey context Ended, queued steps, policy notes

The ladders per channel:

  • Email: Sent -> Delivered -> Opened (failure: Bounced)
  • SMS: Sent -> Delivered -> Opened (failure: Undelivered)
  • Voice: Calling… -> Connected -> Ended (failures: No Answer, Busy)

Delivered means the receiving server or carrier confirmed it. Opened means that contact visited their own alert link - each alert carries a unique link, so an open is tied to exactly one notification, with no tracking pixels involved. Connected means the call was picked up - by a person or their voicemail, which is exactly why it is not the finish line - and Ended records when the call finished. Acknowledged is the only state that certifies a human, and it sits above every channel.

Every step keeps its own timestamp on the record - when it was sent, delivered, opened, connected, ended, and when each contact responded - and every contact’s row is independent: if three people open the alert and two acknowledge, all five facts are recorded with their times. While the incident is live, everything records, including acknowledgments after the first. The moment it is cleared or expires, the record is final - the downloadable archive is the authoritative account of exactly what happened, and nothing rewrites it afterward.

The owner is told by email as the incident moves: when it opens, when someone acknowledges (named, so you know who has it), and when it ends - and the closing email carries the verdict, including “Nobody acknowledged it” when escalation ran out unanswered. In between, the incident page in the console carries the live detail - who was alerted, on what channel, at what level, and who acknowledged.

On a test trigger the chain runs on its real timeline and records everything - each contact’s delivery marked suppressed, at the level and time they would have been reached - and nobody is contacted, the owner emails included. A contact who could not have been alerted even live is marked skipped, with the reason, so the gaps in a chain show up while you can still fix them. See the Test Mode guide.

Every plan includes a usage quota of incidents - live incidents that actually dispatch to contacts. Arming, disarming, repeat triggers folding into an open incident, and test triggers never count. The quota is per account over a rolling 30-day window: 5 incidents on Free, 250 on Pro. Current usage lives in the console on every Account page, under Current Plan.

An alarm is never silently dropped. Past the quota, incidents still open, run their full escalation, and record everything - but contacts are alerted by email only until your trailing 30-day usage falls back under the quota. SMS and voice steps show as skipped on the timeline with the reason, the same way any unreachable channel does. The owner is warned by email at 90% of the quota, when it is reached, and on every trigger while over it.

A panic press follows the same lifecycle with the front cut off: no modes, no false alarm delay - the incident opens immediately. A panic button has no disarm, so clear is the only way a machine caller ends one.