Incidents & Escalation
A trigger is one HTTP call. Everything that follows - who is alerted, in what order, for how long, and when it stops - is the incident. This page is that lifecycle, start to finish.
From Trigger to Incident
Section titled “From Trigger to Incident”When a trigger arrives, two things can hold it before anyone hears about it:
- The false alarm delay, if the mode sets one. A
disarminside the delay cancels the trigger outright - no incident ever opens, though the trigger is still recorded. See Arming. - An incident already open on that alarm. The trigger folds into it - recorded against the incident, alerting nobody new. This is why three sensors tripping in one break-in produce one incident and one escalation, not three voice calls each. The alarm’s activity log shows the burst as one Triggered row with a count; click it to see every trigger and its time.
Otherwise the incident opens and the mode’s policy starts running.
Two deliberate exceptions, both set per mode on the alarm:
- A mode with no policy still opens an incident - the alarm reads as triggered everywhere, the incident sits in your timeline with a No Policy Attached band, and you still get the owner emails - but nobody is contacted. Use it when you want the record without the response.
- A Local Only mode goes one step further: the alarm reads as triggered to Home Assistant and your automations, the trigger is logged in the alarm’s activity, and no incident opens at all - nobody is contacted, you get no email, nothing counts against your usage. There is nothing to clear: the alarm returns to its armed mode on its own after two minutes, or as soon as you disarm it.
Escalation Runs Until Someone Acknowledges
Section titled “Escalation Runs Until Someone Acknowledges”A policy is ordered levels, each naming specific people - and for each person, the channel to reach them on (SMS, voice, or email) - plus how long to wait before moving on. When the incident opens, level 1 is alerted. If nobody acknowledges before the level’s wait runs out, the next level is alerted, and so on. A policy set to repeat starts over at level 1 when the last level’s wait expires, up to its configured number of rounds.
Every alert carries an acknowledgment link on alert.openalarm.io - tell your contacts to
expect that address. The moment any contact taps it, escalation stops - no further levels, no
further rounds. The incident records who acknowledged and when, which is the
question you will actually have at 3am: did anyone see this?
Acknowledgment stops the alerting. It does not end the incident.
Acknowledged Is Not Ended
Section titled “Acknowledged Is Not Ended”An incident distinguishes three things that are easy to collapse:
| State | Meaning |
|---|---|
| Acknowledged | Someone saw it and said so. Escalation stops. |
| Unanswered | Every level and round ran and nobody acknowledged. Alerting is over; the incident stays open. |
| Ended | The event has been dealt with. The alarm can raise a fresh incident again. |
The distinction exists because an open incident is the alarm’s memory: something happened here and nobody has closed it out. Real alarm panels keep that memory after the siren stops, and so does this.
The Three Ways an Incident Ends
Section titled “The Three Ways an Incident Ends”clear- the deliberate path, from the API or the console.- A configured
disarm- each alarm chooses whether disarming also ends an open incident. On by default; turn it off and disarming silences nothing. - The 24-hour auto-close - a day after escalation ends with no clear, the incident closes on its own, marked as expired rather than cleared. A forgotten incident must never suppress the alarm forever - while an incident is open, new triggers fold instead of alerting.
Ending an incident never changes the arming state. An alarm armed Away when it fired is still armed Away after the incident ends, and alerts again on the next trigger.
Reading the Timeline
Section titled “Reading the Timeline”Every alert on an incident is its own row - who, on which channel, with a status that walks its channel’s ladder and wears one of four colors:
| Color | Meaning | Statuses |
|---|---|---|
| Blue | in flight | Queued, Sent, Calling… |
| Green | confirmed | Delivered, Opened, Connected, Acknowledged |
| Red | failed | Bounced, Undelivered, No Answer, Busy |
| Grey | context | Ended, Skipped, upcoming steps, policy notes |
The ladders per channel:
- Email: Queued -> Sent -> Delivered -> Opened (failure: Bounced)
- SMS: Queued -> Sent -> Delivered -> Opened (failure: Undelivered)
- Voice: Queued -> Calling… -> Connected -> Ended, or Connected -> Voicemail when the call is picked up by an answering machine (failures: No Answer, Busy)
Queued means the alert is committed and waiting its turn with the provider. It normally lasts well under a second. If a provider is slow or throttling, the alert waits in the queue and retries rather than failing; it is never dropped. Skipped means the incident ended before the alert went out, so it was withheld rather than delivered late.
Delivered means the receiving server or carrier confirmed it. Opened means that contact visited their own alert link - each alert carries a unique link, so an open is tied to exactly one notification, with no tracking pixels involved. Connected means the call was picked up, which is exactly why it is not the finish line, and Ended records when the call finished. Voicemail means we detected an answering machine and left the alert as a recorded message instead of the keypad menu; it is the final state for that call, so a voicemail is never relabelled Ended. Acknowledged is the only state that certifies a human, and it sits above every channel.
Every step keeps its own timestamp on the record - when it was sent, delivered, opened, connected, ended, and when each contact responded - and every contact’s row is independent: if three people open the alert and two acknowledge, all five facts are recorded with their times. While the incident is live, everything records, including acknowledgments after the first. The moment it is cleared or expires, the record is final - the downloadable archive is the authoritative account of exactly what happened, and nothing rewrites it afterward.
What the Account Owner Sees
Section titled “What the Account Owner Sees”The owner is told by email as the incident moves: when it opens, when someone acknowledges (named, so you know who has it), and when it ends - and the closing email carries the verdict, including “Nobody acknowledged it” when escalation ran out unanswered. In between, the incident page in the console carries the live detail - who was alerted, on what channel, at what level, and who acknowledged.
On a test trigger the chain runs on its real timeline and records everything - each contact’s delivery marked suppressed, at the level and time they would have been reached - and nobody is contacted, the owner emails included. A contact who could not have been alerted even live is marked skipped, with the reason, so the gaps in a chain show up while you can still fix them. See the Test Mode guide.
Every plan includes a usage limit of incidents - every live incident that opens, whether or not its policy alerts anyone. Arming, disarming, repeat triggers folding into an open incident, test triggers, and triggers on a Local Only mode never count. The limit is per account and resets on the 1st of every month: 5 incidents a month on Free, 25 during the Pro trial, and 250 on Pro. Current usage lives in the console on every Account page, under Current Plan.
Past the limit, incidents still open and are recorded, and the owner is still emailed about each one, but no contact is alerted until your usage resets on the 1st. Every step of the policy shows as skipped on the timeline with the reason, and the policy does not repeat. The owner is warned by email at 80% of the limit and when it is reached, and while over it each incident’s opened email says so. A Silent Mode incident sends you nothing, limit or not.
Panic Buttons
Section titled “Panic Buttons”A panic press follows the same lifecycle with the front cut off: no modes, no false alarm delay -
the incident opens immediately. A panic button has no disarm, so
clear is the only way a machine caller ends one.