WarnFireDocs

Incident response

Incident response

Understand acknowledgement, escalation, assistance, activity, and resolution in WarnFire.

Version 1.0 Status Needs verification For RespondersFor Tenant administrators incidentsacknowledgementresolutionassistance

WarnFire keeps one incident record from the first trigger through resolution. Updates to the same correlated problem stay attached to that record, while operational actions and delivery evidence remain available in its activity history.

Configure the response path

Build configuration in dependency order:

  1. Add responders who can receive pages.
  2. Optionally create teams for shared ownership or all-member paging.
  3. Create schedules that resolve who is on call.
  4. Create escalation policies that target responders, schedules, or teams.
  5. Create a service and integration key and assign the policy.

Trigger and escalation

When an event opens an incident, WarnFire captures the escalation plan that applies at that moment. Later schedule or policy edits do not rewrite the plan for an incident already paging.

WarnFire pages the configured responder or schedule and proceeds through the escalation steps until the incident is acknowledged, resolved, or the policy is exhausted.

Acknowledgement

Acknowledgement records the responder who has taken ownership and stops further automatic escalation for that incident. It does not resolve the underlying monitoring condition.

  • In the mobile app, open the incident and tap Acknowledge. Device authentication is required.
  • In the web console, open the incident and use Acknowledge.

The state change synchronizes across signed-in devices and appears in the incident activity record.

Unified activity

The incident workspace preserves the operational story, including:

  • Trigger, update, acknowledgement, escalation, and resolution events.
  • Notification dispatch and delivery evidence.
  • Assistance requests and decisions.
  • War-room creation, notes, and closure.

The mobile app presents these records in unified Activity. The web console also provides focused operational tabs, including resources and war-room details.

Add people during an incident

From the web incident workspace, choose Add resource. In the mobile app, open the incident’s Response view. Either path can request help from a responder, the current on-call responder for a team, or an entire tiger team.

The invitee receives a one-page mobile brief and can Join incident now, commit for In 15m / 30m / 60m, Decline request, or later Leave incident. Assistance adds people to the response without changing the frozen paging plan or transferring acknowledgement.

See Building the response team .

Resolution

A matching recovery or resolve event closes the incident after its known firing signals recover.

If an incident is stuck, an authorized operator can use Force resolve in the web console. WarnFire requires a reason and records the operator, reason, and remaining firing-signal count. A later firing event creates a successor incident; force resolution does not permanently suppress monitoring.

The mobile app can acknowledge incidents but cannot resolve them.

See Incident lifecycle for correlation and force-resolution behavior.

Continue with a task