WarnFireDocs

Incident response

A Slack channel for every incident

Create a Slack war room for each qualifying incident and preserve its operational record.

Version 1.0 Status Needs verification For Tenant administratorsFor Responders slackwar-roomintegrations

WarnFire can create a dedicated Slack channel when an incident opens, add the paged responders, post response controls, and archive the channel after resolution.

Slack war rooms are optional. A Slack failure does not stop incident creation or paging through the configured notification channels.

Before you begin

Connect Slack and authorize at least one responder before enabling war rooms. A service route is optional for a dedicated war room; routing and war-room creation are independent Slack destinations. You need tenant-owner or tenant-administrator access and a Slack installation with the channel-management scopes shown as current. If WarnFire asks you to reconnect, complete that step before continuing.

Configure war rooms

  1. Open Integrations → Slack.
  2. Complete or reconnect the Slack installation if WarnFire reports missing scopes.
  3. Under Incident war room, enable Open a channel for every incident.
  4. Configure the available options:
    • Make it private limits the channel to invited members.
    • Archive the channel when the incident resolves schedules archival after the closing summary.
    • Channel prefix sets the beginning of generated channel names.
  5. Select Save war room settings.

The tenant-wide Configuration → Settings → War rooms controls also determine whether a room is created and which severities qualify. Both Create war rooms automatically there and Open a channel for every incident on the Slack installation must be enabled.

Public rooms use channels:manage; private rooms use groups:write. Inviting a paged responder by verified email also requires users:read and users:read.email. If any required scope is missing, reconnect before testing.

When an incident opens

WarnFire:

  1. Creates the channel and sets its topic.
  2. Posts the incident summary with Acknowledge and Resolve controls.
  3. Adds the responders paged for the incident when their WarnFire and Slack identities can be matched.
  4. Records the war-room opening on the incident.

WarnFire records a newly created channel before it posts or invites. If Slack or the network fails between those steps, a retry reuses that recorded channel instead of creating another room.

A responder who later accepts an assistance request is added to the channel when a Slack identity is available.

Find and use the room

The web incident workspace includes a War Room tab with the channel link and recorded war-room activity. The mobile app does not have a separate War Room tab; it includes war-room events and notes in the incident’s unified Activity view.

The Open war room link belongs to the war-room-opened activity record. After the room is closed and archived, the incident retains its historical reference.

Record an incident note from Slack

Use the Slack command:

/wf note failover to the replica completed

WarnFire records the note with the author and time. It appears in Slack and in the incident’s activity history, making key decisions searchable after the incident.

Resolution and archival

When the incident resolves, WarnFire posts a closing summary. The summary says that archival is scheduled only when both the tenant-wide archive switch and Archive the channel when the incident resolves on the Slack installation are enabled. It includes the configured delay. If either switch is off, the summary makes no archive promise and the channel remains open.

If the WarnFire Slack app is no longer a channel member, WarnFire attempts to rejoin before archiving. Channel creation, incident posting, responder invites, status posts, and archival all use bounded retries. The Slack integration page shows the operation, attempt count, provider error, and whether WarnFire is still retrying or has stopped. After correcting the cause, select Retry failed Slack deliveries.

Troubleshooting

  • If nobody is added, compare each responder’s WarnFire email with their Slack identity and review Authorize responders in the Slack integration.
  • If channel creation is disabled, check both tenant coordination settings and the Slack installation’s Incident war room switch.
  • If WarnFire reports missing scopes, use Reconnect Slack and approve the requested permissions.
  • If a removed email-matched responder does not return automatically, that is intentional. Create an explicit responder link to authorize them again.
  • Use the incident activity record and Delivery Activity to distinguish a paging problem from a Slack-only problem.

Verify it worked

  1. Send a test alert through a service that meets the configured severity threshold. The alert follows the real escalation policy: SMS and voice attempts consume credits and can trigger automatic recharge. Push and email are free.
  2. Confirm that Slack creates a channel with the configured prefix and posts the matching incident summary.
  3. Confirm that the paged responder is added when their Slack identity is linked and that the web incident workspace shows the same channel under War Room.
  4. Resolve the test incident and confirm that Slack posts the closing summary.
  5. If automatic archival is enabled, confirm that the channel archives after the exact delay shown in workspace operational settings .
  6. Return to Integrations → Slack and confirm that no war-room operation is marked retrying or failed.

Next step

Review the WarnFire Slack commands that responders can use inside the incident channel.