Updated 2026-09-29
An incident is Status's record of a problem with a check: when it started, when it ended, and what caused it. Your team works incidents from the Incidents page in the dashboard.
What opens an incident
Incidents open automatically. The kinds are:
- Down — the check failed and was confirmed (see How multi-region confirmation works).
- Slow response (degraded) — response times stayed over the threshold you set. See Alert policies.
- SSL — a certificate problem on an SSL check.
- Domain — a domain check found the domain unregistered or expired.
- Missed heartbeat — a heartbeat check-in didn't arrive within its grace period.
Acknowledge
Acknowledging an incident tells your team someone is handling it. It also stops re-alerts and escalation for that incident, and each channel that was alerted gets one "acknowledged" notice.
Internal notes
Add notes for your team as you work. Notes are never shown on a status page.
Public updates
Post an update to the incident's timeline with one of four statuses: Investigating, Identified, Monitoring or Resolved. Updates are shown on your status page if the check is on one. Posting Resolved closes the incident.
Open an incident manually
If something is wrong that your checks didn't catch, open an incident by hand. You attach it to a check and give it a cause and a description. This needs the Open incidents manually permission (see Invite your team and choose roles).
What subscribers are told
If the status page has email subscribers, the "incident opened" notice waits at least 2 minutes (or the check's alert delay, if that is longer), so a short blip doesn't email them. Incidents that start inside a maintenance window don't notify them.
How long history is kept
Incident history is kept for 90 days on Starter, 365 days on Professional and 730 days on Enterprise. See the pricing page.