Incidents
Grouped operational issues with auto-correlation and lifecycle management.
What is an Incident?
An incident groups one or more related findings into a single operational issue. When a critical or warning-level finding is created, an incident is automatically opened.
Incident Lifecycle
| Status | Meaning |
|---|---|
| OPEN | Active issue — one or more linked findings are still open |
| ACKNOWLEDGED | Team is aware and working on it |
| RESOLVED | All linked findings have been resolved |
Incidents auto-close when all their linked findings resolve. They auto-reopen if a linked finding recurs.
Filtering on the Incidents page
The list is filtered by status using chips labeled Status → Active, Acknowledged, Resolved, or All. Active shows incidents in the OPEN state (same label on the row badge).
Deployment Correlation
Incidents automatically correlate with recent deployments (within a 20-minute window). If a deploy was recorded shortly before an incident opened, the incident shows which deployment likely caused it.
AI Analysis
When AI enrichment is enabled, each incident gets:
- AI Summary — Overview of what's happening across all linked findings
- AI Root Cause — Likely cause based on the findings pattern
- AI Triage Suggestion — Recommended next steps for resolution
Click Analyze with AI on any incident to trigger (or re-trigger) analysis.
Kloner Tasks Integration
When Kloner Tasks integration is configured, incidents can automatically create tasks for your development team to fix. Incidents show a Create k-task button (or display the linked task number if one already exists).
- Task creation routes to the configured project + list
- When the incident resolves, the linked task is automatically completed
- New findings on an open incident add comments to the task