Manual incidents
Automated incidents only know what checks can see: the target stopped answering, then it answered again. Manual incidents are how staff put everything else on the record — and, when a client is attached, how you explain an outage in the client's own portal.
When to write one
- Contextual outages. The fiber cut at the client's office, the upstream provider's failure, the power event — checks catch the symptom, but the record should carry the cause.
- Client-visible explanations. The portal shows each client their last 10 incidents — title, body, start time, and "resolved in N minutes". A manual incident with a clear body is often the only place the client reads what actually happened. See client portal overview.
- Things checks can't detect. A broken feature behind a healthy homepage, a batch job that failed, planned work you want documented — nothing in the check stream will ever record these.
The fields
- Client — optional, and the visibility switch. Left blank, the incident is internal: it never appears in any portal. Set, it appears in that client's portal incident list.
- Monitor — which monitored system the incident concerns.
- Severity — Info, Degraded, or Outage; your call. How to choose: incident severities.
- Status and the Started / Resolved times — log a live incident as open, or backfill one that's already over by entering both times. Times are entered in the workspace timezone; see site and workspace timezones.
- Title and body, in Arabic and English. Write both. Clients read incidents in the portal, and you don't control which language a given reader uses — a blank half means someone gets an empty explanation.
Resolving
An open manual incident has a one-click Resolve button: press it and the incident closes with the current time as its resolution. If the real end was earlier, edit the incident and set the resolved time yourself — the "resolved in N minutes" figure the client sees is computed from these two timestamps, so they're worth getting right.
Alerts fire the same way
Manual incidents go through the same notification path as automatic ones: opening one emails all active staff, and so does resolving it — see email alerts. For the fully automatic lifecycle they complement, see how incidents open and close.