Alert lifecycle
Firewatch separates the signal that something happened from the decisions needed to reach and coordinate the right responder.
1. Ingest
Section titled “1. Ingest”An alert source sends a versioned request to Firewatch. Authentication, idempotency, correlation, and signature validation are applied before an alert event changes response state.
2. Resolve ownership
Section titled “2. Resolve ownership”The affected service selects an escalation policy. Each policy step resolves the on-call schedule at that moment, including time zones and active overrides.
3. Deliver
Section titled “3. Deliver”Firewatch creates notification work for the responder’s verified and enabled channels. Email, Slack, SMS, voice, and outgoing webhooks remain independently observable so one failing provider does not erase the incident record.
4. Escalate or acknowledge
Section titled “4. Escalate or acknowledge”Acknowledgement assigns visible ownership. If nobody acknowledges before the configured timeout, the policy advances to the next step without rewriting history.
5. Coordinate and learn
Section titled “5. Coordinate and learn”The incident timeline, responders, runbooks, and delivery attempts preserve a single operational record. Templates can make delivery channel-specific while keeping the underlying incident facts consistent.