Skip to content
Firewatch
Get started
Site

Alert lifecycle

Firewatch separates the signal that something happened from the decisions needed to reach and coordinate the right responder.

An alert source sends a versioned request to Firewatch. Authentication, idempotency, correlation, and signature validation are applied before an alert event changes response state.

The affected service selects an escalation policy. Each policy step resolves the on-call schedule at that moment, including time zones and active overrides.

Firewatch creates notification work for the responder’s verified and enabled channels. Email, Slack, SMS, voice, and outgoing webhooks remain independently observable so one failing provider does not erase the incident record.

Acknowledgement assigns visible ownership. If nobody acknowledges before the configured timeout, the policy advances to the next step without rewriting history.

The incident timeline, responders, runbooks, and delivery attempts preserve a single operational record. Templates can make delivery channel-specific while keeping the underlying incident facts consistent.