incident.io
Also known as: Incident.io AI SRE
Incident management platform in Slack and Teams with an AI investigation agent that works incidents from declaration, public per user pricing, and root cause analysis from the Pro plan.
incident.io approaches the SRE lane from the coordination side: it is an incident management platform for on call, incident response, status pages and postmortems that runs natively in Slack and Microsoft Teams, creating incident channels, paging responders from alerts raised by the customer's monitoring tools, and running workflows built from more than twenty triggers, conditions, delays and loops.
Its AI investigation agent starts work the moment an incident is declared, connecting telemetry, code changes and past incidents to name what broke, with a confidence score, an investigation timeline of its reasoning and sources behind every hypothesis. It never acts on systems itself: the only change it can make is a pull request the team reviews and merges, and AI suggested updates, summaries and follow ups wait for a person to share, edit or dismiss them. A Nexus memory keeps the queries that worked against each data source as worked examples for later investigations, and the vendor backtests the agent against historical incidents daily.
Pricing is public: a free Basic tier, Team at $19 per user per month ($15 with the annual discount), Pro at $25 with root cause analysis and the autonomous agent, and custom Enterprise. On call costs $10 per user on Team or $20 on Pro. The service runs on Google Cloud in European regions with no region choice documented, holds SOC 2 Type I and II, and exposes a REST API, webhooks, Terraform support and a remote MCP server.
Vendor details
Canonical URL
https://incident.io
Category
SRE / DevOps agent
Subcategory
Incident management with AI SRE
Funding status
Independent, and it stayed that way while rivals consolidated: Freshworks acquired FireHydrant in early 2026, but incident.io remains an independent company focused on incident management. Customers shown on its site include Netflix, Etsy, Intercom, Vanta, monday.com, Skyscanner, and Airbnb.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Operates natively in Slack and Microsoft Teams across incident response, on call, investigations and status pages. Turns alerts from monitoring, error tracking and ticketing tools into pages and incidents, connects to telemetry and code for investigations, and exposes a REST API, webhooks, Terraform workflow management and a remote MCP server.
In practice
Your incident response is chaos across DMs and calls. incident.io declares the incident in Slack, opens a channel, pages the right responders, and runs the workflow automatically.
You want AI investigation without an Enterprise contract. incident.io includes root cause analysis and its autonomous agent from the Pro plan at $25 per user, with pricing published up front.
Postmortems never get written. The AI drafts summaries and follow ups from the incident channel for a responder to accept, edit or dismiss.
Sources & related URLs
Agentic Index coverage score
10.0 / 14 capabilities · 71%
| Integrations & Tool Calling | Full |
|---|---|
|
A named alert source catalog across monitoring, error tracking and ticketing tools, workflow steps that act in Slack and send webhooks, and Investigations that query telemetry and code and open pull requests; API and webhooks on the pricing chart. Sourceincident.io help center index (alert sources, workflows), Investigations page and pricing page; docs.incident.io/workflows/getting-startedread 2026-09-29 |
|
| Workflow Orchestration | Full |
|
Workflows run multi step automations from more than twenty triggers, with conditions on severity, role, status and message content, delays, loops, expressions, decision flows and webhooks, managed in the UI or Terraform; Investigations work several hypotheses in parallel. Sourceincident.io docs, Getting started with Workflows and help center index; docs.incident.io/workflows/getting-startedread 2026-09-29 |
|
| Knowledge Grounding & RAG | Partial |
|
Investigations connect telemetry, code changes and past incidents per run, and the Catalog is a maintained map of services, teams and escalation paths synced from service catalogs; but no published page shows the investigation retrieving from a maintained index, and the Nexus claim of access to all context is marketing. Sourceincident.io AI SRE page and docs, Using the Catalog; docs.incident.io/catalog/catalog-setupread 2026-09-29 |
|
| Human Oversight & Guardrails | Full |
|
AI suggested updates, summaries and follow ups wait for a person to choose 'Share update, Edit before sharing and Dismiss' or 'Accept and set, Edit before setting and Dismiss' before they apply; Investigations 'never takes action without you', the only change being a pull request the team merges; role restrictions govern who may act. Sourceincident.io docs, Suggestions, and Investigations page; docs.incident.io/ai/suggestionsread 2026-09-29 |
|
| Security, Identity & Governance | Full |
|
Admins get SAML single sign on, SCIM provisioning that syncs roles and seats, base roles with custom permissions, team roles and role restrictions, and audit logs of configuration and permission changes. Certifications cover SOC 2 Type I and II and GDPR, and penetration test results sit in the trust center. Sourceincident.io security page and help center index (admin pages)read 2026-09-29 |
|
| Observability & Auditability | Full |
|
'An investigation timeline lets you follow the agent's reasoning from first signal to final conclusion' and 'Every hypothesis links back to its sources'; workflow runs keep an Activity history with run time, incident and status, and incident activity log entries are exposed by API. Sourceincident.io Investigations page and docs, Getting started with Workflowsread 2026-09-29 |
|
| Memory & State Persistence | Partial |
|
Nexus Memory is 'a learned library of the queries that have actually worked for your data sources, built from your own investigations', scoped to the organization, data source and query kind and drawn on as worked examples; its lifetime is stated only as vendor curation, and no customer view, edit or delete path is documented. Sourceincident.io docs, Memory; docs.incident.io/nexus/telemetry/memoryread 2026-09-29 |
|
| Deployment & Data Residency | Not documented |
|
SaaS on Google Cloud in European regions, the one hosting sub-processor named; no region choice, customer environment or self hosting is documented, so the disclosed region is a fact about the vendor's infrastructure, not an offering. Enterprise 'multiple environments' is not described as a deployment option. Sourceincident.io sub-processors page and pricing pageread 2026-09-29 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Six workflow templates ship in the Create workflow drawer for customers to adopt, beside incident and escalation path templates exposed by the API; the template names themselves are not listed in the docs. Sourceincident.io docs, Getting started with Workflows, and API reference index; docs.incident.io/workflows/getting-startedread 2026-09-29 |
|
| Triggers & Channel Coverage | Full |
|
Alerts from monitoring tools page on call and open incidents; 'The moment an incident is declared, Investigations has already done a first pass'; workflows fire on incident changes, channel messages and recurring schedules, in Slack and Microsoft Teams. Sourceincident.io Investigations page and docs, Getting started with Workflowsread 2026-09-29 |
|
| Model Flexibility & Routing | Partial |
|
Anthropic and OpenAI are named as AI sub-processors, with zero data retention agreements; that is vendor internal use of two providers, and no customer or admin model choice is documented. Sourceincident.io sub-processors page and AI SRE pageread 2026-09-29 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
A public REST API at api.incident.io with bearer API keys, published as 76 OpenAPI specifications covering incidents (list, create, edit), alerts, catalog, schedules, escalations, workflows and workflow runs, plus webhooks, Terraform management of workflows and a remote MCP server. Sourceincident.io docs, incidents-v2 OpenAPI spec and llms.txt index; docs.incident.io/openapi/tags/incidents-v2.jsonread 2026-09-29 |
|
| Testing, Debugging & Optimization | Partial |
|
'We backtest against real historical incidents daily, and alert on any degradation before it reaches you': a quality gate the vendor runs on its own agent, with confidence scores on findings. No evaluation surface the customer can invoke on its own configuration is documented. Sourceincident.io Investigations pageread 2026-09-29 |
|
| Browser & Computer Use | Not documented |
|
Works through Slack, Teams, integrations, workflows, an API and an MCP server; no browser, desktop or computer control is documented. Sourceincident.io help center index and Investigations pageread 2026-09-29 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
A new incident.io plugin bundles its remote MCP server with skills that teach agents how to use it, and is listed in the Claude Code, Cowork and Cursor plugin marketplaces. It supports several plugin formats and updates itself as new skills ship.
Bears on: MCP / tool calling / API
View sourceincident.io launched an update enhancing workflow automation and the actionability of its AI Agent. The release introduces a secure secrets store for workflows, the ability to sign workflow webhook requests, and triggers based on alert creation or resolution. Furthermore, the AI Agent has been upgraded to independently resolve incidents, direct escalations, and suggest both custom fields and timestamps during an active response.
Bears on: Workflow orchestration
View sourcePricing
Free Basic tier; Team $19 per user per month ($15 with the annual discount); Pro $25; on call add on $10 (Team) or $20 (Pro) per user
seats (per user per month), tiered plus on call add on
Included quota
Basic is free with limited automation and no API. Team adds multi team on call, AI features, unlimited integrations, and API access. Pro adds advanced insights, private incidents, custom postincident flows, and the full AI SRE.
What is public
All tier prices, the annual discount on Team, on call add on rates and the standalone on call price, and which tier carries each AI feature.
Billing mechanics
Self serve per user monthly subscriptions across four tiers, an annual discount on Team, and a per user on call add on or standalone on call seat. The AI investigation agent is bundled from Pro rather than sold separately.
Cost watchouts
On call is not in the seat price: it adds $10 per user on Team or $20 on Pro, so a Pro team that pages engineers pays about $45 per user a month. Root cause analysis and the autonomous agent need Pro, and advanced access control and multiple environments need Enterprise.
Variable cost rationale
Flat per user tiers with a per user on call add on; no usage metering on incident response, so cost scales with headcount rather than incident volume.
Additional watchouts
The headline seat price understates real cost once on call is added, and root cause analysis needs Pro. Detection comes from the customer's own monitoring tools, so budget for those separately.
Overage / add-ons
Seat based; on call priced as a per user add on. No usage metering published.
Sales call required
Mixed (some tiers require a call)
Free / trial
Free Basic tier with Slack or Teams response, single team on call and a status page; no trial period published
Lowest paid plan
Team at $19 per user monthly ($15 annually)
Commercial notes
Independent while FireHydrant was acquired by Freshworks. Customers include Netflix, Etsy, Intercom, Vanta, and Airbnb. Replaces incident coordination, status pages, and postmortem automation in one invoice.
Key ambiguities
Every tier price is published; the Enterprise price is not.
Related vendors
- AlertD — AI agents for AWS operations that run read only in the customer's…
- Anyshift — AI SRE built on a versioned knowledge graph of infrastructure, apps…
- Avesha — Obliq, Avesha's autonomous AI SRE for Kubernetes and agentic…
- Better Stack — Better Stack offers incident management with built in on call,…
- Bluebricks — Context and control layer that lets AI agents operate cloud…
- Cased — AI workflows for infrastructure and platform engineers: default and…
Alternatives to incident.io
The closest documented capability profiles to incident.io among SRE and DevOps agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Rootly10.5 / 14Fuller documented coverage on Knowledge Grounding & RAG and Memory & State Persistenceincident.io vs Rootly →
- Edge Delta12.0 / 14Adds documented Deployment & Data Residency
- PagerDuty11.0 / 14Adds documented Deployment & Data Residencyincident.io vs PagerDuty →
- Anyshift8.5 / 14Fuller documented coverage on Knowledge Grounding & RAG
- Better Stack9.5 / 14Adds documented Deployment & Data Residencyincident.io vs Better Stack →
- Bluebricks10.5 / 14Adds documented Deployment & Data Residency
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded