Back to vendors
i

incident.io

Also known as: Incident.io AI SRE

Visit site
Entry priceFree Basic tier; Team $19 per user per month ($15 with the annual discount); Pro $25; on call add on $10 (Team) or $20 (Pro) per userFull pricing detail

Incident management platform in Slack and Teams with an AI investigation agent that works incidents from declaration, public per user pricing, and root cause analysis from the Pro plan.

incident.io approaches the SRE lane from the coordination side: it is an incident management platform for on call, incident response, status pages and postmortems that runs natively in Slack and Microsoft Teams, creating incident channels, paging responders from alerts raised by the customer's monitoring tools, and running workflows built from more than twenty triggers, conditions, delays and loops.

Its AI investigation agent starts work the moment an incident is declared, connecting telemetry, code changes and past incidents to name what broke, with a confidence score, an investigation timeline of its reasoning and sources behind every hypothesis. It never acts on systems itself: the only change it can make is a pull request the team reviews and merges, and AI suggested updates, summaries and follow ups wait for a person to share, edit or dismiss them. A Nexus memory keeps the queries that worked against each data source as worked examples for later investigations, and the vendor backtests the agent against historical incidents daily.

Pricing is public: a free Basic tier, Team at $19 per user per month ($15 with the annual discount), Pro at $25 with root cause analysis and the autonomous agent, and custom Enterprise. On call costs $10 per user on Team or $20 on Pro. The service runs on Google Cloud in European regions with no region choice documented, holds SOC 2 Type I and II, and exposes a REST API, webhooks, Terraform support and a remote MCP server.

Vendor details

Canonical URL

https://incident.io

Category

SRE / DevOps agent

Subcategory

Incident management with AI SRE

Funding status

Independent, and it stayed that way while rivals consolidated: Freshworks acquired FireHydrant in early 2026, but incident.io remains an independent company focused on incident management. Customers shown on its site include Netflix, Etsy, Intercom, Vanta, monday.com, Skyscanner, and Airbnb.

Company status

independent

Use cases & customers

Primary use cases

chat native incident responseon call scheduling and pagingAI incident investigation and fix draftingstatus pages and postmortems

Target customers

mid market engineering teamsSRE and DevOps teamsSlack and Teams first organizations

Deployment options

SaaS

Integrations

Operates natively in Slack and Microsoft Teams across incident response, on call, investigations and status pages. Turns alerts from monitoring, error tracking and ticketing tools into pages and incidents, connects to telemetry and code for investigations, and exposes a REST API, webhooks, Terraform workflow management and a remote MCP server.

In practice

Your incident response is chaos across DMs and calls. incident.io declares the incident in Slack, opens a channel, pages the right responders, and runs the workflow automatically.

You want AI investigation without an Enterprise contract. incident.io includes root cause analysis and its autonomous agent from the Pro plan at $25 per user, with pricing published up front.

Postmortems never get written. The AI drafts summaries and follow ups from the incident channel for a responder to accept, edit or dismiss.

Agentic Index coverage score

10.0 / 14 capabilities · 71%

Integrations & Tool Calling Full

A named alert source catalog across monitoring, error tracking and ticketing tools, workflow steps that act in Slack and send webhooks, and Investigations that query telemetry and code and open pull requests; API and webhooks on the pricing chart.

Sourceincident.io help center index (alert sources, workflows), Investigations page and pricing page; docs.incident.io/workflows/getting-startedread 2026-09-29

Workflow Orchestration Full

Workflows run multi step automations from more than twenty triggers, with conditions on severity, role, status and message content, delays, loops, expressions, decision flows and webhooks, managed in the UI or Terraform; Investigations work several hypotheses in parallel.

Sourceincident.io docs, Getting started with Workflows and help center index; docs.incident.io/workflows/getting-startedread 2026-09-29

Knowledge Grounding & RAG Partial

Investigations connect telemetry, code changes and past incidents per run, and the Catalog is a maintained map of services, teams and escalation paths synced from service catalogs; but no published page shows the investigation retrieving from a maintained index, and the Nexus claim of access to all context is marketing.

Sourceincident.io AI SRE page and docs, Using the Catalog; docs.incident.io/catalog/catalog-setupread 2026-09-29

Human Oversight & Guardrails Full

AI suggested updates, summaries and follow ups wait for a person to choose 'Share update, Edit before sharing and Dismiss' or 'Accept and set, Edit before setting and Dismiss' before they apply; Investigations 'never takes action without you', the only change being a pull request the team merges; role restrictions govern who may act.

Sourceincident.io docs, Suggestions, and Investigations page; docs.incident.io/ai/suggestionsread 2026-09-29

Security, Identity & Governance Full

Admins get SAML single sign on, SCIM provisioning that syncs roles and seats, base roles with custom permissions, team roles and role restrictions, and audit logs of configuration and permission changes. Certifications cover SOC 2 Type I and II and GDPR, and penetration test results sit in the trust center.

Sourceincident.io security page and help center index (admin pages)read 2026-09-29

Observability & Auditability Full

'An investigation timeline lets you follow the agent's reasoning from first signal to final conclusion' and 'Every hypothesis links back to its sources'; workflow runs keep an Activity history with run time, incident and status, and incident activity log entries are exposed by API.

Sourceincident.io Investigations page and docs, Getting started with Workflowsread 2026-09-29

Memory & State Persistence Partial

Nexus Memory is 'a learned library of the queries that have actually worked for your data sources, built from your own investigations', scoped to the organization, data source and query kind and drawn on as worked examples; its lifetime is stated only as vendor curation, and no customer view, edit or delete path is documented.

Sourceincident.io docs, Memory; docs.incident.io/nexus/telemetry/memoryread 2026-09-29

Deployment & Data Residency Not documented

SaaS on Google Cloud in European regions, the one hosting sub-processor named; no region choice, customer environment or self hosting is documented, so the disclosed region is a fact about the vendor's infrastructure, not an offering. Enterprise 'multiple environments' is not described as a deployment option.

Sourceincident.io sub-processors page and pricing pageread 2026-09-29

Prebuilt Agents, Templates & Packs Full

Six workflow templates ship in the Create workflow drawer for customers to adopt, beside incident and escalation path templates exposed by the API; the template names themselves are not listed in the docs.

Sourceincident.io docs, Getting started with Workflows, and API reference index; docs.incident.io/workflows/getting-startedread 2026-09-29

Triggers & Channel Coverage Full

Alerts from monitoring tools page on call and open incidents; 'The moment an incident is declared, Investigations has already done a first pass'; workflows fire on incident changes, channel messages and recurring schedules, in Slack and Microsoft Teams.

Sourceincident.io Investigations page and docs, Getting started with Workflowsread 2026-09-29

Model Flexibility & Routing Partial

Anthropic and OpenAI are named as AI sub-processors, with zero data retention agreements; that is vendor internal use of two providers, and no customer or admin model choice is documented.

Sourceincident.io sub-processors page and AI SRE pageread 2026-09-29

APIs, SDKs & MCP Extensibility Full

A public REST API at api.incident.io with bearer API keys, published as 76 OpenAPI specifications covering incidents (list, create, edit), alerts, catalog, schedules, escalations, workflows and workflow runs, plus webhooks, Terraform management of workflows and a remote MCP server.

Sourceincident.io docs, incidents-v2 OpenAPI spec and llms.txt index; docs.incident.io/openapi/tags/incidents-v2.jsonread 2026-09-29

Testing, Debugging & Optimization Partial

'We backtest against real historical incidents daily, and alert on any degradation before it reaches you': a quality gate the vendor runs on its own agent, with confidence scores on findings. No evaluation surface the customer can invoke on its own configuration is documented.

Sourceincident.io Investigations pageread 2026-09-29

Browser & Computer Use Not documented

Works through Slack, Teams, integrations, workflows, an API and an MCP server; no browser, desktop or computer control is documented.

Sourceincident.io help center index and Investigations pageread 2026-09-29

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-09-29·IntegrationsPartially Verified

A new incident.io plugin bundles its remote MCP server with skills that teach agents how to use it, and is listed in the Claude Code, Cowork and Cursor plugin marketplaces. It supports several plugin formats and updates itself as new skills ship.

Bears on: MCP / tool calling / API

View source
2026-07-21·Workflow orchestrationVerified

incident.io launched an update enhancing workflow automation and the actionability of its AI Agent. The release introduces a secure secrets store for workflows, the ability to sign workflow webhook requests, and triggers based on alert creation or resolution. Furthermore, the AI Agent has been upgraded to independently resolve incidents, direct escalations, and suggest both custom fields and timestamps during an active response.

Bears on: Workflow orchestration

View source
View all 2 changes for incident.io →Tracked since Jul 2026 · Verified from public vendor sources

Pricing

Free Basic tier; Team $19 per user per month ($15 with the annual discount); Pro $25; on call add on $10 (Team) or $20 (Pro) per user

seats (per user per month), tiered plus on call add on

Free tier

Included quota

Basic is free with limited automation and no API. Team adds multi team on call, AI features, unlimited integrations, and API access. Pro adds advanced insights, private incidents, custom postincident flows, and the full AI SRE.

What is public

All tier prices, the annual discount on Team, on call add on rates and the standalone on call price, and which tier carries each AI feature.

Billing mechanics

Self serve per user monthly subscriptions across four tiers, an annual discount on Team, and a per user on call add on or standalone on call seat. The AI investigation agent is bundled from Pro rather than sold separately.

Cost watchouts

On call is not in the seat price: it adds $10 per user on Team or $20 on Pro, so a Pro team that pages engineers pays about $45 per user a month. Root cause analysis and the autonomous agent need Pro, and advanced access control and multiple environments need Enterprise.

Variable cost rationale

Flat per user tiers with a per user on call add on; no usage metering on incident response, so cost scales with headcount rather than incident volume.

Additional watchouts

The headline seat price understates real cost once on call is added, and root cause analysis needs Pro. Detection comes from the customer's own monitoring tools, so budget for those separately.

Overage / add-ons

Seat based; on call priced as a per user add on. No usage metering published.

Sales call required

Mixed (some tiers require a call)

Free / trial

Free Basic tier with Slack or Teams response, single team on call and a status page; no trial period published

Lowest paid plan

Team at $19 per user monthly ($15 annually)

Commercial notes

Independent while FireHydrant was acquired by Freshworks. Customers include Netflix, Etsy, Intercom, Vanta, and Airbnb. Replaces incident coordination, status pages, and postmortem automation in one invoice.

Key ambiguities

Every tier price is published; the Enterprise price is not.

Agentic Index verified 2026-09-29

Alternatives to incident.io

The closest documented capability profiles to incident.io among SRE and DevOps agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.