# Introduction

Take your first steps towards incident management using SolarWinds Incident Response (formerly Squadcast).

{% @storylane/embed subdomain="app" url="<https://app.storylane.io/demo/rb7tmtfwzmis>" linkValue="rb7tmtfwzmis" %}

Squadcast is an incident management and on-call alerting platform, built on DevOps & SRE best practices to help you simplify your incident management process, get meaningful notifications, and collaborate to enable faster incident resolution.

Squadcast integrates with your monitoring and metric-collection applications to consolidate alerts, and send notifications, so the moment something goes wrong, it springs the right people to action, at the right time. In this Quick Start Guide, we will cover the basic setup to get you started along with a run-through of the SRE and incident resolution capabilities of Squadcast.

As soon you sign up, you’ll be on the Free Trial plan and will have access to all the features on the platform for 14 days. Post the trial period, you can choose between our Free, Pro, Premium, and Enterprise plans based on your need and usage. You can see all our plans [<mark style="color:blue;">here</mark>](https://www.squadcast.com/pricing).

Begin with the basic setup guide based on your role in the organization: Account Owner, User, or Stakeholder

## Roles in Squadcast

<figure><img src="/files/Yzd4ARWVVFU7pDvTiwLB" alt="Roles in Squadcast - Account owner, User, Stackholder"><figcaption></figcaption></figure>

### **Get Started as an Account Owner**

An Account Owner is the root user of your organization - they have full access. The Account Owner can manage the account subscription settings and billing. Furthermore, Squadcast sends subscription and payment-related update e-mails to the account owner.

Squadcast assigns account ownership to the user that signs up for a Squadcast account. After then, the account owner can manage permissions for each added user.

To get started as an Account Owner, click [<mark style="color:blue;">here</mark>](/quickstart-guide/get-started-as-an-account-owner)**.**

### **Get Started as a User**

Users are typically folks who go on-call and need to be notified every time an incident is triggered. Users can only access the configurations that they’re part of, and they can only access the incidents for teams that they’re a part of. Users can be granted additional permissions controlled by RBAC.

To get started as a User, click [<mark style="color:blue;">here</mark>](/quickstart-guide/get-started-as-a-user).

### **Get Started as a Stakeholder**

Stakeholders are individuals or groups from within the organization, that take an interest and are impacted by the outcomes of the incident management process.

Stakeholders have view-only access to all incidents. They are not notified by default for any of the incidents created in Squadcast. They also can create manual incidents should they notice something wrong and want to notify the on-call team of it. They can add notes to an incident and act as an incident watcher.

To get started as a Stakeholder, click [<mark style="color:blue;">here</mark>](/quickstart-guide/get-started-as-a-user).

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><mark style="color:blue;"><strong>Get Started as an Account Owner</strong></mark></td><td></td><td>To get started as an Account Owner, click here.</td><td><a href="/pages/6obE2XXvu9Qah9AAU2vN">/pages/6obE2XXvu9Qah9AAU2vN</a></td></tr><tr><td><mark style="color:blue;"><strong>Get Started as a User</strong></mark></td><td></td><td>To get started as a User, click here.</td><td><a href="/pages/6obE2XXvu9Qah9AAU2vN">/pages/6obE2XXvu9Qah9AAU2vN</a></td></tr><tr><td><mark style="color:blue;"><strong>Get Started as a Stakeholder</strong></mark></td><td></td><td>To get started as a Stakeholder, click here.</td><td><a href="/pages/A9CkFPUGCh4Sm7QiOEiJ">/pages/A9CkFPUGCh4Sm7QiOEiJ</a></td></tr></tbody></table>

## **Get Help**

<details>

<summary><mark style="color:blue;">Squadcast Community</mark></summary>

The Squadcast community is a place for Squadcast users to share ideas, answers, code, and compare notes.

* [<mark style="color:blue;">Community</mark>](https://thwack.solarwinds.com/categories/solarwinds_incident_response)
* [<mark style="color:blue;">Twitter</mark>](https://twitter.com/SquadcastHub)
* [<mark style="color:blue;">LinkedIn</mark>](https://www.linkedin.com/company/squadcast/)
* [<mark style="color:blue;">Blog</mark>](https://www.squadcast.com/blog)

</details>

<details>

<summary><mark style="color:blue;"><strong>Developer Resources</strong></mark></summary>

* [<mark style="color:blue;">Developer Portal</mark>](https://developers.incidents.cloud.solarwinds.com/)
* [<mark style="color:blue;">API Documentation</mark>](https://apidocs.squadcast.com/)
* [<mark style="color:blue;">Terraform Documentation</mark>](https://registry.terraform.io/providers/SquadcastHub/squadcast/latest/docs)

</details>

<details>

<summary><mark style="color:blue;"><strong>Contact Support</strong></mark></summary>

At Squadcast, we pride ourselves on the kind of support we offer to our users. Feel free to reach out to us on any of the following channels and we’ll be right with you.

* In-App Chat
* [<mark style="color:blue;">Support Email</mark>](mailto:support@squadcast.com)
* Phone Number: [<mark style="color:blue;">+1 650 670 3104</mark>](tel:+16506703104)
* [<mark style="color:blue;">Documentation Support Hub</mark>](https://support.squadcast.com/)

</details>

<details>

<summary><mark style="color:blue;"><strong>Latest Product Updates</strong></mark></summary>

We are constantly updating our platform by adding new features, alert source integrations, and other essential extensions. You can check out our latest releases [<mark style="color:blue;">here</mark>](https://headwayapp.co/squadcast-updates).

</details>

<details>

<summary><mark style="color:blue;"><strong>Squadcast GitHub</strong></mark></summary>

If you’re curious about what we do every day, feel free to drop by the[ <mark style="color:blue;">SquadcastHQ GitHub page</mark>](https://github.com/squadcastHub). You can check out and contribute to our curated repository of[ <mark style="color:blue;">awesome-sre-tools</mark>](https://github.com/SquadcastHub/awesome-sre-tools).

</details>

<details>

<summary><mark style="color:blue;"><strong>Events</strong></mark></summary>

You can catch Squadcast participating in [<mark style="color:blue;">events</mark>](https://www.squadcast.com/events) around the world! Meet our team to discuss all things SRE and what we are building at Squadcast.

</details>

{% hint style="info" %}
**Need more integrations?**

In case you don’t find an integration, email us at <support@squadcast.com>. Our team will reach out to you within 1 working day.
{% endhint %}


# Get started as an Account Owner

Start building your teams, integrate your tools and create on-call schedules, with Squadcast

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th></th></tr></thead><tbody><tr><td><strong>Your Role as an Account Owner</strong></td><td></td><td>You are responsible for the management of the overall configuration, workflow, user permissions, and billing. You are the root user of the organization.</td></tr><tr><td><strong>Your Permissions as an Account Owner</strong></td><td></td><td>You have access to all functionality across the platform including scheduling, integrations, teams, user permissions, and billing.</td></tr></tbody></table>

## **1. Set up your on-call team**

### Create your Profile and add Notification Rules

To begin, configure your profile:

Navigate to the [<mark style="color:blue;">My Profile</mark>](/manage-users/manage-your-profile) section to define your contact information, time zone, and notification preferences.

After you’ve set up your profile, you can head over to the [<mark style="color:blue;">Incident Notifications Rules</mark>](/manage-users/notification-rules) section, to create your paging policies.

{% hint style="warning" %}
**Important:**

Verify your contact information to start receiving notifications from Squadcast.
{% endhint %}

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Use the mobile application to receive push notifications. The app gives you instant access to all details and actions.\
\
🔹 **Best Practice Tip** 🔹 Apple and Google Docs, push notifications operate on a "best effort" basis. Consider setting up backup contact methods (SMS, email, phone) for reliability if push notifications fail.\
\
🔹 **Best Practice Tip** 🔹 Furthermore, push notifications may also be impacted by energy-saving modes, low battery levels, or when the app is force-stopped.

🔹 **Best Practice Tip** 🔹 Your primary notification rule should be the most attention-grabbing notification method. We recommend using a diverse notification rule (Push, SMS, Phone, Email) with multiple steps to avoid single points of notification failure.\\

🔹 **Best Practice Tip** 🔹 Use a custom notification rule during business hours, that may not require aggressive notifying.

🔹 **Best Practice Tip** 🔹 Include a phone call in the last step of your notification rule, as a surefire way of getting alerted and acknowledging the incident.\
\
🔹 **Best Practice Tip** 🔹 Furthermore, push notifications may also be impacted by energy-saving modes, low battery levels, or when the app is force-stopped.
{% endhint %}

### **Download our Mobile App**

Explore the mobile and web platforms to get comfortable before beginning your configurations.

The mobile app is available on both [<mark style="color:blue;">App Store</mark>](https://apps.apple.com/app/id1501689101) and [<mark style="color:blue;">Google Play</mark>](https://play.google.com/store/apps/details?id=com.squadcast.incidents\&hl=en).

### **Add Users**

Next, start adding users and stakeholders to your organization. You can manually add each user or bulk import them using a .csv file. Alternatively, you can automatically provision them using an SSO.

See how to manage users, [here](/manage-users/add-and-delete-users).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Configuring SSO before adding users helps ensure all users link their SSO account. Squadcast supports any SAML 2.0-based Single Sign-On (SSO) and you can set it for your Organization by following this integration guide [<mark style="color:blue;">here</mark>](https://support.squadcast.com/single-sign-on-sso/saml-2.0-based-sso)<mark style="color:blue;">.</mark>

\
🔹 **Best Practice Tip** 🔹 For larger teams, the best way to add users would be to bulk import them using a .csv file.

🔹 **Best Practice Tip** 🔹 Make sure that all users have verified their emails and phone numbers as soon as they are added, to start receiving notifications.
{% endhint %}

### **Assign Permissions**

Once you have added users to your organization, you can customize their access to the account by adding additional permissions. These are additional levels of permissions, on top of the User Type that they have been added as. You can only customize permissions for users and not stakeholders.

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Make sure to give the right org-level permissions to the right team members to have better visibility in the system settings.
{% endhint %}

### **Create a Team**

Next, create teams to segregate data and have different environments for different functional teams. By default, all the users are added to the default team. The default team cannot be deleted.

See how to manage teams, [<mark style="color:blue;">here</mark>](/manage-teams/create-and-delete-teams).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Keep a team naming convention that is intuitive to each team role or the alerts they work with. (ie. Support, Backend, Security, Data, etc.).

\
🔹 **Best Practice Tip** 🔹 Organize your teams according to the service they are responsible for. They will be able to manage their integrations and the whole alerting flow for themselves.
{% endhint %}

### **Assign Roles**

Next, assign roles in a Team from within Squadcast Roles: Admin, Users, and Observers, or create custom roles.

See how to manage roles, [<mark style="color:blue;">here</mark>](/manage-teams/role-based-access-control).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Restrict user access as much as possible to limit the number of users making changes. Recommendation: 1-2 admins per team, the rest as users or stakeholders.

🔹 **Best Practice Tip** 🔹 Make use of the custom roles/edit the default roles and give correct access to the right team member.

🔹 **Best Practice Tip** 🔹 Stakeholders added to teams can only carry the role of an Observer.
{% endhint %}

### **Create a Squad**

Squads are sub-groups that can refer to folks handling a specific functionality, service, or project within the team. Squads are handy when you need to notify the whole group together. For instance, when a coordinated response is required for high-urgency high-complexity incidents, or at the end of an escalation policy when nobody has acknowledged it.

Examples:

* Payment gateway Squad
* Backend Squad
* Frontend Squad
* All Hands

You can create multiple squads within a team. See how to manage squads, [<mark style="color:blue;">here</mark>](/manage-teams/squads).

### **Create Schedules**

Once teams are created, you can set up your on-call schedules. An on-call schedule is used to determine who is on-call at a given time. They are based on different time zones and configurable rotations.

{% hint style="warning" %}
**Important:**

They are active only when added to an escalation policy.
{% endhint %}

See how to [<mark style="color:blue;">Manage Schedules</mark>](/schedules/schedules-legacy/create-and-manage-on-call-schedules-and-rotations) and add [<mark style="color:blue;">overrides</mark>](/schedules/schedules-legacy/schedule-overrides).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Learn and understand the difference between a [<mark style="color:blue;">Rotation</mark>](/escalation-policies/round-robin-and-advanced-escalations), [<mark style="color:blue;">Shift</mark>](/schedules/schedules-legacy/create-and-manage-on-call-schedules-and-rotations), and [<mark style="color:blue;">Escalation Policy</mark>](/escalation-policies/create-and-manage-escalation-policies). Taking the time to understand the relationship between these functions will help you determine the most effective way to configure your team’s on-call schedule.

🔹 **Best Practice Tip** 🔹 Keep your rotations as simple as possible, preferably with a continuous rotation of the same users to make your on-call schedule easy to manage. Remember that you can leverage scheduled overrides to address holidays or schedule conflicts.
{% endhint %}

### **Create Escalation Policies**

Next, create escalation policies, and add your on-call schedules to them. This will automatically notify your on-call engineers when an incident is triggered.

Squadcast enables you to add time-based Escalation Rules for [<mark style="color:blue;">users</mark>](/manage-users/add-and-delete-users), [squads ](/manage-teams/squads)(a group of users), or [<mark style="color:blue;">schedules</mark>](/schedules/schedules-legacy/create-and-manage-on-call-schedules-and-rotations) (on-call schedules).

Examples:

* Website Monitoring
* Payment Portal Monitoring
* Backend Issues

See how to Manage Escalation Policies, [<mark style="color:blue;">here</mark>](/escalation-policies/create-and-manage-escalation-policies).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹When creating escalation policies keep a naming convention that allows others to know the context and priority of incidents that come in through a specific escalation policy.

\
🔹 **Best Practice Tip** 🔹Adding on-call schedules to your first escalation layer is the best way to notify your on-call engineers.

🔹 **Best Practice Tip** 🔹 For critical incidents, create separate layers with different methods of notification. The first layer contains non-intrusive methods like Email & Push, while the second layer contains intrusive methods like SMS & Phone calls.

🔹 **Best Practice Tip** 🔹 Add reminder notifications for acknowledged incidents and re-trigger unresolved incidents after a certain time to help reduce MTTR.
{% endhint %}

### **Add Services**

Next, set up Services within Squadcast.

Services are at the core of Squadcast. A service represents an application or component that is crucial for your product or service. Services are created with an alert source integration through which incidents are triggered. Squadcast provides a Webhook URL to integrate with the tools you use.

See how to manage services, [<mark style="color:blue;">here</mark>](/services/adding-a-service).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Give your services meaningful names that reflect the actual component name or functionality.

🔹 **Best Practice Tip** 🔹 You can assign a Squad as the owner of a service.

🔹 **Best Practice Tip** 🔹 You can use tags to differentiate between business and technical services.

🔹 **Best Practice Tip** 🔹 Only send critical, actionable alerts into Squadcast. Avoid unnecessary or noisy alerts – This will help reduce alert fatigue and make it easier to manage your incidents.

🔹 **Best Practice Tip** 🔹 You can check this nice blog which speaks about How to configure services in Squadcast: Best practices to reduce MTTR.
{% endhint %}

### **Configure Integrations**

To see the platform in action, integrate one of your existing tools. You can use a generic Email or API integration to get your alerts flowing, or just use one of our [native integrations](/integrations/alert-source-integrations-native).

You can search through our documentation to find helpful alert source integration guides to walk you through any particular integration.

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Make sure you are only sending critical, actionable alerts to Squadcast to avoid alert fatigue and confusion.

🔹 **Best Practice Tip** 🔹 Check if your alert source is capable of sending tags/labels in their webhooks, you can use our dynamic tagging rules functions to reflect that on the platform and to use them in better ways.

🔹 **Best Practice Tip** 🔹 We always suggest using Incident webhooks over emails to trigger incidents, this way we can eliminate the dependency on third-party email clients to create incidents.
{% endhint %}

## **2. Incident Response - Reduce MTTR with faster response**

### **Add Extensions**

Extensions are deeper integrations with tools where actions can be taken from within the platform to reflect on the tool as well. Within Squadcast, these are called **Extensions** and can be found on the navigation sidebar.

Typically, extensions augment your incident management process by connecting with other tools where actions are required. ITSM, Communication, Web conferencing, Version Control, CI/CD, and SSO tools would typically act as extensions.

See more about how to use Extensions, [<mark style="color:blue;">here</mark>](/integrations/extensions).

## **3. Incident Response - Noise Reduction & Contextual Awareness**

### Add Tags to incidents

Incident Tags are used to add more context to your incident and help classify incidents. You can configure tags from Tagging Rules associated with a service. You can configure tagging rules with an incident JSON to automatically add tags when incidents are triggered or you can manually create and update them.

See more about Tagging Rules, [<mark style="color:blue;">here</mark>](/services/event-tagging).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 While creating the automation rules, ensure to add the source name under each condition to restrict the rule to apply only to that particular alert source.

🔹 **Best Practice Tip** 🔹 If you use Incident webhook to create incidents and if you send the Tags, the Tags that were carried by the webhook will be added to the incidents and not the Tags configured in the platform for that alert source.
{% endhint %}

### **Configure Routing Rules for automatic overrides**

Alert Routing allows you to configure rules to ensure that alerts are routed to the right responder with the help of event tags attached to each alert. Routing is a part of the rules engine associated with each service. You can access routing rules from a service’s options dropdown.\
Note that this rule will override the escalation policy attached to the service. This is typically used in cases where severities are configured via tags and each severity type is to be handled by a different level of on-call user.

See more on Routing Rules, [<mark style="color:blue;">here</mark>](/services/alert-routing).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Request that your routing rules name(s) follow your Escalation Policy naming convention.
{% endhint %}

### **Deduplicate to reduce alert fatigue**

Alert Deduplication can help you reduce alert noise by organizing and grouping relevant alerts. This also provides easy access to similar alerts when needed. You can configure deduplication rules with an incident JSON to automatically deduplicate and group similar incidents and can see this reflected on the incident dashboard.

See more about Alert Deduplication, [<mark style="color:blue;">here</mark>](/services/alert-deduplication-rules/alert-deduplication-rules).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 While creating the automation rules, ensure to add the source name under each condition to restrict the rule to apply only to that particular alert source.

🔹 **Best Practice Tip** 🔹 Always arrange your automation rules in the right order based on the priority of how the rules have to be executed.
{% endhint %}

### **Suppress non-actionable alerts**

Suppression Rules is a part of the Squadcast Rules Engine that allows you to configure rules to automatically suppress non-actionable alerts such as warning, informational, or test alerts. All suppressed data will still be available on the platform.

See more about Suppression Rules, [<mark style="color:blue;">here</mark>](/services/alert-suppression).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 While creating the automation rules, ensure to add the source name under each condition to restrict the rule to apply only to that particular alert source.

🔹 **Best Practice Tip** 🔹 Always arrange your automation rules in the right order based on the priority of how the rules have to be executed.
{% endhint %}

## **4. Incident Communication**

### **Set up your Public and Private Status Page**

Status Page helps you communicate status updates of your services to your customers and stakeholders about outages and scheduled maintenance.

Status Pages can either be public (accessible by everyone) or private (accessible by just your team on Squadcast) on Squadcast. You can also add a subscription option for your public status page so customers are automatically informed of any updates on the Status Page.

See how to set up Status Pages, [<mark style="color:blue;">here</mark>](/status-page/status-page)<mark style="color:blue;">.</mark>

### **Create a Postmortem Report**

An Incident Postmortem is a post-incident review that allows users to learn from major incidents by providing a summary of events that transpired, how the response was handled, and what steps were taken to resolve the incident.

You can create an incident postmortem from within an incident page once the incident is resolved. You can choose from several popularly used postmortem templates or create custom templates for your Organization.

See how to create Postmortem templates, [<mark style="color:blue;">here</mark>](/postmortems/postmortem-templates). See how to create Postmortems, [<mark style="color:blue;">here</mark>](/postmortems/create-postmortems).

{% hint style="success" %}
🔹 Best Practice Tip 🔹 Always add all the necessary information while creating a postmortem.

🔹 Best Practice Tip 🔹 Add detailed notes in the Incident Notes section on the Incident Details Page, and star them to attach so that they’ll be present in the postmortem as well.
{% endhint %}

## **5. SRE Visibility and Insights**

### **Setup Service Level Objectives (SLOs)**

SLOs are used to define and track your service’s performance delivery. Any breach of SLOs will trigger an incident and notify the relevant Users, Squads, or Schedules.

See how to set up SLOs, [<mark style="color:blue;">here</mark>](/slo-tracker/configure-and-monitor-your-slos).

### **Analytics and Reporting**

Analytics help you view the performance of your Organization/Team, for a given period. It helps gain insights into how your system is functioning and what shape your responders are in.

You can also filter reports based on specific services, tags, and users.

See how to use Analytics, [<mark style="color:blue;">here</mark>](/analytics/analytics).

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Get started as a User

Learn how to configure your profile, get notifications from Squadcast and view your on-call schedules

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th></th></tr></thead><tbody><tr><td><strong>Your Role as a User</strong></td><td></td><td>The user is responsible for taking action on incidents that page you while you are on call.</td></tr><tr><td><strong>Your Permissions as a User</strong></td><td></td><td>User has access to view and edit their user information, view their on-call schedule, and the ability to take action on alerts.</td></tr></tbody></table>

## **1. Set up your on-call profile**

### **Create your Profile and add Notification Rules**

To begin, configure your profile:

Navigate to the [<mark style="color:blue;">My Profile</mark>](/manage-users/manage-your-profile) section to define your contact information, time zone, and notification preferences.

After you’ve set up your profile, you can head over to the [<mark style="color:blue;">Incident Notifications Rules</mark>](/manage-users/notification-rules) section, to create your paging policies.

{% hint style="warning" %}
**Important:**

Verify your contact information to start receiving notifications from Squadcast.
{% endhint %}

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Use the mobile application to receive push notifications. The app gives you instant access to all details and actions.\
\
🔹 **Best Practice Tip** 🔹 Apple and Google Docs, push notifications operate on a "best effort" basis. Consider setting up backup contact methods (SMS, email, phone) for reliability if push notifications fail.\
\
🔹 **Best Practice Tip** 🔹 Furthermore, push notifications may also be impacted by energy-saving modes, low battery levels, or when the app is force-stopped.

🔹 **Best Practice Tip** 🔹 Your primary notification rule should be the most attention-grabbing notification method. We recommend using a diverse notification rule (Push, SMS, Phone, Email) with multiple steps to avoid single points of notification failure.

🔹 **Best Practice Tip** 🔹 Use a custom notification rule during business hours, that may not require aggressive notifying.

🔹 **Best Practice Tip** 🔹 Include a phone call in the last step of your notification rule, as a surefire way of getting alerted and acknowledging the incident.
{% endhint %}

### **Download our Mobile App**

Explore the mobile and web platforms to get comfortable before beginning your configurations.

The mobile app is available on both [<mark style="color:blue;">App Store</mark>](https://apps.apple.com/app/id1501689101) and [<mark style="color:blue;">Google Play</mark>](https://play.google.com/store/apps/details?id=com.squadcast.incidents\&hl=en).

### Manage Escalation Policies

Escalation policies help notify you when an incident is triggered.

Squadcast enables you to add time-based Escalation Policies for users, squads (a group of users), or schedules (on-call schedules).

Examples:

* Website Monitoring
* Payment Portal Monitoring
* Backend Issues

{% hint style="warning" %}
The user requires appropriate team-level permission to configure/manage escalation policies, for that team in the organization.
{% endhint %}

See how to Manage Escalation Policies, [<mark style="color:blue;">here</mark>](/escalation-policies/create-and-manage-escalation-policies).

### **Manage Services**

Services are at the core of Squadcast. A service represents an application or component that is crucial for your product or service. Services are created with an alert source integration through which incidents are triggered. Squadcast provides a Webhook URL to integrate with the tools you use.

{% hint style="warning" %}
The user requires appropriate team-level permission to configure/manage services, for that team in the organization.
{% endhint %}

See how to manage services, [<mark style="color:blue;">here</mark>](/services/adding-a-service).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Only send critical, actionable alerts into Squadcast. Avoid unnecessary or noisy alerts – This will help reduce alert fatigue and make it easier to manage your incidents.

🔹 **Best Practice Tip** 🔹 You can check this nice blog which speaks about [<mark style="color:blue;">How to configure services in Squadcast: Best practices to reduce MTTR</mark>](https://www.squadcast.com/blog/how-to-configure-services-in-squadcast-best-practices-to-reduce-mttr).
{% endhint %}

### **Configure Integrations**

To see the platform in action, integrate one of your existing tools. You can use a generic Email or API integration to get your alerts flowing, or just use one of our [native integrations](/integrations/alert-source-integrations-native).

You can search through our documentation to find helpful alert source integration guides to walk you through any particular integration.

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Make sure you are only sending critical, actionable alerts to Squadcast to avoid alert fatigue and confusion.

🔹 **Best Practice Tip** 🔹 Check if your alert source is capable of sending tags/labels in their webhooks, you can use our dynamic tagging rules functions to reflect that on the platform and to use them in better ways.

🔹 **Best Practice Tip** 🔹 We always suggest using Incident webhooks over emails to trigger incidents, this way we can eliminate the dependency on third-party email clients to create incidents.
{% endhint %}

## **2. On-call Awareness**

### View your Escalation Policies

Navigate to [<mark style="color:blue;">Escalation Policy</mark>](/escalation-policies/create-and-manage-escalation-policies) on the side panel to view all the escalation policies set up for your team.

### **View your Schedule**

Navigate to [<mark style="color:blue;">Schedules</mark>](https://github.com/solarwinds-cloud/sq-Gitbook/blob/main/quickstart-guide/broken-reference/README.md) to get a calendar view of your on-call schedule or check out the My On-Call Shifts widget on the profile page to see when you are on-call.

### **Create Schedule Overrides**

Heading out of town or have a scheduled absence where you will need on-call coverage? Create an override so someone can cover your shift for you.

See how to create schedule overrides, [<mark style="color:blue;">here</mark>](/schedules/schedules-legacy/schedule-overrides).

## 3. Incident Response - Reduce MTTR with faster response

### **Check out our Incidents Page**

The Incidents Details page is where engineers can take action and respond to the triggered incidents.

### **Respond to an Incident**

Once you receive a notification for an incident, you can take several different actions in response.

1. **Acknowledge**: This will stop the incident from actively paging and continuing through the escalation policy. An acknowledgment signifies that you are aware of an incident and are taking action on it.
2. **Resolve**: Once the incident is resolved within the monitoring tool it can be resolved within Squadcast. Once resolved any new alert of the same type will trigger a new incident.
3. **Reassign**: If the incident needs to be addressed by another user or directed to a different escalation policy the reassign option will reroute to the accurate responder.
4. **Squadcast Actions**: Squadcast Actions are typically used as a means to reduce any customer-impacting issue as soon as possible. See more on Squadcast Actions, [<mark style="color:blue;">here</mark>](/quickstart-guide/glossary#squadcast-actions).
5. **Mention**: @mention specific users or teams in the Notes section to collaborate with them. This is also adding them as Incident Watchers.
6. **Communication channels**: Add external links to video calls, chatops, and more. Additionally, you can create a dedicated slack channel for an incident using the communications card.
7. **Update Status Page**: Add status updates to your customers and stakeholders about outages and scheduled maintenance.
8. **Runbooks**: Create and attach Runbooks to your incidents to document routine procedures and operations for referencing.
9. **Tasks**: Add tasks to your incidents as instructions or follow-ups for your team members, working on the incident.
10. **Start Postmortem**: Once an incident is resolved, create a post-incident retrospective as it allows users to learn from major incidents by providing a summary of events that transpired, how the response was handled, and what resolution steps were taken.

## **4. Incident Response - Noise Reduction & Contextual Awareness**

### Add Tags to incidents

Incident Tags are used to add more context to your incident and help classify incidents. You can configure tags from Tagging Rules associated with a service. You can configure tagging rules with an incident JSON to automatically add tags when incidents are triggered or you can manually create and update them.

See more about Tagging Rules, [<mark style="color:blue;">here</mark>](/services/event-tagging).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 While creating the automation rules, ensure to add the source name under each condition to restrict the rule to apply only to that particular alert source.

🔹 **Best Practice Tip** 🔹 If you use Incident Webhook to create incidents and if you send the Tags, the Tags that were carried by the Webhook will be added to the incidents and not the Tags configured in the platform for that alert source.
{% endhint %}

### **Configure Routing Rules for automatic overrides**

Alert Routing allows you to configure rules to ensure that alerts are routed to the right responder with the help of event tags attached to each alert. Routing is a part of the rules engine associated with each service. You can access routing rules from a service’s options dropdown.\
Note that this rule will override the escalation policy attached to the service. This is typically used in cases where severities are configured via tags and each severity type is to be handled by a different level of on-call user.

See more on Routing Rules, [<mark style="color:blue;">here</mark>](/services/alert-routing).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Request that your routing rules name(s) follow your Escalation Policy naming convention.
{% endhint %}

### **Deduplicate to reduce alert fatigue**

Alert Deduplication can help you reduce alert noise by organizing and grouping relevant alerts. This also provides easy access to similar alerts when needed. You can configure deduplication rules with an incident JSON to automatically deduplicate and group similar incidents and can see this reflected on the incident dashboard.

See more about Alert Deduplication, [<mark style="color:blue;">here</mark>](/services/alert-deduplication-rules/alert-deduplication-rules).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 While creating the automation rules, ensure to add the source name under each condition to restrict the rule to apply only to that particular alert source.

🔹 **Best Practice Tip** 🔹 Always arrange your automation rules in the right order based on the priority of how the rules have to be executed.
{% endhint %}

### **Suppress non-actionable alerts**

Suppression Rules is a part of the Squadcast Rules Engine that allows you to configure rules to automatically suppress non-actionable alerts such as warning, informational, or test alerts. All suppressed data will still be available on the platform.

See more about Suppression Rules, [<mark style="color:blue;">here</mark>](/services/alert-suppression).

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 While creating the automation rules, ensure to add the source name under each condition to restrict the rule to apply only to that particular alert source.

🔹 **Best Practice Tip** 🔹 Always arrange your automation rules in the right order based on the priority of how the rules have to be executed.
{% endhint %}

## **5. Incident Communication**

### **Set up your Public and Private Status Page**

Status Page helps you communicate status updates of your services to your customers and stakeholders about outages and scheduled maintenance.

Status Pages can either be public (accessible by everyone) or private (accessible by just your team on Squadcast) on Squadcast. You can also add a subscription option for your public status page so customers are automatically informed of any updates on the Status Page.

See how to set up Status Pages, [<mark style="color:blue;">here</mark>](/status-page/status-page)<mark style="color:blue;">.</mark>

### **Create a Postmortem Report**

An Incident Postmortem is a post-incident review that allows users to learn from major incidents by providing a summary of events that transpired, how the response was handled, and what steps were taken to resolve the incident.

You can create an incident postmortem from within an incident page once the incident is resolved. You can choose from several popularly used postmortem templates or create custom templates for your Organization.

See how to create Postmortem templates, [<mark style="color:blue;">here</mark>](/postmortems/postmortem-templates). See how to create Postmortems, [<mark style="color:blue;">here</mark>](/postmortems/create-postmortems).

{% hint style="success" %}
🔹 Best Practice Tip 🔹 Always add all the necessary information while creating a postmortem.

🔹 Best Practice Tip 🔹 Add detailed notes in the Incident Notes section on the Incident Details Page, and star them to attach so that they’ll be present in the postmortem as well.
{% endhint %}

## **6. SRE Visibility and Insights**

### **Setup Service Level Objectives (SLOs)**

SLOs are used to define and track your service’s performance delivery. Any breach of SLOs will trigger an incident and notify the relevant Users, Squads, or Schedules.

See how to set up SLOs, [<mark style="color:blue;">here</mark>](/slo-tracker/configure-and-monitor-your-slos).

### **Analytics and Reporting**

Analytics help you view the performance of your Organization/Team, for a given period. It helps gain insights into how your system is functioning and what shape your responders are in.

You can also filter reports based on specific services, tags, and users.

See how to use Analytics, [<mark style="color:blue;">here</mark>](/analytics/analytics).

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Glossary

This guide will walk you through the terminologies and their meanings used in Squadcast.

This glossary is a guide to walk you through all the terminologies used within Squadcast and others relevant to the incident management and SRE space.

## Roles in Squadcast

### Account Owner

An Account Owner is the root user of your organization - they have full access. The Account Owner can manage the account subscription settings and billing. Furthermore, Squadcast sends subscription and payment-related update e-mails to the account owner.

Squadcast assigns account ownership to the user that signs up for a Squadcast account. After then, the account owner can manage permissions for each added user.

An Account Owner has the ability to:

1. Access all billing information
2. Add new users/ admins/ stakeholder
3. Delete users/ admins/ stakeholder
4. Create/edit/delete on-call schedules
5. Create/edit/delete escalation policies
6. Create/edit/delete services
7. Create/edit/delete status pages
8. Add/edit/delete postmortem templates
9. Change the account owner or delete the account

### Users <a href="#users" id="users"></a>

Users are typically folks who go on-call and need to be notified every time an incident is triggered. Users can only access the configurations that they’re part of, and they can only access the incidents for teams that they’re a part of. Users can be granted additional permissions controlled by RBAC.

A user can:

1. Create/edit/delete on-call schedules
2. Create/edit/delete escalation policies
3. Create/edit/delete services
4. Create/edit/update/delete Status Page

### Stakeholders

Stakeholders are individuals or groups from within the organization, that take an interest and are impacted by the outcomes of the incident management process.

Stakeholders have view-only access to all incidents. They are not notified by default for any of the incidents created in Squadcast. They also can create manual incidents should they notice something wrong and want to notify the on-call team of it. They can add notes to an incident and act as an incident watcher.

A stakeholder can:

1. Access the incident dashboard
2. Create incidents from the dashboard and assign it to a user/admin/account owner
3. Chat in the war room
4. Watch Incidents
5. Add Incident Notes
6. View/update the status page
7. Add tags to an incident
8. View the analytics page

## Teams

[<mark style="color:blue;">Teams</mark>](/manage-teams/understanding-teams) are used to segregate data and have different environments for different functional units. By default, all the users are added to the default team.

{% hint style="info" %}
**Note**: The default team cannot be deleted.
{% endhint %}

## Squads

[<mark style="color:blue;">Squads</mark>](/manage-teams/squads) are sub-groups that can refer to folks handling a specific functionality, service, or project within the team. Squads are handy when you need to notify the whole group together. For instance, when a coordinated response is required for high-urgency high-complexity incidents, or at the end of an escalation policy when nobody has acknowledged it.

Examples:

* Payment gateway Squad
* Backend Squad
* Frontend Squad
* All Hands

## My Profile

[<mark style="color:blue;">My profile</mark>](/manage-users/manage-your-profile) holds the contact information of a user. It also displays the squads, schedules, and escalation policies that the user is a part of along with the details of his MTTA, MTTR for that particular organization. Additionally, it displays the on-call shifts of the user.

{% hint style="info" %}
**Note**:

You can set your own customized notification rules - rules for how you want to be notified and after how long from the time of incident trigger.

Although, you cannot set the notification rules for any other user.
{% endhint %}

## Notification Rules

[<mark style="color:blue;">Notification Rules</mark>](/manage-users/notification-rules) are rules that determine how an individual user is notified of an incident assigned to them. You can set up rules to notify you on any of the following notification channels:

1. Phone Call
2. SMS
3. Email
4. Push Notification from the Squadcast mobile app

{% hint style="info" %}
**Note**:

You can set up a rule to be notified immediately after an incident trigger or at any time interval (in minutes). You can add as many rules as you want in the rule chain.
{% endhint %}

## Dashboard

The [<mark style="color:blue;">Dashboard</mark>](/dashboards/incident-dashboard) is the first screen that appears when you log in to your Squadcast account. It has two sections:

1. **Summary Section**: The top of the page holds the incident summary where you will be able to see the number of incidents distributed by their state.
2. **Incidents Section**: The bottom of the page holds all the existing and incoming incidents with all the incident details associated with it.

The dashboard supports the following functionalities:

1. **Toggle function**: You can use the toggle button to see incidents assigned to just you or the entire organization. The toggle button can be found on the top left corner of the dashboard page
2. **Incident states**: You can see the number of incidents in each of the states - triggered, acknowledged, resolved and suppressed.
3. **User metrics**: You can use the dashboard toggle function to see your MTTA & MTTR or that of your entire organization.
4. **Filter incident activity by time**: You can filter to see incidents from last week, last month, last year or for a custom date range. This can be done using the **Last Week**, **Last Month**, **Last Year** and **Custom Range** buttons on the top right corner of the dashboard page.
5. **Incident Filter**: In the incident section, incidents can be filtered via Impacted service (service name(s)), Incident source (alert source), assigned to (name of user, squad or escalation policies).
6. **Bulk Actions**: You can take actions to bulk acknowledge or resolve incidents from the **Actions** button the incident section from the dashboard page.

### MTTA <a href="#mtta" id="mtta"></a>

Mean Time To Acknowledge is the average time taken to acknowledge incidents. You can use the toggle switch to view the MTTA for yourself or the organization.

{% hint style="info" %}
**Note**:

The MTTA is calculated as a separate metric for every organization that you are a part of on Squadcast.
{% endhint %}

### MTTR <a href="#mttr" id="mttr"></a>

Mean Time To Resolve is the average time taken to resolve incidents. You can use the toggle switch to view the MTTR for yourself or the organization.

{% hint style="info" %}
**Note**:

The MTTR is calculated as a separate metric for every organization that you are a part of on Squadcast.
{% endhint %}

## Alert

An Alert is an incoming JSON sent to Squadcast from any alerting tool. Alerts are sent into Squadcast through [<mark style="color:blue;">alert source integrations</mark>](https://www.squadcast.com/integrations) that you can find here. Alerts can be of different types - informational, warnings or actionable. You will also be able to send in alerts through our [<mark style="color:blue;">API</mark>](/integrations/incident-webhook-incident-webhook-api) or [<mark style="color:blue;">Email Integration</mark>](/integrations/alert-source-integrations-native/email).

### Alert Forwarding <a href="#alert-forwarding" id="alert-forwarding"></a>

Alert Forwarding is used to forward one’s alerts to another on-call user for a period of time. It can be accessed from the [<mark style="color:blue;">Users</mark>](https://app.squadcast.com/users) page on the navigation sidebar.

Alert Forwarding is typically used if the on-call user is sick, on vacation or had to step away due to an emergency and want another user to fill in for their on-call shift. Alert forwarding is also known as Vacation Mode.

## Incident

An incident can be made up of multiple alerts or can be a standalone incident that is service / customer impacting. An incident is triggered within a service via the alert source integration. This then sets off the notification for the on-call user as per its escalation policy. When an incident is triggered, it will be in the Triggered state until the on-call user acknowledges it.

When an incident is triggered, it comes with the following information:

1. **Incident ID**: The incident number on Squadcast. Incident number follows the general order with which the incidents are pushed into Squadcast.
2. **Incident Name**: The name of an incident. This typically describes the nature of the incident.
3. **Incident Description**: This carries a short summary of the incident and supporting links can be added here to give more context to the incident
4. **Impact on**: The name of the service for which the incident was triggered
5. **Created Via**: Alert source through which the incident was created
6. **Assigned To**: The name of the user/ squad/ escalation policy that the incident was assigned to
7. **Status**: The Incident state: triggered/acknowledged/resolved or suppressed.
8. **Tags**: Tags are added to an incident to classify them however best fits your incident management process (ex: sev:high or sev:critical; frontend or backend)

## States of an Incident

### Triggered <a href="#triggered" id="triggered"></a>

An incident is considered to be in the triggered state before any user responds to the incident notification. Once an incident is triggered it will notify the on-call user(s) based on their notification rules. This also means that the incident is in the open state.

### Acknowledged <a href="#acknowledged" id="acknowledged"></a>

An incident is considered to be in the acknowledged state when a user has acknowledged an incident and is working on resolving it.

### Resolved <a href="#resolved" id="resolved"></a>

An incident is considered resolved when the user has fixed the issue and they want the incident to be closed. Once an incident is resolved, no additional notifications will be sent and the incident cannot be opened again. This is one of the two final states on the Squadcast platform.

### Suppressed <a href="#suppressed" id="suppressed"></a>

All incidents that evaluate to be true to any of the suppression rules configured for service will automatically go into the suppressed state. This, and resolved are the two final states on the Squadcast platform.

## Incident Page <a href="#mtta" id="mtta"></a>

The incident page holds all the details associated with an incident. Each incident will open into an incident page. The page has three main sections:

* [<mark style="color:blue;">Incident Details</mark>](/incidents-page/incidents-details)
* [<mark style="color:blue;">Incident Notes</mark>](/incidents-page/incident-notes)
* [<mark style="color:blue;">Incident Timeline</mark>](/incidents-page/incident-activity-timeline)

### Incident Details

The [<mark style="color:blue;">Incident Details</mark>](/incidents-page/incidents-details) give you the context of the incident by holding details such as - the name, description, impacted service, alert source, and tag(s) on the top of the page. The page also holds all the actions you can take on the incident:

* Acknowledge
* Resolve
* More Actions

### Tags <a href="#mtta" id="mtta"></a>

[<mark style="color:blue;">Incident Tags</mark>](/services/event-tagging) are used to add more context to your incident and help classify incidents. You can add as many tags and map them with relevant information to add more context to the incident.

You can configure tags from Tagging Rules associated with a service. You can choose to configure rules with an incident JSON to automatically add tags when incidents are triggered. To know more about how to configure this, [<mark style="color:blue;">click here</mark>](/services/event-tagging).

### Incident Notes <a href="#mtta" id="mtta"></a>

[<mark style="color:blue;">Incident Notes</mark>](/incidents-page/incident-notes) enable you to add important notes for you and your team that can help mitigate an incident faster. You can @mention specific users or teams in the Notes section to collaborate with them. This is also adding them as Incident Watchers.

### Incident Timeline <a href="#mtta" id="mtta"></a>

You can access the [<mark style="color:blue;">Incident Timeline</mark>](/incidents-page/incident-activity-timeline) by visiting the Incident Details page in the web app and the timeline will be displayed on the right-hand side of the page. The Incident Timeline will display the timeline of the incident in reverse chronological order as to when the incident was first Triggered and Assigned, who Acknowledged it or Re-assigned, and who resolved them and when. The incident timeline can be exported in PD and MD formats.

### Squadcast Actions <a href="#mtta" id="mtta"></a>

Squadcast Actions lets you take actions directly from Squadcast as a response to incidents by clicking the More Actions button from the incident page. Squadcast Actions are typically used as a means to reduce any customer-impacting issue as soon as possible. In some cases, this resolves the issue and in others, there is a need for longer-term remediation. This is left to the user and team to decide and act on.

Today the platform has the following Actions:

1. [<mark style="color:blue;">Circle CI</mark>](/integrations/extensions/circleci)
2. [<mark style="color:blue;">JIRA Cloud</mark>](/integrations/extensions/jira-cloud)
3. [<mark style="color:blue;">JIRA Server (on-premise)</mark>](/integrations/extensions/jira-dc)
4. [<mark style="color:blue;">Manual Webho</mark>](/integrations/outgoing-webhooks)<mark style="color:blue;">ok Triggers</mark>

Some simple examples of actions are rebuilding your project, rolling back to the previous build, and rebooting a server. You can choose to build a repository of any actions, even more, complex ones to take action from Squadcast.

## Schedules

[<mark style="color:blue;">Schedules</mark>](/schedules/schedules-legacy/create-and-manage-on-call-schedules-and-rotations) define on-call rotations to ensure coverage at all times and to distribute load across your team members. Schedules can be set up based on any flexibility you desire - 24 x7 , Mon-Friday, etc.

{% hint style="info" %}
**Note**:

A Schedule must be added to an Escalation Policy for it to be active.
{% endhint %}

### Rotations Type

Rotation types determine how schedules function. Rotation types can be set to have users on-call for a day at a time or a week at a time, or the rotation can be customized to any specified number of hours, days, or weeks.

### On-Call Restrictions

Restrictions on an on-call schedule determine what hours during the day, and which days, a user is on-call. You can restrict on-call shifts to daily or weekly for a period of time. No notifications will be triggered if an incident is triggered at any time outside of this restriction.

### Gaps in Schedule

A gap in the schedule indicates that no one is on call for a certain amount of time. If there is a gap in the schedule, and no one is on call. This is typically seen when custom rotations are created. In this case, a primary on-call rotation is used as a fallback layer for incidents that may occur during the schedule gaps. This would mean that if an incident were to occur in a gap period, this incident would automatically be sent to the user on the primary rotation layer.

### Rotation Layers

Rotation layers are used to create a fallback layer when there are schedule gaps.

## Escalation Policies <a href="#escalation-policies" id="escalation-policies"></a>

An [<mark style="color:blue;">Escalation Policy</mark>](/escalation-policies/create-and-manage-escalation-policies) is the chain of escalations that determines who should be notified first, second and so on when an incident is triggered. Escalation policies are attached to a specific service. The same escalation policy can be attached to multiple services.

Escalation policies can have users, multiple users, squads, and schedules.

You will need to add the below details to create an escalation policy:

1. Policy Name: The name of the escalation policy (Ex: backend escalation)
2. Policy Description: The description of the policy (Ex: Incidents triggered for all the backend services should be routed to the backend escalation policy)
3. Rules
4. User or Squad or Schedul&#x65;**:** Add users, squads or schedules to the rule
5. Escalation After: This is the time period after which if an incident is still in the triggered state, is escalated to the next rule in the policy. This time period can be adjusted to any amount of time (in minutes).
6. Escalate if: Incident is not acknowledged. Right now we only support this. Soon, we will be adding capability for escalating if not resolved.

### Escalation Rule <a href="#escalation-rule" id="escalation-rule"></a>

Multiple escalation rules make an escalation policy. Typically, each escalation rule represents a different level of on-call duty. The first rule in the policy will determine who gets notified first about the triggered incident. This can either be a user, multiple users, squads, and schedules.

If the incident still remains in the triggered state after the notifications have gone through to the users/squad/schedule and the time period closes from the first escalation rule, then the user/squad/schedule on the second rule on the escalation policy will be notified, and so on.

## Services <a href="#services" id="services"></a>

[<mark style="color:blue;">Services</mark>](/services/adding-a-service) are at the core of Squadcast. It represents a logical unit that maps to alert sources (aka monitoring tools) in your environment. When alerts are received from these sources, incidents are triggered and routed to users based on the attached escalation policy. You can also opt-in to get notified on ChatOps tools such as Slack, MS Teams, and Google Hangouts.

### Routing Rules

[<mark style="color:blue;">Alert Routing</mark>](/services/alert-routing) allows you to configure rules to ensure that alerts are routed to the right responder with the help of event tags attached to each alert. Routing is a part of the rules engine associated with each service.

{% hint style="info" %}
**Note**: This rule will override the escalation policy attached to the service.

This is typically used in cases where severities are configured via tags and each severity type is to be handled by a different level of on-call user.
{% endhint %}

### Service Dependencies

[<mark style="color:blue;">Dependencies</mark>](/services/alert-deduplication-rules/service-dependency-based-deduplication) capture the dependent services for each service. This is an indication of what other services can get affected if the main service is impacted. You can add dependant services for each service from the services page. These defined dependencies are associated with the Status Page.

### Maintenance Mode

[<mark style="color:blue;">Maintenance Mode</mark>](/services/maintenance-mode) is used to temporarily disable notifications for a service for a set period of time. Incidents triggered when a service is in maintenance mode will automatically go into the suppressed state. You can add multiple maintenance windows or schedule recurring maintenance windows.

{% hint style="info" %}
**Note:** No notifications will be sent when a service is under maintenance.
{% endhint %}

### Service Levels <a href="#service-levels" id="service-levels"></a>

Service Levels are attached to services and connect to the SLO dashboard. Service Levels are Service Level Objectives that you define for each service and can be configured for a service from the service page. Today, the configuration is made through our open-source SDK, DEX. DEX SDK is available in Golang and NodeJS.

You can add multiple Service Level Indicators that make up the Service Level Objective for a service. Today you can choose from Latency, Memory, and Status Codes for Service Level Indicators.

### DEX SDK <a href="#dex-sdk" id="dex-sdk"></a>

**Service Levels** are configured with DEX, our open-source SDK. DEX is available in two languages:

* DEX SDK for Golang: <https://github.com/squadcastHQ/dex-go>
* DEX SDK for NodeJS: <https://github.com/squadcastHQ/dex-node>

## Alert Source Integrations <a href="#alert-source-integrations" id="alert-source-integrations"></a>

An Alert Source Integration is used to integrate with any monitoring, logging, or tracing tool. Alert source integrations can be configured for services. You can also choose to send in alerts for a service using the API or email integrations. You can search through our documentation to find helpful alert source integration guides to walk you through any particular integration.

View our list of alert source integrations [<mark style="color:blue;">here</mark>](https://www.squadcast.com/integrations).

{% hint style="info" %}
**Note**:

If you don't see an integration you want, feel free to reach out to us via the Intercom Chat Widget in the bottom right corner of your screen or you can drop a line to our [<mark style="color:blue;">Support Team</mark>](mailto:support@squadcast.com) and someone will get back to you.
{% endhint %}

## Extensions (Integrations) <a href="#extensions-integrations" id="extensions-integrations"></a>

[<mark style="color:blue;">Extensions</mark>](/integrations/extensions) are deeper integrations with tools where actions can be taken from within the platform to reflect on the tool as well. Within Squadcast, these are called **Extensions** and can be found on the navigation sidebar.

Typically, extensions augment your incident management process by connecting with other tools where actions are required. ITSM, Communication, Web conferencing, Version Control, CI/CD, and SSO tools would typically act as extensions.

### Circle CI Actions <a href="#circle-ci-actions" id="circle-ci-actions"></a>

Squadcast support actions such as rebuilding [<mark style="color:blue;">CircleCI</mark>](/integrations/extensions/circleci) projects directly from the incident page. The link for the project status will be added to the timeline and you should be able to click on the link to view the status from Squadcast.

### JIRA Cloud & Server <a href="#jira-cloud--server" id="jira-cloud--server"></a>

The [<mark style="color:blue;">JIRA Cloud</mark>](/integrations/extensions/jira-cloud) and [<mark style="color:blue;">JIRA Server</mark>](/integrations/extensions/jira-dc) Actions allow you to create tickets in JIRA with the incidents from Squadcast and sync status bidirectionally.

This is especially helpful if you have some tasks for the longer-term remediation of a particular incident or project.

## Service Level Objective (SLO) <a href="#service-level-objective-slo" id="service-level-objective-slo"></a>

[<mark style="color:blue;">Service Level Objective</mark>](/slo-tracker/slo-basics) is an agreement within an SLA about a specific metric over a certain period of time. It is expressed as a percentage or ratio over some time, for example, “99.95% availability over 24 hours”.

### Service Level Agreement (SLA) <a href="#service-level-agreement-sla" id="service-level-agreement-sla"></a>

[<mark style="color:blue;">Service Level Agreement</mark>](/slo-tracker/slo-basics) is an explicit or implicit agreement between a client and service provider stipulating the client’s reliability expectations and the service provider’s consequences for not meeting them.

### Service Level Indicator (SLI) <a href="#service-level-indicator-sli" id="service-level-indicator-sli"></a>

[<mark style="color:blue;">Service Level Indicator</mark>](/slo-tracker/slo-basics) measures compliance with an SLO (Service Level Objective). So, for example, if an SLA specifies that your system will be available 99.95% of the time, your SLO is likely 99.95% uptime and your SLI is the actual measurement of your uptime. Maybe it’s 99.90%, or maybe it’s 99.99%.

### Error Budgets <a href="#error-budgets" id="error-budgets"></a>

[<mark style="color:blue;">Error Budgets</mark>](/slo-tracker/configure-and-monitor-your-slos#error-budget-policy) are the single metric that can be utilized to determine whether the system can take on the additional risk of deploying a new feature or if the team should rather be focused on making the system more reliable. It is an indication of the amount of headroom you have before an SLA breach.

$$
Error Budget = (1 - Availability) = Failed Requests / (Total Number of Requests)
$$

So if an SLO for a service is indicated as an Availability of 99.5%, then this service has an error budget of 0.5% which specifies the amount of total downtime you are allowed.

### Toil Budgets <a href="#toil-budgets" id="toil-budgets"></a>

**Toil Budgets** are a way for an engineer to understand how much time is going into doing work that holds no long-term value that can be automated. Toil is any work that tends to be manual, repetitive, automatable, tactical, and devoid of long-term value. Additionally, toil tends to scale linearly as the service grows.

{% hint style="info" %}
**Note**:

Today, this feature is not available on the platform but we are working on bringing the capabilities to measure this.
{% endhint %}

### SLO Summary <a href="#slo-summary" id="slo-summary"></a>

The [<mark style="color:blue;">SLO summary</mark>](/slo-tracker/slo-basics) is a visual representation of your services’ health.

{% hint style="info" %}
**Note**:

Only the services for which service levels are configured will show up on the SLO dashboard.
{% endhint %}

## Squadcast Runbooks <a href="#squadcast-runbooks" id="squadcast-runbooks"></a>

[<mark style="color:blue;">Runbooks</mark>](/runbooks/runbooks) are a compilation of routine procedures and tasks, in the form of checklists, that are documented for reference while working on a critical incident.

## Postmortem <a href="#postmortem" id="postmortem"></a>

[<mark style="color:blue;">Postmortems</mark>](/postmortems/create-postmortems) help teams document incident failures and their subsequent fixes to create a knowledge base of learnings that can be shared across the organization. All of the steps taken for incident resolution can be documented and shared in a Postmortem.

{% hint style="info" %}
**Note**:

You can choose from several popularly used postmortem templates or have your admin/ account owner create one for your organization.
{% endhint %}

## Status Page <a href="#status-page" id="status-page"></a>

The [<mark style="color:blue;">Status Page</mark>](/status-page/status-page) helps you communicate critical updates about outages and scheduled maintenance to your customers and stakeholders.

Status Pages can either be public (accessible by everyone) or private (accessible by just your team on Squadcast) on Squadcast.

{% hint style="info" %}
**Note**:

You can also add a subscription option for your public status page so customers are automatically informed of any updates on the Status Page.
{% endhint %}

## Webforms

[<mark style="color:blue;">Webforms</mark>](/webforms/webforms) give your stakeholders and customers a way to report issues through a publicly hosted form. Improve your customer support offering and manage critical customer-impacting issues as incidents within Squadcast.

## Analytics <a href="#analytics" id="analytics"></a>

The [<mark style="color:blue;">Analytics</mark>](/analytics/analytics) dashboard helps analyze incident data using Organization-level analytics & Team-level analytics. Visualize with graphs: MTTA & MTTR, Alert noise reduction, Incident count by Name, Tags, Alert sources, and so on.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# FAQs

This document will take you through some of the most frequently asked questions.

If you don’t find what you’re looking for, feel free to drop us a line in the Intercom widget below, write to our [Support](mailto:support@squadcast.com) team, or [*Ask the community*](https://community.squadcast.com/view/home)*.*

<details>

<summary><mark style="color:blue;">What is Squadcast? How can it help me?</mark></summary>

Squadcast is an incident response platform built on DevOps & SRE best practices to help you adopt the same to simplify incident management, get meaningful notifications, and enable faster incident resolution in collaboration.

You can learn how to use the platform to reduce your MTTA, and MTTR and significantly reduce your unplanned downtime.

</details>

<details>

<summary><mark style="color:blue;">Is Squadcast right for me?</mark></summary>

You should consider using Squadcast if:

* You want to add the ability to customize notification rules for your existing monitoring tools (i.e. text or call me if it’s high-urgency, send me a push notification, or email if it’s low-urgency).
* You want to extend agile incident management workflows to your existing environment with on-call scheduling, escalations, and incident tracking.
* You want a single place to view the overall health of your systems and operations, no matter how many tools, services, or applications your team manages.

</details>

<details>

<summary><mark style="color:blue;">How can I try out Squadcast?</mark></summary>

You can try out for a 14-day free trial, [<mark style="color:blue;">here</mark>](https://www.squadcast.com/register).

For any support setting up, you can reach out to us via the Intercom Chat Widget in the bottom right corner of your screen or you can drop a line to our [<mark style="color:blue;">Support Team</mark>](mailto:support@squadcast.com) and someone from our team will get back to you.

</details>

<details>

<summary><mark style="color:blue;">How does the 14-day trial work?</mark></summary>

When you sign up for Squadcast, you will be put on the [<mark style="color:blue;">trial plan</mark>](https://www.squadcast.com/register) for 14 days and can test out all the platform's features.

</details>

<details>

<summary><mark style="color:blue;">Can you extend my trial for a few days?</mark></summary>

If you wish to extend your trial for a few days, please reach out to our [<mark style="color:blue;">Support Team</mark>](mailto:support@squadcast.com).

</details>

<details>

<summary><mark style="color:blue;">Can Squadcast route incidents depending on the source of the problem?</mark></summary>

Yes. Squadcast allows you to add alert source integrations into services that mirror your service-oriented architecture. Each Squadcast service has its own associated notification and escalation rules (we call them “escalation policies”). This automatically routes issues to the people best able to resolve them.

For example, you should create an escalation policy for your database administrator team, and use this policy for all services that integrate with database monitoring systems. This ensures that database problems are always forwarded to a database specialist.

</details>

<details>

<summary><mark style="color:blue;">What notification methods do you support?</mark></summary>

In Squadcast, incident notifications are automatically sent using any preferred combination of phone calls, SMS, push notifications, and emails.

</details>

<details>

<summary><mark style="color:blue;">What if the on-call engineer doesn’t respond?</mark></summary>

Sqaudcast allows you to specify comprehensive escalation rules. When an incident is triggered in Squadcast, we will first try to contact the level-one on-call responder for the incident. If that person doesn’t answer within the user-specified escalation timeout, Squadcast will automatically escalate to the level-two responder, and so on.

You can repeat an individual escalation level a maximum of 5 times, while the entire escalation policy can be repeated an additional maximum of 3 times.

</details>

<details>

<summary><mark style="color:blue;">Do you support international SMS and phone calls?</mark></summary>

Yes, we support SMS and phone call notifications to most countries. We use third-party providers to send out SMS and phone call incident notifications.

To learn more about the list of supported countries, [click here](https://support.squadcast.com/notifications/understanding-incident-notifications#phone-calls-and-sms-support).

</details>

<details>

<summary><mark style="color:blue;">What numbers will the SMS and Phone Calls from Squadcast come from?</mark></summary>

Phone Calls:

1. +17076844278
2. +17072447799
3. +18038848378

SMS:

1. +17076844278
2. +17072447799
3. +18038848378

</details>

<details>

<summary><mark style="color:blue;">What happens when I receive a phone/SMS notification?</mark></summary>

When you receive a phone call for an incident, you will hear the incident details and you can acknowledge the incident by pressing 1 during the call.

When you receive an SMS for an incident, you will receive the incident details and a link to the incident. Click on the link to open the incident in the Squadcast mobile app (if applicable) or on the browser.

</details>

<details>

<summary><mark style="color:blue;">What is the difference between a User and a Stakeholder?</mark></summary>

Users are typically folks who go on-call and need to be notified every time an incident is triggered. Users can only access the configurations that they’re part of, and they can only access the incidents for teams that they’re a part of. Users can be granted additional permissions controlled by RBAC.

While, Stakeholders are individuals or groups from within the organization, that take an interest and are impacted by the outcomes of the incident management process.

Stakeholders have view-only access to all incidents. They are not notified by default for any of the incidents created in Squadcast. They also can create manual incidents should they notice something wrong and want to notify the on-call team of it. They can add notes to an incident and act as an incident watcher.

</details>

<details>

<summary><mark style="color:blue;">Where is our data stored?</mark></summary>

Squadcast allows customers to choose the geographic region of the Squadcast data centres that host their accounts. When signing up, you can choose the service region. Currently, the available options are the United States (US) and Europe (EU).

</details>

<details>

<summary><mark style="color:blue;">What is the difference between an account in the EU and US data centre?</mark></summary>

Accounts in both data centres will have all of the features, except for:

* [<mark style="color:blue;">Jira Server</mark>](https://support.squadcast.com/docs/jira-server-on-premise) extension will not be supported in the EU data centre.

</details>

<details>

<summary><mark style="color:blue;">Can I get a Quote?</mark></summary>

Reach out to the [<mark style="color:blue;">Support Team</mark>](mailto:support@squadcast.com) with details on the # of users/plan and subscription type and we'll get back to you.

</details>

<details>

<summary><mark style="color:blue;">Can you delete our data?</mark></summary>

We won't delete data unless you delete your account. When any account is deleted, all the data of that account will be deleted within 7 days.

</details>

<details>

<summary><mark style="color:blue;">I accidentally deleted my account. How can I undo this?</mark></summary>

Reach out to our [<mark style="color:blue;">Support Team</mark>](mailto:support@squadcast.com) within 7 days from the date of deletion and we’ll help you sort this out.

</details>

<details>

<summary><mark style="color:blue;">Can I request a new integration that is not supported on Squadcast?</mark></summary>

You can reach out to us via the Intercom Chat Widget in the bottom right corner of your screen or you can drop a line to our [<mark style="color:blue;">Support Team</mark>](mailto:support@squadcast.com) and someone will get back to you.

</details>

<details>

<summary><mark style="color:blue;">Does Squadcast support 2-factor authentication?</mark></summary>

We don’t support 2FA as of now. This is already a part of our Product Roadmap and we will be introducing this soon.

However, right now, we support SAML 2.0 based SSOs.

</details>

<details>

<summary><mark style="color:blue;">How long is the data retained in the system?</mark></summary>

* Essential Plan (Free) - 6 Months
* Pro Plan - 1 Year
* Essential Plan - Unlimited

</details>

<details>

<summary><mark style="color:blue;">How can I log a support ticket?</mark></summary>

There are multiple ways to reach us in case of issues you face.

1. Intercom Chat Widget in the bottom right corner of your screen
2. Write to our [<mark style="color:blue;">Support Team</mark>](mailto:support@squadcast.com)
3. [<mark style="color:blue;">Submit a ticket</mark>](https://www.squadcast.com/support-ticket-form)

</details>

<details>

<summary><mark style="color:blue;">Do we provide live call routing?</mark></summary>

We're using Webforms as a recommended alternative to live call routing today.

Webforms give your stakeholders and customers a way to report issues through a publicly hosted form. It helps improve your customer support offering and manage critical customer-impacting issues as incidents within Squadcast.

To see more on Webforms, click [<mark style="color:blue;">here</mark>](/webforms/webforms).

</details>

<details>

<summary><mark style="color:blue;">How can I write blog articles for you?</mark></summary>

Squadcast offers a Technical Writer Program and we’d love to get you on board! You can fill out [<mark style="color:blue;">this form</mark>](https://docs.google.com/forms/d/1yosFRhYQXu7rc28iMUzlxGVrlM66S2VYlfXYmAQX8y8/viewform?edit_requested=true) and we’ll get in touch with you for the next steps.

</details>

<details>

<summary><mark style="color:blue;">Can I copy my notification rules to other users?</mark></summary>

No, Notification Rules are a user-specific setting, with access limited to each individual. Even if you are an <mark style="color:red;">`Account Owner`</mark> or an <mark style="color:red;">`Admin`</mark>, you will still not be able to do this.

</details>

<details>

<summary><mark style="color:blue;">What email addresses are accepted?</mark></summary>

* We allow any and all valid emails.
* We do not allow temporary or junk emails.

</details>

<details>

<summary><mark style="color:blue;">Who do I reach out to for help with setting up?</mark></summary>

You can reach out to us via the Intercom Chat Widget in the bottom right corner of your screen or you can drop a line to our [<mark style="color:blue;">Support Team</mark>](mailto:support@squadcast.com) and someone from our team will get back to you.

</details>

<details>

<summary><mark style="color:blue;">Why do I get the error “The Email is not registered” even though I already have an account?</mark></summary>

For it to work, make sure you are logging into the correct data centre in which you have an account. While signing in, you will have the option to switch between data centres.

</details>


# Login With SolarWinds

A new login option exhibiting a unified experience for shared users of SWO SaaS and IR

{% hint style="info" %}
Squadcast is now SolarWinds Incident Response. We are undergoing a phased re-branding activity. In the mean time, you might notice both names in use across multiple places.
{% endhint %}

#### Authentication & Seamless Access

Users can move between SolarWinds Observability SaaS (SWO SaaS) and Incident Response (IR) without redundant credential entries.

**A. In-App Switching**

* The Switcher: Once the trial is active (or a paid subscription of the IR account is present), a "Incident Response" button appears within the SWO SaaS UI.
* Seamless Transition: Clicking this button utilises a shared session to move the user to the IR app without requiring a new login.

<figure><img src="/files/9AcsKRrwk6UrujzlaSKz" alt=""><figcaption></figcaption></figure>

**B. Incident Response Login Page**

* Federated Login: The IR login page will feature a "Login with SolarWinds" option.
* If you are already logged into your SWO SaaS account: You will be automatically signed into IR.
* Otherwise, below is the redirection logic:
  1. User clicks "Login with SolarWinds."
  2. System redirects to the SWO SaaS login page.
  3. User enters their SWO SaaS credentials.
  4. System redirects the authenticated user back to the IR home page.

<figure><img src="/files/eE5wMy74wB2V6rR9IJlL" alt=""><figcaption></figcaption></figure>

**C. Mobile Access**

* The Incident Response mobile app will now include the "Login with SolarWinds" button, ensuring consistency across web and mobile platforms.

<figure><img src="/files/1wdu8q3hUFqAJLwZYNcY" alt="" width="188"><figcaption></figcaption></figure>

#### FAQs

1. When a user in SWO SaaS is not present in the linked IR account but tries to “Sign in with SolarWinds” on IR login page, what happens then?

Such users will see an error - Your SolarWinds account is not yet linked to a SolarWinds Incident Response workspace. Please activate or join a workspace from your SolarWinds account. Such users can simply click on "Incident Response" button from their SWO SaaS account, which will then provision their user in IR and then, they can login with available options.

2. What happens when a user or a viewer clicks “Try Incident Response”?

Such users will see an error - You don’t have permissions to activate SolarWinds Incident Response for this organization. Please contact an Account Owner or Admin.


# Experience Incident Response with Observability (SaaS)

SWO SaaS users can experience modern incident response with automated trial provisioning

{% hint style="info" %}
Squadcast is now SolarWinds Incident Response. We are undergoing a phased re-branding activity. In the mean time, you might notice both names in use across multiple places.
{% endhint %}

### Incident Response Trial & Integration Overview

This feature enables existing SWO SaaS users to seamlessly provision, explore, and integrate a 30-day Enterprise Plan trial of the Incident Response (IR) platform directly from their current ecosystem.

#### Trial Activation & Provisioning

The activation process is designed to be frictionless, requiring minimal manual input.

* Visibility: A call-to-action (CTA) labeled "Try Incident Response" will be visible at the bottom of the left navigation bar for all account users and viewers.
* Eligibility: Only Admins or Account Owners have the permission to trigger the activation.
* Automated Provisioning: Clicking the button initiates an automated, single-click trial provisioning almost instantly.
* Redirection: Upon success, the user is automatically logged into the IR platform, pre-populated with basic entities for immediate context.

<figure><img src="/files/cbZFOMAM3IOVdF1TrPoh" alt=""><figcaption></figcaption></figure>

#### Onboarding & User Experience (FTUE)

To ensure quick value realisation, new trial users follow a guided First-Time User Experience (FTUE).

* Identity Verification: Users can start by adding and verifying their phone number via OTP to secure the account and enable alerting via SMS and voice calls.
* Guided Tours: Context-aware walkthroughs are triggered on each page the user visits, explaining key features and workflows at a high-level.
* Enterprise Access: The trial defaults to the Enterprise Plan, granting unlimited access to all features for 30 days.
* Customer Success: Our teams will provide high-touch support throughout the trial duration.

#### User Mapping, Management and Other Details

| SWO SaaS Type                                     | IR User Type  | IR Permissions, Roles                                          |
| ------------------------------------------------- | ------------- | -------------------------------------------------------------- |
| First Account Owner / Admin to provision IR Trial | Account Owner | All Permissions + Manage Team and Admin Roles in Default Team  |
| Account Owner / Admin                             | User          | All Permissions + Admin Role in Default Team                   |
| User                                              | User          | Permissions associated with User and User Role in Default Team |
| Viewer                                            | Stakeholder   | Observer Role in Default Team                                  |

{% hint style="info" %}
**User management limitations**\
Removing a user from SWO SaaS does not automatically remove them from IR. Such users must be manually marked as Stakeholders in IR.
{% endhint %}


# Types of Users

Understanding the different User Types supported in Squadcast - Account Owners, Users and Stakeholders

Squadcast has **three different types of users**:

<figure><img src="/files/OdTX5snEHXSyvRpJkwud" alt="Incident management - Types of users - Account holder, user, stakeholder"><figcaption></figcaption></figure>

### Account Owner <a href="#account-owner" id="account-owner"></a>

Squadcast allows only one Account Owner per Organization. An Account Owner has all the privileges in that Organization and by default will also be responsible for the billing of the account.

{% hint style="info" %}
The user that first signs up for the account & creates an Organization is by *default* the `Account Owner`. Learn about transferring ownership of the account to another user, [<mark style="color:blue;">here</mark>](/manage-users/change-account-owner#transferring-account-ownership).
{% endhint %}

{% hint style="warning" %}
Each Squadcast Organization can have only **one** `Account Owner` type of user.
{% endhint %}

### User <a href="#user" id="user"></a>

Users, by default, have the ability to customize their Profile, Notification Rules, Respond to, and resolve incidents. Typically, Users are the Engineers, SREs, Systems Engineers or anyone in your team that handles incident management & on-call.

### Stakeholder <a href="#stakeholder" id="stakeholder"></a>

As the name implies, these are typically other participants from the Organization who may have an interest in the incident management process. They could be Product Managers, Customer Support Representatives, CxOs, and so on.

Stakeholders have **view-only access** to all incidents. This means that Stakeholders are **not notified by default** for any of the incidents created in Squadcast. If Stakeholders need to be notified of incidents, [<mark style="color:blue;">this</mark>](/incidents-page/incident-notes#mentioning-users-squads-and-teams-in-notes) is how it can be done.

Stakeholders also have the ability to create manual incidents should they notice something wrong and want to notify the on-call team of it.

{% hint style="info" %}
**Note**: Stakeholder licenses are allocated at a 1:1 ratio with total users licenses purchased. Additional licenses available as add-on.
{% endhint %}

{% hint style="warning" %}
**Important:**

* Stakeholders will not receive SMS/Phone call notifications for incidents in Squadcast.
* Stakeholders cannot be added to Schedules or Escalation Policies.
  {% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Add and Delete Users

Adding and Deleting Users from your Organization

## Add Users <a href="#add-users" id="add-users"></a>

To add users to your organization,

1. Navigate to **Settings** -> Click on **Users** from the secondary navigation menu.
2. Next, Click on **Add Users** in the top right corner -> Here, fill in the following details to invite users into your Organization:
   * First Name
   * Last Name
   * Email
   * User Type (<mark style="color:red;">`User`</mark>, <mark style="color:red;">`Stakeholder`</mark>)
3. Lastly, click on the **Send Invites** button, to invite these newly added users to your Organization.

{% hint style="info" %}
**Note:**

You can only invite users from pre-approved domains.

You can find the list of approved domains for your organization in the web app in the Add Users page (<https://app.squadcast.com/add-users> , <https://app.eu.squadcast.com/add-users>).

If you need additional email domains pre-approved before adding users, you can reach out to our [Support Team](mailto:support@squadcast.com).
{% endhint %}

### Verify Email and Phone

To receive Phone/SMS/Email notifications, it is paramount that your team members have verified their account's phone number and email.

As a member or admin, you can easily check the verification status of each teammate's phone and email. Additionally, you can send reminders to those who haven't completed the verification process yet.

{% tabs %}
{% tab title="Email" %}

* After inviting a user, they will receive an email for verification. Until their verification is completed, an icon will indicate 'Verification Pending' next to their email.
* If a user hasn't verified their email, you can send them a reminder by clicking 'Send Reminder.'
* Please advise them to check not only their Inbox but also their Spam or Promotions folders to ensure the verification email is received.
* On verifying, you will begin to receive email notifications for your incidents.
  {% endtab %}

{% tab title="Phone" %}

* To start receiving SMS/phone notifications for your incidents, please add and verify your phone number in your profile.
* This simple step ensures you stay in the loop and can take timely action when incidents occur.
* If a user hasn't verfied their phone number, an icon will indicate 'Verification Pending' next to their phone number.
* You can send them a reminder by clicking 'Send Reminder.'
* Once email and phone are verified, their will be a :white\_check\_mark: icon against the user.
  {% endtab %}
  {% endtabs %}

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Configuring SSO before adding users helps ensure all users link their SSO account. Squadcast supports any SAML 2.0-based Single Sign-On (SSO) and you can set it for your Organization by following this integration guide [<mark style="color:blue;">here</mark>](https://support.squadcast.com/single-sign-on-sso/saml-2.0-based-sso)<mark style="color:blue;">.</mark>

\
🔹 **Best Practice Tip** 🔹 For larger teams, the best way to add users would be to bulk import them using a .csv file. More information on this is available [here](/manage-users/import-users).

🔹 **Best Practice Tip** 🔹 Make sure that all users have verified their emails and phone numbers as soon as they are added, to start receiving notifications.
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

To view the profile of another user added to the Organization, click **More Option** -> **View Profile.**

<img src="/files/PsTuqOrDdTzNtoJFiWf2" alt="View User Profile - How to view of user profile in Squadcast" data-size="original">
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> The Account Ownership cannot be altered or transferred through the Add Users flow. This action must be performed separately after the users have been imported.
{% endhint %}

## Delete Users <a href="#delete-users" id="delete-users"></a>

To remove/delete users added to your organization,

1. Navigate to **Settings** -> Click on **Users** from the secondary navigation menu.
2. Next, Click on the <mark style="color:red;">`More Options`</mark> icon and select **Delete** to delete the user.
3. If the user is part of any Team, a modal listing all the Teams that the user is a part of, appears as shown below. Users who are part of some team can’t be deleted. You’ll have to [remove them from the team](/manage-teams/add-and-remove-team-members#remove-a-member-from-a-team) before deleting them..

![Delete users  - How to delete user in Squadcast dashboard](/files/Pd4dm6BpJwTSyXf4dMSZ)

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Import Users

Import users into Squadcast using a .csv file

You can import multiple users to your Organization without having to add them manually, one-by-one.

### Steps to Import Users <a href="#steps-to-import-users" id="steps-to-import-users"></a>

1. Click on **Settings** in the sidebar

<figure><img src="/files/bHKBXE6OxwrF1F59nyZS" alt="Settings - How to import users in Squadcast"><figcaption></figcaption></figure>

2\. Click on **Users** from the secondary navigation menu

<figure><img src="/files/v0xqQ4DkkkLjdqiVIKyX" alt="Users - How to import users in Squadcast"><figcaption></figcaption></figure>

3\. Click on **Add Users** on the top right corner

<figure><img src="/files/8cPhTRcdifNrsCMCMrxB" alt="Add users - How to import users in Squadcast"><figcaption></figcaption></figure>

* Now, simply import multiple users’ details into the fields using a <mark style="color:red;">`.csv`</mark> file
* To import your <mark style="color:red;">`.csv`</mark> file, you can either drag and drop it on the page or click on the <mark style="color:red;">`select a file from your computer`</mark> on the top of the page

<figure><img src="/files/5Xib81jhj4fx99tR0HLZ" alt="Import Users in Squadcast - How to import users using .csv file"><figcaption></figcaption></figure>

{% hint style="warning" %}
**Important:**

Your `.csv` file should be of the following format:

```csv
first_name,last_name,email,user_type
Todd,Chavez,todd@squadcast.com,stakeholder
Diane,Nguyen,diane@squadcast.com,user
Princess,Carolyn,carolyn@squadcast.com,user
```

{% endhint %}

{% hint style="info" %}
**Note:**

You can skip the `user_type` field if you wish to fill that field later, post the import. By default, the `user_type` chosen will be `User`.
{% endhint %}

### Things to Remember <a href="#things-to-remember" id="things-to-remember"></a>

1. If you have already filled some fields and then choose to merge the <mark style="color:red;">`.csv`</mark> file data with the existing rows, click on the **Continue** button in the modal for confirmation of the same. Once the import is successful, you will see all the user details populated in the list. Click on the **Send Invites** button, on the bottom left, to invite these newly added users to your Organization.
2. The invited user will receive an email for verification. Until the user has been successfully verified, you will notice an icon indicating that <mark style="color:red;">`Verification Is Pending`</mark> against that User.
3. You can choose to resend the verification email by clicking on the <mark style="color:red;">`Verification Is Pending`</mark> icon should that be necessary. Please ensure that you check not only your *Inbox*, but also *Spam* or *Promotions* folders to ensure the verification email ended up landing there.
4. You cannot change or transfer the Account Ownership using this *Add Users* flow. This needs to be done after the users have been imported.
5. If an invalid **User Type** is detected, Squadcast automatically assigns the **User Type** as <mark style="color:red;">`User`</mark> for that particular user.
6. Ensure that there are **no spaces before or after the data in any of the cells, especially for the Email addresses of the users**.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# User Permissions - Access Controls

Organization-level Access Controls within your Account

Once you have onboarded users into your Organization, you can customize their accesses to the account by adding additional permissions. These are an additional level of permissions, on top of the *User Type* that they have been added as.

### Organization-level Permissions <a href="#organization-level-permissions" id="organization-level-permissions"></a>

The below Organization-level entities can be managed by enabling the checkboxes against the users:

1. Users
2. Teams
3. API Tokens
4. Webhooks
5. Extensions
6. Postmortem Templates
7. Audit Logs
8. Organization Analytics
9. Feature Settings
10. Billing

<figure><img src="/files/vyJ89n9iGJ9nnzsjqCTj" alt=""><figcaption></figcaption></figure>

### Understanding Organization Level Permissions <a href="#understanding-organization-level-permissions" id="understanding-organization-level-permissions"></a>

These Organization Level specific entity permissions can be assigned only to <mark style="color:red;">`Account Owners`</mark> and <mark style="color:red;">`Users`</mark>.

| Permission Type               | What it means                                             | User Types who can be assigned these |
| ----------------------------- | --------------------------------------------------------- | ------------------------------------ |
| Manage Users                  | Add, Delete users                                         | Account Owner, User                  |
| Manage Teams                  | Create Teams                                              | Account Owner, User                  |
| Manage API Tokens             | Create, Revoke API Tokens for all users                   | Account Owner, User                  |
| Manage Webhooks               | Add, Edit Webhooks                                        | Account Owner, User                  |
| Manage Extensions             | Enable, Disable Extensions                                | Account Owner, User                  |
| Manage Audit Logs             | View Audit Logs                                           | Account Owner, User                  |
| Manage Organisation Analytics | View Organisation Analytics                               | Account Owner, User                  |
| Manage Postmortem Templates   | Create & Modify Templates, set Default Template           | Account Owner, User                  |
| Feature Settings              | Enable and Disable Organisation-level feature settings    | Account Owner, User                  |
| Access and manage Billing     | Access, Manage Billing and Card Details in Billing Portal | Account Owner, User                  |

{% hint style="warning" %}
**Important:**

* `Account Owners` have all of these permissions by default.
* You cannot assign any permissions to a `Stakeholder` type of user by default.
  {% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Manage Your Profile

Edit your account details and set up notification preferences

### Profile Page <a href="#profile-page" id="profile-page"></a>

To view the profile page,

1. Click on the user icon in the upper right corner and select **Profile.**
2. On your **Profile** page, you can:
   1. Edit your *First Name* and *Last Name*
   2. *Change Password*
   3. *Change Phone Number*
   4. Update [<mark style="color:blue;">Personal Notification Rules</mark>](/manage-users/notification-rules). Additionally, if your Squadcast Organization is integrated with Slack/Google Hangouts, the same will be indicated here as well
   5. Update [<mark style="color:blue;">On-Call Reminder Notification Rules</mark>](/manage-users/on-call-reminder-rules)
   6. View the Escalation Policies, Squads, and Schedules you are a part of.
   7. [<mark style="color:blue;">Generate and view existing API Refresh Tokens</mark>](/terraform-and-api-documentation/public-api-refresh-token)
   8. For the past week, view the number of incidents Acknowledged and Resolved by you, along with MTTA and MTTR.

### Username

Your profile page will display your auto-generated username. This will help to distinguish users with common names within your team and identify the correct user on the platform.

The username is generated based on the prefix of your email address and cannot be manually edited. Additionally, this username will be visible across the platform, appearing in profile cards, filter lists, and more, as illustrated below.

<figure><img src="/files/tcQKjq7iF2PaCGClyDov" alt="" width="563"><figcaption><p>Image. Username across the platform</p></figcaption></figure>

### Edit Profile <a href="#edit-profile" id="edit-profile"></a>

1. Click on the **More Options** icon, and select **Edit**
2. Fill out the details and click **Save**

### Change Password <a href="#change-password" id="change-password"></a>

1. Click on the **More Options** icon, and select **Change Password**
2. Fill out *Current Password*, *New Password* and *Re-enter New Password*
3. Click on **Save**

### Change Mobile Number <a href="#change-mobile-number" id="change-mobile-number"></a>

1. Click on the **More Options** icon, and select **Change Phone Number**
2. Select your country *Dial Code* and fill in the *Mobile Number*
3. Click on **Verify**

<figure><img src="/files/ktcgNFc4qSqWhnwiz55K" alt="How to change mobile number in Squadcast"><figcaption></figcaption></figure>

4\. An OTP will be sent to you, fill in the OTP and click **Submit**

<figure><img src="/files/ZfXublJsW2pc4GJlQ289" alt="OTP verification in Squadcast"><figcaption></figcaption></figure>

5\. If you did not receive an OTP, you can click on **Send again** to get a new OTP. **Send again** will only be enabled after 1 minute has passed every-time an OTP is sent. You can also click on **Skip and verify later** to verify the *Mobile Number* later

<figure><img src="/files/QtXlkN2o5CfgmJiPmPRs" alt="OTP verification in Squadcast"><figcaption></figcaption></figure>

### Mobile Number Verification <a href="#mobile-number-verification" id="mobile-number-verification"></a>

{% hint style="warning" %}
**Disclaimer:**

1. Existing users of Squadcast will continue receiving Phone and SMS notifications as usual until **September 1st, 2021**. Post this, unless their Mobile Number is verified, they will not receive Phone and SMS notifications
2. For new users of Squadcast, please verify your Mobile Number in order to start receiving Phone and SMS notifications post signing up
3. In order to prevent misuse, a user cannot edit and verify the modified phone number more than 3 times during the user's lifetime. If there is a legitimate reason for doing so, please reach out to our Support who will validate the reasoning provided and help as needed.
   {% endhint %}

{% hint style="info" %}
**Note:**

1. In order to receive Phone and SMS notifications, ensure a valid Mobile Number is entered. By verifying the mobile number, you will be opting-in to receive any incident-related SMS and Voice Alerts
2. Phone and SMS notifications will be disabled if the Mobile Number is either not added or not verified (when added)
3. Every time you change your Mobile Number, you have to verify the new Mobile Number to continue receiving Phone and SMS notifications
   {% endhint %}

### Change Timezone and Date Format

1. Click on the **More Options** icon, and select **Edit**
2. Select your country's *Timezone* and the *Date Format*
3. Click on **Save**

![Squadcast onboarding details](/files/beQEEz9dlHBToIf8wdIK)

{% hint style="info" %} <mark style="color:blue;">**Note**</mark><mark style="color:blue;">:</mark>

Places where your Timezone will still reflect UTC:

* Incident Exports
* Analytics Panel Exports
* Status Page Incidents

Postmortem Download and Activity Timeline Download will be in the User selected Timezone
{% endhint %}

### While Onboarding <a href="#while-onboarding" id="while-onboarding"></a>

1. Enter the details, *Mobile Number* is **optional**. You can add a *Mobile Number* later on your **Profile** page

<figure><img src="/files/nhd7jwnOoy4R6lBYw1Eo" alt="Squadcast onboarding details"><figcaption></figcaption></figure>

2\. If *Mobile Number* is provided, a One-time Password (OTP) will be sent to you through SMS and you will be taken to the OTP verification screen

1. Fill in the OTP and click on **Verify** to verify your *Mobile Number*
2. If you did not receive an OTP, you can click on **Send again** to get a new OTP. **Send again** will only be enabled after 1 minute has passed every time an OTP is sent
3. If you want to verify your *Mobile Number* later, you can select **Skip and verify later**. *Mobile Number* can be verified on the [<mark style="color:blue;">**Profile page**</mark>](/manage-users/manage-your-profile)
4. You will then be logged in, irrespective of whether you choose to verify instantly or at a later point in time

<figure><img src="/files/LOZdWnjkFRgzABmbPjw8" alt="Squadcast mobile OTP verification"><figcaption></figcaption></figure>

### In Profile Page <a href="#in-profile-page" id="in-profile-page"></a>

To verify the *Mobile Number:*

1. Click on **Verify Phone Number**

![Verify Phone Number - How to verify the Phone Number](/files/yu8xtXr7p1CbLerz3JOZ)

2\. An OTP will be sent to your *Mobile Number*. Fill in the OTP and **Submit**

<figure><img src="/files/UKgPmXqvILEsVgOtj35q" alt="Create User Profile - OTP Verification"><figcaption></figcaption></figure>

3\. If you did not receive an OTP, you can click on **Send again** to get a new OTP. **Send again** will only be enabled after 1 minute has passed every time an OTP is sent. You can also click on **Skip and verify later** to verify the *Mobile Number* later

<figure><img src="/files/xFjpX5n34ItiCU3bZzxY" alt="Create User Profile - Did not receive OTP"><figcaption></figcaption></figure>

4\. After verification is complete, the warning message will disappear and you will receive Phone & SMS notifications for incidents

<figure><img src="/files/q1HapZmnEGJ9slPqcy9C" alt="Edit User Profile Details"><figcaption></figcaption></figure>

{% hint style="info" %}
**Note:**

If the Mobile Number is not verified via OTP, the same will be indicated in the web app as well as the mobile app.

**In the web app:**

<img src="/files/SG1dYWS07UKhwGj01k83" alt="Add User Mobile Number - Verify OTP" data-size="original">

**In the mobile app:**

Navigate to **My Profile**:

<img src="/files/9tusVPjgvc5IL9NO8jXk" alt="Edit User Details in Mobile App" data-size="original">
{% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Incident (Personal) Notification Rules

Notification rules define how and when you are notified when an incident is assigned to you

Incident (Personal) Notification Rules determine how an individual user is notified for an incident that is assigned to them. One can set up rules to be notified on any of the following notification channels:

* Email
* [<mark style="color:blue;">Push notification on the Squadcast mobile app</mark>](/mobile-app/using-the-mobile-app)
* SMS
* Phone

As a preference, one would like to be notified a certain way for P1 priority incidents versus P4 or P5 priority incidents. By selecting the priority first, users have a way to define how they should be notified for incidents assigned to them.

{% hint style="info" %}
**Edit Notification Rules for other users of Squadcast**

Irrespective of your User Role in Squadcast, you will only be able to set/edit your own Incident (Personal) Notification Rules. You will not be able to do it for any other member of Squadcast. If you wish to explicitly specify Notification Channels for all the users, this can be done in the Escalation Policy by selecting **Custom** from the drop-down.
{% endhint %}

### Edit Notification Rules <a href="#edit-notification-rules" id="edit-notification-rules"></a>

1. Click on the user icon in the upper right corner and select **Profile**

<figure><img src="/files/cRn9cLd6QhUeUNIcmKBh" alt="Notification rules in Squadcast"><figcaption></figcaption></figure>

2\. You will be taken into the **My Profile** section where you can navigate to **Alert Settings** to configure this

<figure><img src="/files/jzcZSNtnCPjU9ixK1jTO" alt=""><figcaption></figcaption></figure>

By default, there will be a a fallback / default configuration that will be used for all incidents without a defined priority if it is assigned to that user.

<figure><img src="/files/tpKjGQIOdKSuTkFPlC4P" alt=""><figcaption></figcaption></figure>

3\. To define a priority-specific configuration, start by selecting **Add Notification Rules**

<figure><img src="/files/Z0MultCjLCgL931PhXBh" alt=""><figcaption></figcaption></figure>

Here, you can select the priority that this configuration needs to apply to and define the notification rules

4\. Select **Save** after making changes to save the configuration

{% hint style="info" %}
**Info:**

1. Each priority - P1 through P5 can have one configuration each
2. You can set up a rule to be notified immediately, as soon as the incident is triggered, if you input 0 in the text box that asks for time
3. You cannot add `SMS` and `Phone` more than 2 times within each of your priority-specific configurations. However, there are no such limits for `Push` or `Email`
4. A maximum of 8 rules per priority-specific configuration can be configured
5. You cannot define 2 rules through the same medium to be dispatched at the same time - for instance, you cannot have 2 rules via Email that has to be triggered at time t=0 as believe spam has not helped anyone, and definitely not while looking at high priority incidents
   {% endhint %}

You’re good to go. Now, when an incident is assigned to **you**, you will be notified based on your notification preferences set in the **Incident (Personal)** **Notification Rules** section.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# On-Call Reminder Rules

On-Call Reminder Rules define how and when you are notified about the upcoming On-Call Shift

On-Call Reminder Rules determine how an individual user is notified about the upcoming On-Call shift. One can set up rules to be notified on any of the following notification channels:

* Email
* [<mark style="color:blue;">Push notification on the Squadcast mobile app</mark>](/mobile-app/using-the-mobile-app)

## Edit On-Call Reminder Rules <a href="#edit-on-call-reminder-rules" id="edit-on-call-reminder-rules"></a>

1. Click on the user icon in the upper right corner and select **Profile**

<figure><img src="/files/PWE7jIHocPD1LbM3geUu" alt="How to edit on call reminder notification in Squadcast"><figcaption></figcaption></figure>

2\. You will be taken into the **My Profile** section where you can see the **On-Call Reminder Rules** below the **Notification Rules** on the right. Click on the **Edit** button to edit the rules

<figure><img src="/files/J9CdB7QFbGxJssQ6nmMO" alt="on call reminders rules notification via email in Squadcast"><figcaption></figcaption></figure>

3\. Choose the medium from the drop-down, enter the amount of time before which you wish to be reminded and choose the unit of time from the drop-down

4\. You can also add new rules by clicking **Add More Rules** at the bottom

5\. Select **Save** after making changes to save the configuration

You’re good to go. Now, when **you** have an upcoming On-Call Shift, you will be notified based on your On-Call Reminder Rules preferences set in the **On-Call Reminder Rules** section.

<figure><img src="/files/0TuXW6xQKO7BFVrudeoe" alt="on call management via on call notification rules in Squadcast"><figcaption></figcaption></figure>

{% hint style="info" %}
**Note:**

1. By default, every new user’s **On-Call Reminder Rules** would be defined by Squadcast as 1 hour before the On-Call Shift starts.
2. You can remove all the rules from **On-Call Reminder Rules** if you wish not to be reminded about your upcoming On-Call Shift.
   {% endhint %}

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark>

1. In the case of a **complete override**, where the original on-call participant is overridden for the entire duration, only the override participant will receive on-call reminder notifications.

In the following example, only "PK" will receive on-call reminders.

<img src="/files/bfv81iscLbQYSKinwYwD" alt="" data-size="original">

2. In the case of a **partial override**, on-call reminder notifications are sent to both the original on-call participant and the override participant.

In the following example, both "DT" and "PK" will receive the on-call reminders.

<img src="/files/mEhp2gDI7gB6mcbbMt3Y" alt="" data-size="original">
{% endhint %}

## Global On-Call Reminder Rules (API-First Feature)

The Global On-Call Reminder Rules feature allows organizations to set uniform On-Call Reminder Rules for all users within a team. This API-first feature ensures consistency across the team by overriding any individual On-Call Reminder Rules set by users on their Profile Pages. These settings will be indicated on user profile pages within both the Web App and Mobile App.

* **Uniform On-Call Reminder Rules**: Applies the same reminder rules to all users within a team, ensuring consistency.
* **Team-Wise Application**: The feature applies team-wide and includes all relevant users in the organization. Stakeholders and observer roles associated with customer roles are excluded.
* **Reverting to Default**: If the feature is disabled, the system will revert to the original settings as they were previously set by the user.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

Please note that this feature can be enabled, disabled, or modified by users with the Manage Team role within any team in the organization.
{% endhint %}

{% hint style="info" %}
**Note**:

For more details, refer to the [<mark style="color:blue;">API Documentation</mark>](https://apidocs.squadcast.com/#a34b87b9-c873-4d78-a4f3-78e2f7903de7) and [<mark style="color:blue;">Terraform Documentation</mark>](https://registry.terraform.io/providers/SquadcastHub/squadcast/latest/docs/resources/global_oncall_reminder_rules) for Global On-Call Reminder Rules.
{% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Change Account Owner

Transfer your Account Ownership to someone else from your Organization

### Transferring Account Ownership <a href="#transferring-account-ownership" id="transferring-account-ownership"></a>

There might be multiple reasons why one would want to transfer Account Ownership to another user in the Organization. This can be done using one of the two methods.

### Via the Users section <a href="#via-the-users-section" id="via-the-users-section"></a>

1. Click on **Settings** in the sidebar

<figure><img src="/files/pr82PDtm3b5ZdYPnzbD0" alt="how to transfer account ownership in Squadcasst - Settings"><figcaption></figcaption></figure>

2\. Click on **Users** from the secondary navigation menu

<figure><img src="/files/vIMev17vrKEQtfLbOgMX" alt="change account owner user in Squadcast"><figcaption></figcaption></figure>

3\. Click on **Transfer Ownership** beside your name

<figure><img src="/files/P1MQk1Bf75hbSCqFYWMr" alt="transfer ownership in Squadcast"><figcaption></figcaption></figure>

### Via Organization Settings <a href="#via-organization-settings" id="via-organization-settings"></a>

1. Click on **Settings**, then select **General Settings** and click on **Transfer Ownership**

<figure><img src="/files/TRXWldxu1IiySbpAO2K4" alt="transfer ownership via Organization in Squadcast"><figcaption></figcaption></figure>

2\. From the **Users** drop-down, select the user you would like to transfer your Organization’s ownership to

<figure><img src="/files/073UyLksoAMi3whQMVpx" alt="how to transfer Organization Ownership in Squadcast"><figcaption></figcaption></figure>

3\. Enable the checkbox confirming your action to proceed. Once you have confirmed, click on the **Save** button to transfer your ownership to that user

<figure><img src="/files/fzzRsFxsYPzCBnGoKfz5" alt="change the account owner in Squadcast"><figcaption></figcaption></figure>

{% hint style="warning" %}
**Important:**

Once the ownership transfer is successful, your **User Type** within the Organization will be changed to `User` from `Account Owner`.
{% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Understanding Teams

What Teams are and the entities it can contain

Most organizations are divided into various different operational units. This is typically done to allow them to manage, design and increase the efficiency of their business operations to meet their internal requirements. Some are organized by technical specializations, others by activities, some by services, by geography, or any combination of those (or others). Whichever structure the organization chooses, these operational units remain responsible for the problems which occur in their own environments.

Having Teams is a way for customers to represent their organizational structure. The number of Teams that can be created per Organization is based on our [<mark style="color:blue;">Pricing Plans</mark>](https://squadcast.com/pricing)<mark style="color:blue;">.</mark>

### Understanding the Default Team <a href="#understanding-the-default-team" id="understanding-the-default-team"></a>

This, as the name suggests, is the <mark style="color:red;">`default`</mark> team in an Organization. Every and all users in the Organization will be a part of the **Default Team**.

<figure><img src="/files/QzLC1tlaqwYXrfKF0Jpw" alt="how to check default team in Sqaudcast"><figcaption></figcaption></figure>

{% hint style="warning" %}
**Important:**

1. This behaviour/flow cannot be modified.
2. The **Default Team** cannot be deleted
   {% endhint %}

### Viewing the Default Team <a href="#viewing-the-default-team" id="viewing-the-default-team"></a>

1. Click on **Settings** on the sidebar

<figure><img src="/files/c1VbRZoqtx5ueOAFsTPG" alt="how to view default team members in Squadcast"><figcaption></figcaption></figure>

2\. Click on **Teams** from the secondary navigation menu

<figure><img src="/files/feXiREsQWfPkqL0sYux7" alt="How to view default team members in Squadcast"><figcaption></figcaption></figure>

3\. Click on **Default Team**

<figure><img src="/files/fnSSZbbWT8W6Ou83dIw9" alt="Manage Teams - How to view default team members in Squadcast"><figcaption></figcaption></figure>

Here, you will be able to view:

* All the [<mark style="color:blue;">`Members`</mark>](/manage-users/add-and-delete-users) of this Team (your entire Organization)
* The [<mark style="color:blue;">`Roles`</mark>](/manage-users/user-permissions-access-controls) of these <mark style="color:red;">`Members`</mark>
* The associated [<mark style="color:blue;">`Entities`</mark>](#entities-in-squadcast)
* Any defined [<mark style="color:blue;">`Squads`</mark>](/manage-teams/squads)
* Team-specific [<mark style="color:blue;">`Settings`</mark>](/manage-teams/create-and-delete-teams)

### Entities in Squadcast <a href="#entities-in-squadcast" id="entities-in-squadcast"></a>

Each team has ownership of specific entities that they are responsible for, or are unique to them. You can easily search for these entities or filter them based on their owner.

<figure><img src="/files/prWAdZIYBHkryNmYy92r" alt="" width="563"><figcaption></figcaption></figure>

The entities include:

1. [<mark style="color:blue;">Escalation Policies</mark>](/escalation-policies/create-and-manage-escalation-policies)
2. [<mark style="color:blue;">Schedules</mark>](/schedules/schedules-legacy/create-and-manage-on-call-schedules-and-rotations)
3. [<mark style="color:blue;">Services</mark>](/services/adding-a-service)
4. [<mark style="color:blue;">Status Pages</mark>](/status-page/status-page)
5. [<mark style="color:blue;">Postmortems</mark>](/postmortems/create-postmortems)
6. [<mark style="color:blue;">Runbooks</mark>](/runbooks/runbooks)
7. [<mark style="color:blue;">SLOs</mark>](/slo-tracker/configure-and-monitor-your-slos)
8. [<mark style="color:blue;">Webforms</mark>](/webforms/webforms)
9. [<mark style="color:blue;">Global Event Rules</mark>](/global-event-rulesets/global-event-rulesets)
10. [<mark style="color:blue;">Live Call Routing</mark>](/live-call-routing/live-call-routing)

All such entities owned by a Team are indicated here.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Role Based Access Control

Understanding the Roles and Access Controls for Teams and Custom Roles

Roles are a *set of permissions* granted that are specific to the Team that the user is a member of. There are pre-defined Roles that can be directly assigned to the members of the Team. If one wants to define [<mark style="color:blue;">Custom Roles</mark>](#custom-roles)<mark style="color:blue;">,</mark> that is also doable.

It is critical to thoroughly note that **Roles are Team-specific**, that is, **Roles will allow you specific abilities for just that Team that you are a part of**.

### Default Types of Roles and Abilities <a href="#default-types-of-roles-and-abilities" id="default-types-of-roles-and-abilities"></a>

There are 4 different default Roles that can be assigned to a Team member in Squadcast. See below to understand what they are, along with their abilities.

### 1. Manage Teams <a href="#id-1-manage-teams" id="id-1-manage-teams"></a>

This Role will allow you to manage just this Team. The abilities are:

| Entity | Abilities                |
| ------ | ------------------------ |
| Teams  | `read` `update` `delete` |

### 2. Admin <a href="#id-2-admin" id="id-2-admin"></a>

| Entity              | Abilities                         |
| ------------------- | --------------------------------- |
| Escalation Policies | `create` `read` `update` `delete` |
| Postmortems         | `create` `read` `update` `delete` |
| Runbooks            | `create` `read` `update` `delete` |
| Schedules           | `create` `read` `update` `delete` |
| Services            | `create` `read` `update` `delete` |
| SLOs                | `create` `read` `update` `delete` |
| Squads              | `create` `read` `update` `delete` |
| Status Pages        | `create` `read` `update` `delete` |
| Team analytics      | `read`                            |
| Webforms            | `create` `read` `update` `delete` |

### 3. User <a href="#id-3-user" id="id-3-user"></a>

| Entity              | Abilities       |
| ------------------- | --------------- |
| Escalation Policies | `read` `update` |
| Postmortems         | `read` `update` |
| Runbooks            | `read` `update` |
| Schedules           | `read` `update` |
| Services            | `read` `update` |
| SLOs                | `read` `update` |
| Squads              | `read` `update` |
| Status Pages        | `read` `update` |
| Team analytics      | `read`          |
| Webforms            | `read` `update` |

### 4. Observer <a href="#id-4-observer" id="id-4-observer"></a>

| Entity              | Abilities |
| ------------------- | --------- |
| Escalation Policies | `read`    |
| Postmortems         | `read`    |
| Runbooks            | `read`    |
| Schedules           | `read`    |
| Services            | `read`    |
| SLOs                | `read`    |
| Squads              | `read`    |
| Status Pages        | `read`    |
| Team analytics      | `read`    |
| Webforms            | `read`    |

{% hint style="warning" %}
**Important:** `Stakeholders` can be added with only `Observer`Role within a Team.
{% endhint %}

### Manage Roles and Abilities <a href="#manage-roles-and-abilities" id="manage-roles-and-abilities"></a>

Follow the steps below to manage Roles for a Team:

1. Click on **Settings** in the sidebar

<figure><img src="/files/tFBmruZP7RcuTccCXlrb" alt="How to manage role and abilitis in Squadcast"><figcaption></figcaption></figure>

2\. Click on **Teams** from the secondary navigation menu and select the Team you want to manage *Roles and Access Controls* for

<figure><img src="/files/y1ybeLdclqRULfIzf2lA" alt="Assign access to teams in squadcast"><figcaption></figcaption></figure>

3\. Click on **Roles** from the horizontal menu and you will have the option to <mark style="color:red;">`edit`</mark> or <mark style="color:red;">`delete`</mark> the Roles and Access Controls via the <mark style="color:red;">`More Option`</mark>

<figure><img src="/files/qgYYVA0FwTXjfu8MIvbL" alt="How to edit the roles in Squadcast"><figcaption></figcaption></figure>

{% hint style="info" %}
**Note:** Roles are Team specific, i.e. roles will allow you specific abilities for just that team that you’re a part of.
{% endhint %}

### Custom Roles <a href="#custom-roles" id="custom-roles"></a>

There might be situations where the predefined *Roles and Abilities* available for members of a Team in Squadcast, by default, are not sufficient or that they do not align with how you want your Team members to be organized (in terms of Access Controls).

In such situations, you can either choose to modify one of the default Roles itself or you can create **Custom Roles** to provide special, customised permissions to specific types of users in your Organization for that Team.

It is critical to thoroughly note that only members of the Team with **Manage Team** Role permissions can create and manage **Custom Roles**.

### Creating a Custom Role <a href="#creating-a-custom-role" id="creating-a-custom-role"></a>

Follow the steps below to create a Custom Role for a Team:

1. Click on **Settings** in the sidebar

<figure><img src="/files/c1VbRZoqtx5ueOAFsTPG" alt="how to create custom rules in Squadcast"><figcaption></figcaption></figure>

2\. Click on **Teams** from the secondary navigation menu and select the Team for which you want to add the **Custom Role**

<figure><img src="/files/zDlnVdbM31LPGkiYgsr9" alt="how to assign custom role to team in Squadcast"><figcaption></figcaption></figure>

3\. Click on **Roles** from the horizontal menu and scroll down to the bottom of the page

<figure><img src="/files/9MqUGmPyMK9dIfVl4Ilv" alt="Add new team role in Squadcast"><figcaption></figcaption></figure>

4\. Click on **Add new team role**. Here:

* Give the Custom Role a **Name** indicating the Role type
* Next, for the available Entities (Escalation Policies, Postmortems, Schedules, Services, Squads, Status Pages), select the Access Controls (<mark style="color:red;">`read`</mark>, <mark style="color:red;">`create`</mark>, <mark style="color:red;">`update`</mark>, <mark style="color:red;">`delete`</mark>)

5\. Click on **Save** to create the new Custom Role for the Team

<figure><img src="/files/J7JslYXNqfuVFwQd7Y9V" alt="Assign custom role to team in Squadcast"><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Owner Based Access Control

Understanding the Roles and Access Controls for Entities within OBAC.

Owner-Based Access Control is an access control model where the ability to modify and delete entities is restricted to just its owners, Team Owners, and the Account Owner.

It is an alternative to the Role Based Access Control (RBAC) model, and it offers a robust framework that reduces the scope for human errors by restricting the ability to modify and delete entities to just its owners.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

Please note that this feature is made available to select accounts only. You can reach out to our [<mark style="color:blue;">Support Team</mark>](mailto:support@squadcast.com) to have it enabled for your account.
{% endhint %}

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>:

This section applies exclusively to organizations with Owner Based Access Control enabled. There are no changes for other organizations that have opted for Role Based Access Control.
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

Users can refer to this document to learn how they can migrate from Role-Based Access Control (RBAC) to Owner-Based Access Control (OBAC) in Terraform: [Migrating from RBAC to OBAC with Terraform](https://www.squadcast.com/blog/how-do-you-migrate-from-rbac-to-obac-with-terraform)<mark style="color:blue;">.</mark>
{% endhint %}

## Managing Teams

### User Roles

With Owner-Based Access Control, there are three different types of roles in a Team:

* [<mark style="color:blue;">Team Owner</mark>](#team-owner)
* [<mark style="color:blue;">Team Member</mark>](#team-member)
* [<mark style="color:blue;">Stakeholder</mark>](#stakeholder)

Each role decides what a user can do. Roles show what actions users can take in a team.

<figure><img src="/files/22Tj120t2jEN3lwT2ETE" alt=""><figcaption></figcaption></figure>

#### Team Owner

In a team:

* Team Owners can manage the team, including adding/removing members, changing team member's roles, and deleting the team.
* Team Owners can modify or delete any team entity, regardless of ownership.
* Only Team Owners can create, modify, and delete Stakeholder Groups for the team.
* Both Team Owners and Team Members can create entities and squads.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> Teams can have multiple Team Owners.
{% endhint %}

#### Team Member

In a team:

* Team Members can create entities and squads.

#### Stakeholder

In a team:

* Stakeholders have read-only access to all team entities.

## Managing Squads

### User Roles

With Owner-Based Access Control, there are three different types of roles in a Squad:

* [<mark style="color:blue;">Squad Owner</mark>](#squad-owner)
* [<mark style="color:blue;">Squad Member</mark>](#squad-member)

Each role decides what a user can do. Roles show what actions users can take in a squad.

<figure><img src="https://lh7-us.googleusercontent.com/AxFiYi2QZT3Vi8U_-ZS_X-4XmDLNOe1h9vUJxLAYj9lUYK45CbQHrf75oLaqjiNykEokVCgeexJW2d2wNqdlFG9PgiWsR6aS2zNX-7QTgumYzmkWttBVEojuHcU62oMDHdGFIfBZbQCDyyWAK_UorGg" alt="" width="563"><figcaption></figcaption></figure>

#### Squad Owner

In a squad:

* Squad Owners can manage the squad, including adding/removing members, changing squad member's roles, and deleting the squad.
* Squad Owners are the only ones who can transfer ownership of an entity owned by the squad to another user or squad.

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>:

* User permissions to create entities and squads are based on their team role, not their squad role. Both team members and team owners can create entities and squads.

* Team Owners have authority over all squads in a team, even if they are not explicitly part of those squads.
  {% endhint %}

* Stakeholders are not part of any squads.

#### Squad Member

In a squad:

* Squad Members can view and edit the entities within a squad.

## Access Control for Entities

<table><thead><tr><th width="233">Action</th><th>Who can perform this action</th></tr></thead><tbody><tr><td>View Entities</td><td>All users have access to view the entities associated with their team.</td></tr><tr><td>Create Entities</td><td>All members of a team (except stakeholders) can create entities.</td></tr><tr><td>Modify Entities</td><td><ol><li>If an entity is owned by a user, the user can modify the entity.</li><li>If an entity is owned by a squad, all members within the squad can modify the entity.</li></ol><p><mark style="color:blue;"><strong>Note</strong></mark>: Team Owners and the Account Owner have the access to modify all entities within the team.</p></td></tr><tr><td>Change Entity Owner</td><td><ol><li>If an entity is owned by a user, the user can change the entity's owner.</li><li>If an entity is owned by a squad, only the owners of that squad can change the entity's owner.</li></ol><p><mark style="color:blue;"><strong>Note</strong></mark>: Team Owners and the Account Owner have the access to change the owner of any entity within the team.</p></td></tr><tr><td>Delete Entities</td><td><ol><li>If an entity is owned by a user, only that user can delete the entity.</li><li>If an entity is owned by a squad, only the owners of that squad can delete the entity.</li></ol><p><mark style="color:blue;"><strong>Note</strong></mark>: Team Owners and the Account Owner have the access to delete all entities within the team.</p></td></tr></tbody></table>


# Create and Delete Teams

Creating a new Team or deleting an existing Team

This document will walk you through how you can create a new Team or delete an existing Team.

### Create a Team <a href="#create-a-team" id="create-a-team"></a>

1. Navigate to **Settings** -> **Teams** from the secondary navigation menu.

<figure><img src="/files/iOqTJwcAUIjiJY2V9bCk" alt="how to add team in Squadcast" width="563"><figcaption></figcaption></figure>

3\. Click on the <mark style="color:red;">`plus (+)`</mark> button and enter the suitable <mark style="color:red;">`Name`</mark> for the new Team.

<figure><img src="/files/c8qhL6cLXCVKUcWXXNVh" alt="" width="188"><figcaption></figcaption></figure>

4\. Click on **Create**

<figure><img src="/files/t6zpwYAhtU7RIwRWj8Bq" alt="" width="188"><figcaption></figcaption></figure>

### Delete a Team <a href="#delete-a-team" id="delete-a-team"></a>

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark> Please be aware that deleting a Team is irreversible.
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>:

1. In organizations with Owner Based Access Control enabled, only Team Owners have the authority to delete a team.

2. For organizations with Role-Based Access Control, users with the Manage Team role can delete the team.
   {% endhint %}

3. Navigate to **Settings** -> **Teams,** and select the *Team* you want to delete.

<figure><img src="/files/iOqTJwcAUIjiJY2V9bCk" alt="How to delete a team account Squadcast" width="563"><figcaption></figcaption></figure>

In this example, we are deleting the <mark style="color:red;">`Testing Team`</mark>.

3\. Click on **Settings** from the horizontal menu and enable the <mark style="color:red;">`Delete Testing Team`</mark> checkbox.

4\. Click on the **Delete Testing Team** button.

<figure><img src="/files/pwIlCQm4WW7fLmDGzyyL" alt="How to delete a team in Squadcast" width="563"><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Add and Remove Team Members

This document will walk you through how you can add or remove members from a Team.

### Add a Member to a Team <a href="#add-a-member-to-a-team" id="add-a-member-to-a-team"></a>

1. Navigate to **Settings** -> **Teams** and select the Team to which a new member needs to be added.

<figure><img src="/files/zDlnVdbM31LPGkiYgsr9" alt="How to add a new member in an existing team in Squadcast" width="563"><figcaption></figcaption></figure>

2. Under **Members** section, scroll down to the bottom of the page -> Click on **Add New Members**, select the member from the drop-down list, and select the <mark style="color:red;">`Team Roles.`</mark>
3. Click on **Add Members** and confirm their addition to the Team

<figure><img src="/files/FdMtwzYVIZM6axoNVPlZ" alt="" width="188"><figcaption></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>:

In organizations utilizing Owner-Based Access Control, users can be assigned one of three Team Roles: Team Owner, Team Member, or Stakeholder. Please refer to the image below.

<img src="/files/OTIdgjuI3d2PAM8G9QOQ" alt="" data-size="original">
{% endhint %}

### Remove a Member from a Team <a href="#remove-a-member-from-a-team" id="remove-a-member-from-a-team"></a>

1. Click on **Settings** in the sidebar

<figure><img src="/files/tFBmruZP7RcuTccCXlrb" alt="How to remove a member from a team in Squadcast" width="563"><figcaption></figcaption></figure>

2\. Click on **Teams** from the secondary navigation menu and select the Team from which the Team member has to be removed

<figure><img src="/files/zDlnVdbM31LPGkiYgsr9" alt="How to remove a member from an existing Squadcast team" width="563"><figcaption></figcaption></figure>

3\. Click on **Members** from the horizontal menu and hover over the name of the Team member that needs to be removed

4\. Click on **Remove** via <mark style="color:red;">`More Options`</mark> corresponding to the concerned Team member & confirm **Remove** in the pop-up window to remove the member from the Team

<figure><img src="/files/Hk3gslRTUSErE97cX1rE" alt="Remove team member from Squadcast" width="563"><figcaption></figcaption></figure>

5\. If the Team member to be removed is a part of any of the entities (Incidents, Escalation Policies, Schedules) that belong to the Team, a modal displaying those details will appear

<figure><img src="/files/xOhDCaOjSeD7Ohs4M4LZ" alt="" width="188"><figcaption></figcaption></figure>

6\. Now, select the Team member who will replace the one who is being removed using the available drop-down

{% hint style="warning" %}
**Important:** For incidents, there are 2 options:

* If the checkbox is left **unchecked**, all the incidents assigned to the member being removed will be reassigned to the replacing Team member. The replacing Team member will receive **one** Email notification notifying them of the incidents that are now assigned to them
* If the checkbox is **checked**, all the **open** incidents (incidents in the <mark style="color:red;">`Triggered`</mark> and <mark style="color:red;">`Acknowledged`</mark> states) assigned to the member being removed will be suppressed
  {% endhint %}

7\. Once the appropriate replacement Team member is selected and action for incidents is determined, click on **Swap & Remove.**

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark> If a user is removed from the team or downgraded to a stakeholder role, they will be removed from the responder list.
{% endhint %}

8\. A success modal confirming the swap will appear, like in the screenshot below

<figure><img src="/files/ojiteuggWz2K7pWvxXta" alt="" width="188"><figcaption></figcaption></figure>

In addition to this, if a user also needs to be deleted from the Organization, please follow the steps [here ](/manage-users/add-and-delete-users#delete-users)to do so.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Squads

What Squads are and understanding how to manage Squads

Squads are smaller groups of members within Teams. Squads could correspond to groups of people who are responsible for specific projects within a Team.

These are especially useful for adding groups of people to be on-call in a [<mark style="color:blue;">Schedule</mark>](/schedules/schedules-legacy/create-and-manage-on-call-schedules-and-rotations). Squads are also handy when you need to notify the entire group together. For instance, when coordinated responses are required for high-urgency, high-complexity incidents, or as the last level of notification in an <mark style="color:blue;">Escalation Policy</mark> when an incident is still unacknowledged at that point.

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>:

* In organizations with Role-Based Access Control, users with the Manage Teams role can modify or delete squads.
* In organizations with Owner-Based Access Control, only Squad Owners and Team Owners can modify or delete squads.
  {% endhint %}

### Create a Squad <a href="#create-a-squad" id="create-a-squad"></a>

{% hint style="info" %}
**Prerequisite:** [<mark style="color:blue;">Add Users</mark>](/manage-users/add-and-delete-users#add-users) to your Team before defining a Squad.
{% endhint %}

To create a Squad in a Team:

1. Navigate to **Settings** in the sidebar -> Click on **Teams** from the secondary navigation menu and select the **Team** that you want to create a Squad in.

<figure><img src="/files/dAGXyv1YEaSkngcFHncq" alt="How to create a squad in Squadcast"><figcaption></figcaption></figure>

3\. Click on **Squads** from the horizontal menu. -> Click on **Add Squad** to add a new Squad.

5\. Add a **Squad Name** and map the members of the Team. -> Click on **Save** to create and view the Squad

<figure><img src="/files/aewC6u2lcHLYkEDlzRcv" alt="" width="370"><figcaption></figcaption></figure>

### Edit or Delete a Squad <a href="#edit-or-delete-a-squad" id="edit-or-delete-a-squad"></a>

To edit or delete a squad,

1. Navigate to Settings -> Click on **Teams** from the secondary navigation menu and select the **Team** that you want to create a Squad in.

<figure><img src="/files/yfsMBf1JDN2tLAEI7B6a" alt="Create a squad from a team in Squadcast"><figcaption></figcaption></figure>

3\. Click on **Squads** from the horizontal menu -> To edit an existing Squad, click on <mark style="color:red;">`More Options`</mark> for that particular Squad.

5\. Choose **Edit** to modify the existing Squad or **Delete** to delete the Squad entirely.

<figure><img src="/files/ISbMYVWv1G1uvoHVLvFK" alt="Delete a squad from a team in Squadcast" width="375"><figcaption></figcaption></figure>

6\. After modifying/choosing to delete the Squad, either click on **Save** or confirm the deletion accordingly.

<figure><img src="/files/7fcpJHFFVDe8pwxC6zOi" alt="confirmation of deleting the squad in Squadcast" width="375"><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Stakeholder Groups

Create a smaller subset of stakeholders in a project to keep them looped in about specific incidents and issues.

Stakeholder Groups serve as distinct collectives of stakeholders within a Team, designated to receive notifications concerning incident progress. When tagged via @mentions in incident notes, these stakeholders also get added as incident watchers for real-time updates on the progress of incidents.

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark>

* Kindly note that the Stakeholder Groups cannot be integrated into Escalation Policies, on-call Schedules, or incident responder roles, maintaining consistency with existing stakeholder restrictions.
* They can be added as incident watchers by @ mentioning them in the incident notes.
  {% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>\
The number of Stakeholder Groups that can be created depends on the plan you have.

* With the Premium plan, you can create up to 10 Stakeholder Groups, each with a maximum of 10 members.
* Meanwhile, with the Enterprise plan, you can create up to 15 Stakeholder Groups, each with a maximum of 15 members.
  {% endhint %}

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* The User Role associated with the user in the Team must have required permissions to manage Teams.

### Create Stakeholder Group

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> Please note that stakeholders must first be added to the Team, with read-only roles assigned before proceeding with group creation.
{% endhint %}

To create Stakeholder Groups,

1. Go to Settings, then navigate to Teams. -> Choose the Team where you want to create the group.
2. Navigate to Stakeholder Groups in the top menu within the Team. -> Before adding a group, ensure there's at least one stakeholder in the Team.
3. Similar to adding a Squad, input the **Name and Stakeholders** you wish to include in the group.
4. Click Save to finalize.

Once created, you can now @ mention these groups in incident notes that will add as watchers to stay updated on incident resolution progress.

<div><figure><img src="/files/uAwsJDRB2NQ5j37IorVh" alt=""><figcaption></figcaption></figure> <figure><img src="/files/pvjsTrpHc3hwIMaFGWMV" alt=""><figcaption></figcaption></figure></div>

### Delete Stakeholder Group

To delete an existing Stakeholder Group,

1. Go to Settings, then navigate to Teams. -> Choose the team where you want to delete the group.
2. Navigate to Stakeholder Groups in the top menu within the team.
3. Against the group you want to delete, click on the three-dot menu. -> Click Delete and confirm deletion.

<div><figure><img src="/files/UsyydtE0Q8xgYydPoMBE" alt=""><figcaption></figcaption></figure> <figure><img src="/files/wlI1biFpUSdnUwfvMiCu" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark><mark style="color:blue;">:</mark> Please note when removing a stakeholder who is part of a group, you will be prompted about any existing conflicts. Before deletion, you will be required to substitute the stakeholder with another stakeholder.
{% endhint %}


# Adding a Service

Effortlessly add a new service and integrations for incident notifications - A step-by-step guide to creating and configuring a service for efficient incident management.

{% embed url="<https://www.youtube.com/watch?v=MdaMk_O_4jI>" %}

A Service is a core component of your infrastructure/application for which alerts are generated.

Services in Squadcast represent specific systems, applications, components, products, or teams for which an incident is created. To check out some of the best practices for creating Services in Squadcast, refer to the guide [<mark style="color:blue;">here</mark>](https://www.squadcast.com/blog/how-to-configure-services-in-squadcast-best-practices-to-reduce-mttr).

## Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* The User Role associated with the user in the Team must have required permissions to manage Services.
* You need to have at least one [<mark style="color:blue;">Escalation Policy</mark>](/escalation-policies/create-and-manage-escalation-policies) before you can add Services.
* The number of Services that can be added to an Organization is determined by the [<mark style="color:blue;">plan</mark>](https://squadcast.com/pricing) that your account is currently on.

## Creating a Service <a href="#creating-a-service" id="creating-a-service"></a>

1. Navigate to **Services** -> Click on **Add New Service**. On the next screen, you will be guided through two steps.

<figure><img src="/files/2wOrp2RwXinL9cYRzscy" alt="How to add a new service in Squadcast"><figcaption></figcaption></figure>

2\. **Define Service**: Enter the **Name** and **Description** based on the function that the service provides. Select an **existing Escalation Policy** and **Owner**. Enter **Tags**, and Click **Save and Continue**.

<div><figure><img src="/files/4hg8563DKXWtwV3c6gMD" alt="Define a new service in Squadcasst"><figcaption></figcaption></figure> <figure><img src="/files/5Ld4neaMP4OimMKN03rO" alt="define a new service in Squadcasst"><figcaption></figcaption></figure></div>

{% hint style="info" %}
**How to pick an Owner?**

Typically, an owner of a Service is well versed with the architecture, design and dependencies of the service. Assigning an owner helps others in the team know who they can reach out to should they need help with anything.
{% endhint %}

{% hint style="info" %}
**How to use Tags?**

Use tags to organize, classify and add context to your services. We recommend using tags like Type, Environment, Functionality and Priority to make them more context-rich.

Examples, Environment: PROD, Severity: Sev1, Type: Technical.
{% endhint %}

{% hint style="success" %}
Tips

* Give your services meaningful names that reflect the actual component name or functionality like - Login, Checkout, Payment API
* You can also assign a Squad as the owner of a service
* You can use tags to differentiate between business and technical services
  {% endhint %}

3\. **Add Alert Source**: Select the integration(s) you use to send alerts to this service from the search bar, dropdown, or from a list of our most popular integrations.

If you chose to add an integration to your service, you will now be in the service’s Integrations tab, where you’ll find the integration guide and an integration key. Follow the integration guide instructions to complete the configuration. Once you have completed the integration guide instructions, your service configuration is now complete.

4\. Click on **Done** to Create a **New Service**.

<figure><img src="/files/QpwsN8ebjl9yLJEB9kIr" alt="Configure an alert source to new service in Squadcast"><figcaption></figcaption></figure>

{% hint style="info" %}
**Note:** Ensure that the right Team is chosen from the team picker on the top of the screen (which is also visible as a display tag again on the top of the Create Service screen).
{% endhint %}

{% hint style="info" %}
**Note**: You can create and manage a service using our latest Terraform provider (1.0.4). To view our Terraform documentation, click [here](https://registry.terraform.io/providers/SquadcastHub/squadcast/latest/docs).
{% endhint %}

## **Edit Service Setting**

To edit an existing service’s settings:

1. Navigate to **Services** -> **Service Overview** -> select or search for your desired service.
2. Click on the service to navigate to the **Service Details** page.
3. In the top right, click **More** -> **Edit Service.**
4. Once you have edited your preferred settings, click **Save Changes**.

<div><figure><img src="/files/zLE7sqs2iMQch5cbmkgT" alt="Edit service settings in Squadcast"><figcaption></figcaption></figure> <figure><img src="/files/i4ioM8SsvmhDbdwJvaRt" alt="edit service settings in Squadcast"><figcaption></figcaption></figure></div>

## **Edit a Service’s Escalation Policy**

To edit a service’s escalation policy:

1. Navigate to **Services** -> **Service Overview** -> select or search your desired service.
2. Click on the service to navigate to the **Service Details** page.
3. In the top right, click **More** -> **Edit Service**.
4. Under the escalation policy drop-down, search and select an **escalation policy**.
5. Click **Save Changes.**

<div><figure><img src="/files/hpIdRRFyejZoVo7Vtoj5" alt="Edit service settings in Squadcast"><figcaption></figcaption></figure> <figure><img src="/files/nESypiV3s9fnCeSTlcEg" alt="how to edit Service’s Escalation Policy"><figcaption></figcaption></figure></div>

## **Delete Service**

To delete an existing service:

1. Navigate to **Services** -> **Service Overview** -> select or search for your desired service.
2. Click on the service to navigate to the **Service Details** page.
3. In the top right, select **More** -> **Delete Service.**
4. You will receive a prompt, click on **Yes, Delete Services.**

It will delete your Service.

<div><figure><img src="/files/sR3QdAXsgYFnEImB6F2W" alt="How to delete a service in Squadcast"><figcaption></figcaption></figure> <figure><img src="/files/BiC9JmKEWjVEGcDgDVMF" alt="how to delete service in Squadcast"><figcaption></figcaption></figure></div>

{% hint style="warning" %}
If your Service has any open (triggered/ acknowledged) incidents, the system will not allow service deletion until those incidents are resolved. Click on **Show Open Incidents** to resolve and follow the same steps stated above to delete the service.

To resolve multiple incidents in one shot, check out the [<mark style="color:blue;">Take Bulk Actions</mark>](/dashboards/take-bulk-actions) documentation
{% endhint %}

## **Add Integrations to an Existing Service**

{% hint style="info" %}
You can add more than one integration on a service, which allows you to represent the actual entities you are monitoring, managing, and operating as services. The list of supported alert source integrations is available [<mark style="color:blue;">here</mark>](https://www.squadcast.com/integrations)<mark style="color:blue;">.</mark>
{% endhint %}

To add an Alert Source Integration to your service:

1. Navigate to **Services** -> **Service Overview** -> select or search for your desired service.
2. In the extreme right, expand the accordion -> In the Alert Sources section, **Add Alert Source**.
3. Select the **integration(s)** you use to send alerts to this service from the search bar, dropdown, or from our most popular integrations list.
4. Click **Add Alert Source**.
5. Now your alert source is added, copy the **Webhook URL**.
6. Follow the Integration Guide to complete configuring the desired alert source.

<div><figure><img src="/files/4AYLTBginpTSWtny77FW" alt="How to add an alert source integration to your Service in Squadcast"><figcaption></figcaption></figure> <figure><img src="/files/u6h9BDWqVwAdHuwQSMmf" alt="how to add an alert source integration to your Squadcast service"><figcaption></figcaption></figure></div>

{% hint style="info" %}
**How to send alerts from a source I don’t see here?**

In cases where you want to send custom alerts that don’t come from any tools listed here, you can use our Incident Webhook or our Email integrations.
{% endhint %}

{% hint style="success" %}
**Tips:**

* Incident auto-resolution is enabled by default provided the alert source supports it.
* Email as an alert source does not support incident auto-resolution.
* Reduce alert noise at the source end by sending in just actionable alerts that you want your on-call team to work on.
* When not possible at the source end, use automation rules to group, suppress, tag, and route incidents intelligently.
  {% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Service Overview

Use Service Overview to drill into relevant information and perform actions on services

The Service Overview is a searchable, high-level aggregate view of all Squadcast services in your team, and their corresponding owners. From the Service Overview, you can dive into each individual service to learn more about it, make changes to the settings, and take further action.

## **Navigate to the Service Overview**

Navigate to the **Service** -> **Service Overview**.

The Service Overview provides the following information about services:

| Component                 | Description                                                                                                                                                                                                                                                                                                           |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Alert Source              | Alert Source Integrations configured with the service.                                                                                                                                                                                                                                                                |
| Extension                 | Extensions added to your service, like Slack Channel.                                                                                                                                                                                                                                                                 |
| Owner & Escalation Policy | <p>Mentions the owner and escalation policy attached to the service.</p><p><mark style="color:blue;"><strong>Note</strong>:</mark> You can also assign a Squad as the owner of a service.</p>                                                                                                                         |
| Open Incidents            | The current number of triggered and acknowledged incidents on the service.                                                                                                                                                                                                                                            |
| MTTA                      | Mentions MTTA metric of the service.                                                                                                                                                                                                                                                                                  |
| MTTR                      | Mentions MTTR metric of the service.                                                                                                                                                                                                                                                                                  |
| Status                    | <p><mark style="color:green;"><strong>Healthy</strong></mark>: when the service has no open incidents.</p><p><mark style="color:yellow;"><strong>Needs Attention</strong></mark>: when the service has 1 or more open incidents.</p><p><strong>Under Maintenance</strong>: when the service is under maintenance.</p> |
| Recent Incidents          | Mentions list view of the most recent incidents that came in for the service, click on View All for more.                                                                                                                                                                                                             |
| Automation                | Weekly stats on Automation Rules like Deduplication Rule, Suppression Rule, Routing Rule and Tagging Rule.                                                                                                                                                                                                            |
| Alert Sources             | Open Incidents of all the Integrated Alert Sources.                                                                                                                                                                                                                                                                   |
| Maintenance Mode          | Mentions the schedules for upcoming maintenance windows.                                                                                                                                                                                                                                                              |
| View Dependency           | Used to view, edit and add Service Dependencies.                                                                                                                                                                                                                                                                      |
| Tags                      | Used to add tags like Type, Environment and Functionality to add more context to your services.                                                                                                                                                                                                                       |

## **Search**

With the **Service Overview** open, you can search for a service by name or description or tags. By default, the results are ordered by highest relevance to lowest.

## **Sort by**

Refine your results by combining search queries, and sorting. You can sort by using the following:

1. Service Name
2. MTTA
3. MTTR
4. Status

## Maintenance Windows

You can review and manage Maintenance Windows in the Search Overview, by viewing the Maintenance Window tab under each service. To learn more, read Maintenance Windows.

## **Update Service Tags**

You can attach Tags to Services to make your service context-rich, and classifiable. Some examples are, severity:high, service: customer-support, so on.

To add tags to services:

1. Navigate to **Services** -> **Service Overview** -> select or search for your desired service.
2. On hovering over the service, click **Add Tag(s)**.
3. Enter the key and value pairs and click **Add Tags(s)**.

<div><figure><img src="https://github.com/solarwinds-cloud/sq-Gitbook/blob/main/.gitbook/assets/21spaces%2F8TaWz01jmUJl58p4ZVel%2Fuploads%2Fgit-blob-6354d1f6cf0b0e6d123bc707d6c0246e02b1caa8%2Fservice_catalog_add_tags_1%20(1).png" alt="How to update service tags in Squadcast"><figcaption></figcaption></figure> <figure><img src="https://github.com/solarwinds-cloud/sq-Gitbook/blob/main/.gitbook/assets/21spaces%2F8TaWz01jmUJl58p4ZVel%2Fuploads%2Fgit-blob-87771ddf9efc36b3e16d169fbda3dddd6814a7b9%2Fservice_catalogue_add_tags_2.png" alt="Adding and updating a service in Squadcast"><figcaption></figcaption></figure></div>

## **Service Dependency**

Service dependencies can be used to define other technical or business services that your service uses, or those that are used by your service. If an issue arises on your service for one of the dependencies you have configured, you can use the Service Dependencies tab to quickly assess the scope of the impact.

Defining dependencies between Services also helps Squadcast understand the relationship between your actual systems.

### **Add and Delete Service Dependency**

To add service dependencies:

1. Navigate to **Services** -> **Service Overview** -> select or search for your desired service.
2. Expand the accordion -> **View Dependency** -> you are navigated to a list of dependent services
3. Click **Add Dependency** -> enter the name of the dependent service
4. Click **Save**

<div><figure><img src="https://github.com/solarwinds-cloud/sq-Gitbook/blob/main/.gitbook/assets/21spaces%2F8TaWz01jmUJl58p4ZVel%2Fuploads%2Fgit-blob-7447ce928bf0405ac0c27219a37862e8d294be3f%2Fservice_dependency_111%20(1)%20(1).png" alt="How to add and delete a service dependency in Squadcast"><figcaption></figcaption></figure> <figure><img src="https://github.com/solarwinds-cloud/sq-Gitbook/blob/main/.gitbook/assets/21spaces%2F8TaWz01jmUJl58p4ZVel%2Fuploads%2Fgit-blob-54c8e74627e0924e30ba0ce1d07d7494012cd522%2Fservice_dependency_2%20(1).png" alt="Save Service Dependency in Squadcast"><figcaption></figcaption></figure></div>

To delete a service dependency:

1. Click the **Cross** next to the service name to delete the service dependency
2. Click **Save**

<div><figure><img src="https://github.com/solarwinds-cloud/sq-Gitbook/blob/main/.gitbook/assets/21spaces%2F8TaWz01jmUJl58p4ZVel%2Fuploads%2Fgit-blob-7447ce928bf0405ac0c27219a37862e8d294be3f%2Fservice_dependency_111%20(1)%20(2).png" alt="How to delete a service dependency in Squadcast"><figcaption></figcaption></figure> <figure><img src="https://github.com/solarwinds-cloud/sq-Gitbook/blob/main/.gitbook/assets/21spaces%2F8TaWz01jmUJl58p4ZVel%2Fuploads%2Fgit-blob-3d79a599a18e48c3b19e351f812f14668489f095%2Fservice_dependency_3.png" alt="Delete a service dependency in Squadcast"><figcaption></figcaption></figure></div>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Service Graph

Visualize and manage all your service dependencies with the Service Graph.

The Service Graph in Squadcast is an interactive map showcasing the dependencies among your services. This visual representation provides a quick overview of service health and interconnections.

During incident response, leverage the Service Graph to understand the full impact of an issue, identify the probable cause, and enhance cross-team collaboration.

<figure><img src="/files/ieOkNTOByEUvToKg5p7c" alt="" width="563"><figcaption><p>Image. Service Graph</p></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> This feature will be available in the [<mark style="color:blue;">Premium and Enterprise plans only</mark>](https://www.squadcast.com/pricing).
{% endhint %}

## View Service Graph

To view the service graph, Navigate to **Services** -> **Graph**.

The graph only displays services that have one or more [<mark style="color:blue;">dependency relationships</mark>](/services/service-overview#service-dependency). Any services that do not yet have dependency relationships will be listed in the right panel under Independent Services. You can click on the services to view more details about them.

<div><figure><img src="/files/CjLOCauhpdDkivgRxCAA" alt="" width="563"><figcaption><p>Image. Access Service Graph</p></figcaption></figure> <figure><img src="/files/lE0eXMU1Z78IP2sefGJx" alt="" width="563"><figcaption><p>Image. Access details of the selected Service.</p></figcaption></figure></div>

## Service Graph Actions

This graph is auto-generated by Squadcast based on the service dependencies you create.

* Users can zoom in and out, fit to the screen to view the graph.
* User can interact with the elements of the graph by dragging the components to better visualize it as per their needs and they can further lock this created view.
* Users can select to view the right panel for the displayed services.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> Any interaction done on this graph is retained for the current session only. If you navigate to a different page or close the application, the service nodes move to the default graph position.
{% endhint %}

### Filters

To focus on services with a specific status, users can leverage the filters on the bottom menu. Clicking on a status will highlight all the services in that state.

<figure><img src="/files/0ytXhBdGhpV9MUESC34I" alt="" width="563"><figcaption><p>Image. Status Filters for the Service Graph</p></figcaption></figure>

## **Right Panel**

To open the right panel, click on the **<** icon located on the right side of the page. This panel provides a comprehensive list of both dependent and independent services. Selecting any service from the list will reveal additional information about that particular service.

<div><figure><img src="/files/SxSqHGn5RcnhqOrpX1qa" alt="" width="563"><figcaption><p>Image. Access Right Panel</p></figcaption></figure> <figure><img src="/files/nvc9tEbLAWguE7LQEazB" alt="" width="563"><figcaption><p>Image. View Service details on the right panel</p></figcaption></figure></div>

The information displayed in the right panel includes:

| Field                           | Description                                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Service Name**                | Name of the Service.                                                                                                                                                                                                                                                                                                                                                                                   |
| **Status**                      | <ul><li><mark style="color:green;"><strong>Healthy</strong></mark> - Denotes operational services, i.e., services with no open incidents.</li><li><mark style="color:yellow;"><strong>Needs Attention</strong></mark> - Denotes impacted services, i.e., services with one or more open incidents.</li><li><strong>Under Maintenance</strong> - Denotes services that are under maintenance.</li></ul> |
| **Owner**                       | Shows the user or squad that is the owner of the service.                                                                                                                                                                                                                                                                                                                                              |
| **Escalation Policy**           | Shows the escalation policy attached to the service.                                                                                                                                                                                                                                                                                                                                                   |
| **Recent Incidents**            | Shows up to three most recent incidents that have come in for the service. To view all open incidents for the affected service, you can use the navigation under the list.                                                                                                                                                                                                                             |
| **Manage Service Dependencies** | A navigation link to manage dependencies on the service detail page.                                                                                                                                                                                                                                                                                                                                   |

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Maintenance Mode

Create Maintenance Mode windows for Services

{% embed url="<https://www.youtube.com/watch?v=mHl5esGmdJ0>" %}

Maintenance Mode enables you to reduce alert noise during the scheduled maintenance window. Alerts generated during active maintenance windows would be automatically suppressed and hence, no notifications are generated for those suppressed alerts. One can quickly list incidents that are in the suppressed state by simply filtering them in the [<mark style="color:blue;">Incidents</mark>](/incident-list/incident-list-view#quick-filter-by-incident-status) page.

## Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* The User Role associated with the user in the Team must have required permissions to manage Services (ability to manage Maintenance Windows).

## **Set up a Maintenance Window**

To set up a maintenance window for a service:

1. Navigate to **Services** -> **Service Overview** -> select a service you’d like to schedule a maintenance for.
2. On hovering over the service, click **Maintenance Mode** -> **Enable maintenance mode for service**.
3. Select a **Start Date** and **Time**, along with **End Date** and **Time**.
4. If you want to set repetition, select the frequency of repetition, and the **End Date**.
5. Add as many maintenance windows as you’d like and click **Save**.

<div><figure><img src="/files/4tVOl0hdb2VCo5dX93yD" alt="Set up maintenance mode in Squadcast"><figcaption></figcaption></figure> <figure><img src="/files/DQNh9UunhsHfwngvFNdU" alt="Set up a maintenance window"><figcaption></figcaption></figure></div>

## FAQs <a href="#faqs" id="faqs"></a>

1\. Where can I see all the suppressed incidents?

Suppressed incidents can be viewed on the **Dashboard** by clicking on the <mark style="color:red;">`Suppressed`</mark> tab as shown below:

<figure><img src="/files/78rs0hs5SIbhcVzONJZg" alt="View suppressed incidents in Squadcast dashboard"><figcaption></figcaption></figure>

On the **Incidents** page, suppressed incidents can be viewed under the <mark style="color:red;">`Suppressed`</mark> state as shown below:

<figure><img src="/files/Fgq68j1qe5lKXTyzyDwO" alt="View suppressed incidents in Squadcast"><figcaption></figcaption></figure>

2\. How do I know if an incident is suppressed due to scheduled maintenance and not due to any other Suppression Rule?

In the Incident’s Activity Timeline the reason for suppression is displayed, in this case, it will be <mark style="color:red;">`auto suppressed due to scheduled maintenance`</mark>.

<figure><img src="/files/IUXCSZzXG6vLlZFRd4no" alt="Suppression notification in the activity timeline in Squadcast"><figcaption></figcaption></figure>

3\. Is a maintenance window global to the associated Service?

Yes, it is global to the associated Service.

4\. Can I change the state of a suppressed incident?

No, <mark style="color:red;">`suppressed`</mark> would be the final state of an incident. It cannot be changed.

5\. I am able to view Services for my Team but am unable to add a maintenance window to it. What am I missing?

The User Role associated with your user in the Team must have required permissions (such as <mark style="color:red;">`Update`</mark>) to manage/edit Services.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Alert Deduplication Rules


# Alert Deduplication Rules

Reduce alert noise by grouping similar alerts together

{% embed url="<https://www.youtube.com/watch?v=wG5571TiScc>" %}

Alert Deduplication can help you reduce alert noise by organizing and grouping alerts. This also provides easy access to similar alerts when needed.

This can be achieved by defining Deduplication Rules for each Service in Squadcast. When these rules evaluate *true* for an incoming incident, alerts will get deduplicated.

## Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* The User Role associated with the user in the Team must have required permissions to manage Services (ability to manage Deduplication Rules).
* Integrate with an Alert Source and ensure that the Alert Source has started sending alerts to Squadcast before setting up Deduplication Rules.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> The Key-Based Deduplication (Dedupe Keys) feature is available across all subscription plans.

Regarding Deduplication Rules Feature:

**For Existing Accounts:**

* No changes will be applied, and the current settings will remain in effect.

**For New Sign-ups (Post Deduplication Keys Release - Aug 21, 2023):**

* Deduplication Rules will only be accessible for enterprise accounts. Other subscription plans will not have access to Deduplication Rules.

\
This clarification aims to ensure a better understanding of the deduplication framework and its application across different account scenarios.
{% endhint %}

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark>

* Deduplication Rules work only on incidents in either the **Triggered** or **Acknowledged** states.
* Automation rule CRUD operations have a 5-minute caching delay before changes take effect.
  {% endhint %}

## **Create a Deduplication Rule**

To create a Deduplication Rule:

1. Navigate to **Services** -> **Service Overview** -> select or search for your desired service.
2. In the extreme right, expand the accordion -> In **Automation** section, **View All**
3. In the **Automation Rules** section, **Add Deduplication Rules**
4. Select an **Alert Source** from the drop down -> **Add New Rule**
5. Deduplication Rules can be added in two ways:

### A. UI-based Rule Builder (Beginner-friendly) <a href="#a-ui-based-rule-builder-beginner-friendly" id="a-ui-based-rule-builder-beginner-friendly"></a>

1. On the right, you can view the *payload of the **latest** alert* for the chosen Alert Source
2. The drop-downs in the Rule Builder contain values from the payload on the right. You can use them to easily create your Deduplication Rules

You can create Deduplication Rules using the following conditions:

| Operators        | Condition                                                        |
| ---------------- | ---------------------------------------------------------------- |
| ==               | if the payload value is equal to the given value                 |
| !=               | if the payload value is not equal to the given value             |
| matches/contains | if the payload value matches (***or** contains*) the given value |
| does not contain | if the payload value does not contain the given value            |

{% hint style="warning" %}
**Note**: All these operators are case-sensitive.\
\
If you want to make the rules *case insensitive*, then you have to do it with the regular expression method.
{% endhint %}

<figure><img src="/files/ztiJhb3yuqc8CUZxAwYu" alt="Alert Deduplication based on time in Squadcast"><figcaption></figcaption></figure>

3\. You can add more than 1 condition for a rule by selecting **Add Condition** (a logical AND is performed between all the conditions -> the entire Deduplication Rule will evaluate to <mark style="color:red;">`True`</mark> only if all the conditions evaluate to <mark style="color:red;">`True`</mark>)

Next, choose the **Deduplication Time Window**. You can deduplicate incidents for a **maximum of 48 hours**.

{% hint style="info" %}
**Time Window**

During the set time window, incidents that occur are compared against all incidents that come in during that time period, and will then get deduplicated against the first incident that it matches with.
{% endhint %}

4\. Click on **Save**

<figure><img src="/files/fvsAOoAY0qd9P3twGqeR" alt="Add alert deduplication based on time in Squadcast"><figcaption></figcaption></figure>

{% hint style="info" %}
**Note**:

The search option under payload is not a free search, we have to search by JSON format, for example, type in payload.annotations to get annotations.

\
We also have an option for click-to search, wherein you can click on the keys in the payload to get their required values.
{% endhint %}

### B. Raw String Method <a href="#b-raw-string-method" id="b-raw-string-method"></a>

{% hint style="warning" %}
**Important**

Once you opt for the **Raw String method**, you cannot revert to the **UI-based Rule Builder** method for that rule.
{% endhint %}

1. On the right, you can view the payload of the latest alert for the chosen Alert Source
2. Click on **Edit** to enable the Raw String method

<figure><img src="/files/avQvLZatfSum4LJty6B7" alt="deduplication rule in Squadcast using raw string method"><figcaption></figcaption></figure>

3\. Write your custom Deduplication Rule expression. Below are some examples to help you get started:

{% hint style="info" %}
**How to make rules&#x20;*****case-insensitive*****?**\\

1. Click **Edit** -> **Proceed**
2. You will see the rule in the regular expression. Now you need to add the command lc (lower\_case) before the individual parameters

**Here is an example**:

`re(payload["subscription"]["type"], "Subscription")`

The rule says if the payload\["subscription"]\["type"]contains the string "Subscription" in it then do some actions.

If you want to make the above rule case insensitive, you have to add the command lc before the individual parameters.

The case insensitive rule would look like this,

`re(lc(payload["subscription"]["type"]), lc("Subscription")) or`

`re(lc(payload["subscription"]["type"]), "subscription")`
{% endhint %}

#### **Supported Rules**

The rule engine supports expressions with parameters, arithmetic, logical, and string operations.

#### **Basic Expressions**

$$
10 > 0, 1+2, 100/3
$$

#### **Parameterized Expressions**

$$
past.metric == current.metric
$$

The available parameters are <mark style="color:red;">`past`</mark>, <mark style="color:red;">`current`</mark> and <mark style="color:red;">`event_count`</mark> + <mark style="color:red;">`past`</mark>: This parameter contains the JSON payload of the previous incident which the current event is compared with + <mark style="color:red;">`current`</mark>: This parameter contains the JSON payload of the incoming event which will be compared with the past incidents’ JSON payload + <mark style="color:red;">`event_count`</mark>: This denotes the number of deduplicated events for a given incident

{% hint style="info" %}
**Use-case for event\_count:**

This can be used in scenarios where you do not want to deduplicate more than <mark style="color:red;">`n`</mark> number of alerts to a particular incident.
{% endhint %}

#### **Regular Expressions**

This can be used to check if a particular JSON payload field matches a regular expression.

$$
re(payload.metric, "disk.\*")
$$

#### **Parse JSON content within the payload using `jsonPath`**

#### **General Format**

<mark style="color:red;">`jsonPath(<the JSON string that should be parsed for JSON content>, <"the parameter that needs to be picked from the parsed JSON object">)`</mark>

**Example**

Below is an example payload:

```
{
	"payload": {
		"Type": "Notification",
		"MessageId": "5966c484-5b37-58df",
		"TopicArn": "arn:aws:sns:us-east-1:51:Test",
		"Message": "{\"AlarmName\":\"Squadcast Testing - Ignore\",\"AlarmDescription\":\"Created from EC2 Console\"}"
	}
}
```

```
jsonPath(payload.Message, "AlarmName");
```

This will pick out the value <mark style="color:red;">`AlarmName`</mark> from the Message object in the payload, based on which, you can de-duplicate incidents.

{% hint style="info" %}
**Multiple Alert Sources**

We can see alert payloads of past events from different alert sources for the Service by selecting the respective alert source from the dropdown in the right-half side.

\
Since the payload format is fixed for a given alert source, it is usually preferable to have Deduplication Rules on a per-alert source basis. This can be done by making use of the <mark style="color:red;">`source`</mark> field which lets you know the alert source that triggered the incoming event.\
\
For example, if you want to have a Deduplication Rule for a Service, only for alerts coming for <mark style="color:red;">`grafana`</mark> alert source, then the corresponding rule would look something like: <mark style="color:red;">`source == 'grafana' && (<your_deduplication_rule>)`</mark>
{% endhint %}

**Example**

Below is an example payload for demonstration:

```
{
	"event_count": 5,
	"past": {
		"issue_description": "bug - 2",
		"issue_id": "10029",
		"issue_key": "HYD-30",
		"issue_labels": [],
		"issue_link": "http://13.233.254.18:8080/browse/HYD/issues/HYD-30",
		"issue_priority": "Medium",
		"issue_summary": "bug - 2",
		"issue_type": "Bug",
		"project_id": "10000",
		"project_key": "HYD",
		"project_name": "hydra"
	},
	"source": "grafana"
}
```

To deduplicate any incoming alert when:

* The <mark style="color:red;">`metric`</mark> matches the regular expression <mark style="color:red;">`^disk.*`</mark>
* The <mark style="color:red;">`past`</mark> incident <mark style="color:red;">`metric`</mark> and the <mark style="color:red;">`current`</mark> event <mark style="color:red;">`metric`</mark> are the same
* The <mark style="color:red;">`past`</mark> incident <mark style="color:red;">`host`</mark> and the <mark style="color:red;">`current`</mark> event <mark style="color:red;">`host`</mark> are the same
* The <mark style="color:red;">`current`</mark> disk usage <mark style="color:red;">`value`</mark> is less than 60%
* The <mark style="color:red;">`context`</mark> value tag is same

#### **Deduplication Rule:**

```
past.metric == current.metric &&
	re(current.metric, "^disk.*") &&
	past.host == current.host &&
	current.value < 60 &&
	jsonPath(past.tags, "context.value") ==
		jsonPath(current.tags, "context.value");
```

## Viewing Deduplicated Incidents <a href="#viewing-deduplicated-incidents" id="viewing-deduplicated-incidents"></a>

From the [<mark style="color:blue;">Incidents</mark>](/incident-list/incident-list-view) page, you can view which incidents have deduplicated events when there is a **+\<number>** next to the Incident ID like in the screenshot below.

The **number** indicates how many alerts were deduplicated against this incident.

<figure><img src="/files/LfKbGClBFnclt6HvHfjY" alt="Viewing deduplicated incidents in Squadcast"><figcaption></figcaption></figure>

Clicking on such an incident will take you to its [<mark style="color:blue;">Incident Details</mark>](/incidents-page/incidents-details) page where, by clicking on **Deduped Events**, you will be able to see the following:

* Number of deduplicated events
* Time when they reached Squadcast
* **Message** and **Payload** of the event

<figure><img src="/files/hWa164CkUVh0ASZdsFua" alt="deduplicated events in Squadcast"><figcaption></figcaption></figure>

Clicking on any of the deduplicated events will display will all the information that is sent for that alert from the monitoring tool, including the **Deduplication Reason** (which Deduplication Rule got executed).

![deduplication reason in Squadcast](/files/DBsxVPnO6Y9FibxglBpq)

## FAQs <a href="#faqs" id="faqs"></a>

1\. Will I get notified of the duplicate alerts that come in for an incident in a Triggered state?

No, nobody is notified of the duplicate alerts that come in for an incident in the <mark style="color:red;">`Triggered`</mark> or <mark style="color:red;">`Acknowledged`</mark> state.

2\. Will I get notified of the duplicate alerts that come in for an incident in the Resolved state?

Yes, Incident Deduplication will not take place for an incident when it is in the <mark style="color:red;">`Resolved`</mark> state. Squadcast triggers a fresh incident for such an alert and notifies the right people.

3\. Why can’t I deduplicate incidents for more than 48 hours?

Most organizations across the world follow the best practice of resolving critical incidents within 48 hours of their creation. This is also the reason why Squadcast allows you to deduplicate incidents for a maximum of 48 hours.

4\. Can I create OR rules?

Yes, you can. The evaluation between different Deduplication Rules is <mark style="color:red;">`OR`</mark>.

5\. What kind of regex can be used to write custom rules?

The rule engine supports expressions with parameters, arithmetic, logical, and string operations. You can also check [<mark style="color:blue;">this</mark>](https://regex101.com/) out to get an idea of all the expression types accepted in Squadcast. Please do your regex [<mark style="color:blue;">here</mark>](https://regex101.com/) against <mark style="color:red;">`Golang`</mark> flavor as shown in the screenshot below and then, set them up in Squadcast:

![Regex used to write custom rules in Squadcast](/files/z0Rt2yQUxRs6wpvmlLLa)

6\. Do the Deduplication Rules have priority?

Yes, you can specify Execution Rule Priority for the rules defined by moving them <mark style="color:red;">`Up`</mark> or <mark style="color:red;">`Down`</mark> the list of rules.

7\. While adding a Deduplication Rule, is the *search string* in the rule case sensitive?

Yes, that is correct. For example, if your search string is “ALERT” and your payload does not contain “ALERT” but contains “Alert”, this will not be matched. Your search string should be “Alert”.

8\. I have configured multiple rules for a particular Service. Can I search through the configured rules to find the rule I am looking for?

Yes, that is doable. You will notice a **Search** option on the left-top of the rules modal. You can type in a word you recall from the rule description or the rule itself. Any matching results will yield the narrowed-down set of rules.

<figure><img src="/files/lWxXp8JZNn2BWaTEmu05" alt="Search rules configured in Squadcast"><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Incident Status Based Deduplication

Use Incident Status Based Deduplication to deduplicate all alerts to an existing open incident for a Service

Incident Status Based Deduplication works on the logic that all alerts that come in for a Service are related to the same issue. So, if there is an open incident for a Service - that is, the incident is in the <mark style="color:red;">`Triggered`</mark> or <mark style="color:red;">`Acknowledged`</mark> state, **all** incidents that come in for this Service will get deduplicated against the existing, open incident within the specified time window.

## Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* The User Role associated with the user in the Team must have required permissions to manage Services (ability to manage Deduplication Rules).

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark>\
Automation rule CRUD operations have a 5-minute caching delay before changes take effect.
{% endhint %}

## Enabling the Incident Status-Based Deduplication <a href="#enabling-the-incident-status-based-deduplication" id="enabling-the-incident-status-based-deduplication"></a>

1. Navigate to **Services** -> **Service Overview** -> select or search for your desired service.
2. On the extreme right, expand the accordion -> In the **Automation** section, **View All**
3. In the **Automation Rules** section, **Add Deduplication Rules**
4. Select an **Alert Source** from the drop-down -> **Add New Rule**
5. Incident Status Based Deduplication Rules can be added in two ways:

### (a) **UI-based Rule Builder (Beginner-friendly)**

1. Create a rule specifying the **Label** as <mark style="color:red;">`past_incident["is_suppressed"]`</mark>, **Condition** as <mark style="color:red;">`==`</mark> and **Value** as <mark style="color:red;">`False`</mark>.
2. Add an appropriate deduplication time window.
3. Click on **Save Rule** to complete.

<figure><img src="/files/DwjZlcmnE1TLuXEIDMqV" alt="Incident status based deduplication in Squadcast"><figcaption></figcaption></figure>

{% hint style="info" %}
The key of the Tag label, "tag key" can only contain letters (both lowercase and uppercase) and numbers. Anything else will be ignored.
{% endhint %}

{% hint style="info" %}
The maximum time allowed for deduplication is **48 hours**.
{% endhint %}

{% hint style="info" %}
**Note**: The search option under payload is not a free search, we have to search by JSON format, for example, type in payload.annotations to get annotations.

\
We also have an option for click-to search, wherein you can click on the keys in the payload to get their required values.
{% endhint %}

### (b) **Raw String Method**

{% hint style="info" %}
Once you opt for the Raw String method for a rule, you cannot revert to the UI-based Rule Builder method.
{% endhint %}

1. You can copy and paste the rule below and change the Rule Execution Priority accordingly.

![Add Incident status based deduplication in Squadcast](/files/mcm0DijPGPdMojTrLJzJ)

2\. Add an appropriate deduplication time window.

3\. Click on **Save Rule** to complete.

{% hint style="info" %}
The maximum time allowed for deduplication is **48 hours**.
{% endhint %}

<figure><img src="/files/LRufYvYn7s3JoqXmDwME" alt="Create condition for incident status based deduplication"><figcaption></figcaption></figure>

## FAQs <a href="#faqs" id="faqs"></a>

1\. I have added the Deduplication Rule <mark style="color:red;">`past_incident.is_suppressed == false`</mark> manually to an existing Service to deduplicate all alerts against any open incident for the Service. Nevertheless, I do not see Incident Status Based Deduplication taking place as expected. What am I missing?

Once the Deduplication Rule <mark style="color:red;">`past_incident.is_suppressed == false`</mark> is added manually to an existing Service, please move the rule <mark style="color:red;">`up`</mark> or <mark style="color:red;">`down`</mark> based on the Rule Execution Priority you wish to have. If you do not want any of your other Deduplication Rules to be executed for the Service, move the newly added Deduplication Rule to the top of the list of rules.

<figure><img src="/files/Ev5hrcr1DskUeAHfRFEp" alt="Change rule execution priority"><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Service Dependency Based Deduplication

Deduplicate incoming alerts for a Service against the latest open incident of its dependent Service(s)

Service Dependency Based Deduplication works on the logic that the incidents coming in for a Service and its dependencies have a related cause.

It is most likely the case where, when one Service has an incident, it's dependent Service(s) may also have incidents and hence, you will be notified of the incident only once. *This helps control unnecessary alert noise and notification fatigue during critical outages*.

Defining dependencies between Services also helps Squadcast understand the relationship between your actual systems.

To understand this better, let us consider 3 Services: *Service A*, *Service B* and *Service C*.

If *Service A* is <mark style="color:red;">`dependent on`</mark> *Service B* and *Service C*, then:

* **Dependent Service**: *Service A*
* **Dependency Service(s)**: *Service B*, *Service C*

Let’s say, *Service B* has an open incident at *time x* and *Service C* has an open incident at *time x+1*. Now, *Service A* receives an incident. This incident for *Service A* gets deduplicated with the **latest** open incident of its dependency Service(s) - i.e., with the open incident for *Service C*, in this case.

## Prerequisites <a href="#prerequisites" id="prerequisites"></a>

The User Role associated with the user in the Team must have required permissions to manage Services (ability to manage Deduplication Rules).

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark>\
Automation rule CRUD operations have a 5-minute caching delay before changes take effect.
{% endhint %}

## Add a Service Dependency <a href="#adding-a-service-dependency" id="adding-a-service-dependency"></a>

To add service dependencies:

1. Navigate to **Services** -> **Service Overview** -> select or search for your desired service.
2. On the extreme right, expand the accordion -> **View Dependency** -> you are navigated to a list of dependent services.
3. Click **Add Dependency** -> enter the name of the dependent service.
4. Click **Save**

> In this example, we have considered <mark style="color:red;">`Backend Prometheus Service`</mark> and <mark style="color:red;">`Translations`</mark> Services as dependencies of the <mark style="color:red;">`Payment Portal`</mark> Service.
>
> <img src="/files/Xpven9gmd60QyxiJhz9J" alt="Service dependencies in Squadcast" data-size="original">
>
> This means that the <mark style="color:red;">`Payment Portal`</mark> Service is dependent on <mark style="color:red;">`Backend Prometheus`</mark> <mark style="color:red;">`Service`</mark> and <mark style="color:red;">`Translations`</mark>.

## **Delete a Service Dependency**

To delete a service dependency:

1. Click the **Cross** next to the service name to delete the service dependency
2. Click **Save**

## Enabling Service Dependency-Based Deduplication <a href="#enabling-service-dependency-based-deduplication" id="enabling-service-dependency-based-deduplication"></a>

Once you have defined the Service Dependencies, you can set a Service Dependency Based Deduplication rule which would deduplicate all incoming alerts for the chosen Service against the latest open incident of its Service Dependencies.

1. Navigate to **Services** -> **Service Overview** -> select or search for your desired service.
2. On the extreme right, expand the accordion -> In the Automation section, **View All.**
3. In the Automation Rules section, **Add Deduplication Rules.**
4. Check **If this service and service depends on both have an incident, alert only once** -> Click **Save.**

{% hint style="info" %}
**Note:** This checkbox for every Deduplication Rule is disabled by default.
{% endhint %}

<figure><img src="/files/y5JdQgde38Tb4DzF4LVi" alt="Add Service dependency based deduplication rules in Squadcast"><figcaption></figcaption></figure>

{% hint style="info" %}
**Note:**

1. The Service Dependency Based Deduplication will deduplicate any incoming alert against either a <mark style="color:red;">`Triggered`</mark> or <mark style="color:red;">`Acknowledged`</mark> incident only.
2. Service Dependency-based Deduplication is rule-specific and can be enabled for any number of Deduplication Rules that are defined for a Service.
   {% endhint %}

## Enabling Service Dependency-Based Deduplication for a Specific Service Dependency <a href="#enabling-service-dependency-based-deduplication-for-a-specific-service-dependency" id="enabling-service-dependency-based-deduplication-for-a-specific-service-dependency"></a>

In cases where you would like Squadcast to consider just one of the many dependencies for a Service for Service Dependency Based Deduplication, you can follow the method below.

Along with enabling the Service Dependency checkbox, as shown above, you will need to add the below condition to the rule:

<mark style="color:red;">`past_incident.service == <slug_of_the_particular_dependency_service>`</mark>

## FAQs <a href="#faqs" id="faqs"></a>

1\. Where can one find the <mark style="color:red;">`slug`</mark> of a Service?

The <mark style="color:red;">`slug`</mark> of a Service is displayed on the Service card as shown below.

![Service Slug in Squadcast](/files/VwJ5jCiYtQOmL9k5mtNO)

2\. Can I set up dependencies between Services that are in 2 different Teams?

No, you can set up dependencies only within Services for a given Team and not across Teams.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Key Based Deduplication

Define dedup keys using customizable templates for configured alert sources. Auto-group similar incidents for efficient incident management and grouping of duplicates.

Key Based Deduplication is an efficient way to avoid duplicate entries when processing incoming Events alongside existing Incidents. It works by generating a Deduplication Key using a user-defined template specific to events from an Alert Source. This key helps identify and group duplicates.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: This feature is available across all pricing plans.\
\ <mark style="color:blue;">**For all older accounts (created before Aug 21, 2023) and Enterprise accounts**</mark>:

The introduction of this feature does not affect any existing Deduplication Rules you may have set up for your Services. Your current rules will remain unchanged and continue to function as expected, providing you with the same level of control and efficiency in managing your alerts.

If you switch to Key-Based Deduplication by setting it to <mark style="color:green;">active</mark>, Deduplication Rules will become <mark style="color:red;">inactive</mark>.
{% endhint %}

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark>\
Automation rule CRUD operations have a 5-minute caching delay before changes take effect.
{% endhint %}

## How it works

1. To use the Key Based Deduplication feature, the user must opt-in to a specific Service.
2. They can define a template to generate dedupe keys for each alert source within the Service. The user also specifies a duration (x) for the Deduplication Window.
3. For an incoming Event, the Deduplication Key is calculated based on the defined template.
4. This Key is then compared (using equality) against any previous Incidents within the Deduplication Window (last 5 minutes or the specified duration).
5. If an Incident with the same Deduplication Key is found, the current Event is deduplicated against that Incident.
6. However, if no matching Incident is found, a new Incident is created.
7. Once the Deduplication Duration (x) elapses, the system recalculates the Deduplication Key using the defined template. This process continues for ongoing Deduplication.

<figure><img src="/files/OSW1rK6DOKYulSGyaK2g" alt="Flow Diagram for Key Based Deduplication" width="563"><figcaption><p>Image. Flow Diagram for Key Based Deduplication</p></figcaption></figure>

## Prerequisites

The User Role associated with the user in the Team must have required permissions to manage Services (ability to manage Key Based Deduplication).

## Create Key Based Deduplication

To add Key Based Deduplication:

1. Navigate to **Services** -> **Service Overview** -> Select or search for your desired Service.
2. On the extreme right, expand the accordion -> In the Automation section, **View All.**
3. In the Key Based Deduplication section, **Add Dedup Key**.
4. Select an alert source to begin creating Deduplication Keys for your incoming Events.
5. On the right, you can view the *payload of the **latest** alert* for the chosen Alert Source.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: You can configure one Dedup Key per Alert Source.
{% endhint %}

6. The user needs to define a template to generate Deduplication Keys using the variables from the payload referenced on the right, for a particular alert source of a Service. For additional information on how to write templates, please refer to [<mark style="color:blue;">Go's standard library</mark>.](https://developer.hashicorp.com/nomad/tutorials/templates/go-template-syntax)\
   \
   A Deduplication Key is calculated for the incoming event based on the template defined by the user.

<details>

<summary><mark style="color:blue;">Here are some illustrative examples that demonstrate how to define a template for generating Deduplication keys</mark>.</summary>

![](/files/oqGqC9VMIRFNvVgkzIBf) ![](/files/wdzp4nbDrlwHy5QCj9FC) ![](/files/RgrGq52iYtgQG2PnbXps) ![](/files/TW0QWME3d5dzadhixT5A) ![](/files/rDHFC37dLiLL3w3axQWS)

</details>

7. Define the **Deduplication Time,** in min(s) or hour(s).

<details>

<summary><mark style="color:blue;"><strong>Regular Expression-Based Extraction in Go Template</strong></mark></summary>

Our system supports regular expression-based extraction using regex rules. It allows for multiple name captures but only retains the first match for a specific named group. Additionally, when the passed expression is not valid, the function returns empty match results.

<pre class="language-go"><code class="lang-go"><strong>{{- with $matches := ("(?m)^Container: (?P&#x3C;container>.*)|Alertname: (?P&#x3C;alertname>.*)|Summary: (?P&#x3C;summary>.*)$" | reExtract .description) -}}
</strong>    {{$matches.container}}-{{$matches.alertname}}
{{- end -}}
</code></pre>

This code snippet is a template written in Go's text templating language, used to parse alert descriptions. It extracts specific details like container name, alert name, and summary from the descriptions using regular expressions and presents them in a concise format.

Here's a breakdown:

1. Regular Expression (`(?m)^Container: (?P<container>.*)|Alertname: (?P<alertname>.*)|Summary: (?P<summary>.*)$`):
   * `(?m)` enables multiline matching.
   * `^Container: (?P<container>.*)` captures everything after "Container: " into a named group "container".
   * `|Alertname: (?P<alertname>.*)` captures everything after "Alertname: " into a named group "alertname".
   * `|Summary: (?P<summary>.*)$` captures everything after "Summary: " into a named group "summary" and ensures it matches the end of the line (`$`).
2. Template Processing (`{{$matches := ...}}`):
   * The code defines a variable `$matches` using the regular expression to extract details from the description string `.description`.
3. Output Formatting (`{{$matches.container}}-{{$matches.alertname}}`)
   * The template accesses the captured container name (`$matches.container`) and alert name (`$matches.alertname`) from the `$matches` variable.
   * It combines them with a hyphen (-) for a one-line description format.

</details>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: The maximum time limit is 48 hours.
{% endhint %}

8. Click **Save**.

## Delete Key Based Deduplication

To delete a Key Based Deduplication config,

1. Click on the **Key Based Deduplication Rule** for a selected Service.
2. On the right-hand side, click **More Options** -> **Delete Key**
3. In the Configuration page, click **Delete**. A confirmation modal will appear.
4. Click **Delete anyway** to confirm.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: Kindly note that the Deduplication will cease once the Key is deleted.
{% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Event Tagging

Auto-add relevant information like priority, severity or alert type to make incoming incidents context-rich

{% embed url="<https://www.youtube.com/watch?v=-Mx0vsvzUU8>" %}

Event Tagging is a rule-based, auto-tagging system with which you can define customised tags based on incident payloads, that get automatically assigned to incidents when they are triggered.

You can define tags as <mark style="color:red;">`key:value`</mark> pairs. For example, the <mark style="color:red;">`key`</mark> could be <mark style="color:red;">`severity`</mark> and the *possible values* could be <mark style="color:red;">`SEV0`</mark>, <mark style="color:red;">`SEV1`</mark>, <mark style="color:red;">`SEV2`</mark>, etc., or the <mark style="color:red;">`key`</mark> could be <mark style="color:red;">`Team`</mark> and the *possible values* could be <mark style="color:red;">`Backend`</mark>, <mark style="color:red;">`Frontend`</mark>, <mark style="color:red;">`Database`</mark>, etc.

Event Tagging can be achieved by defining Tagging Rules for each Service in Squadcast. When these rules evaluate *true* for an incoming incident, the defined tag pairs are added to it.

## Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* The User Role associated with the user in the Team must have required permissions to manage Services (ability to manage Tagging Rules).
* Integrate with an Alert Source and ensure that the Alert Source has started sending alerts to Squadcast before setting up Tagging Rules.

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark>\
Automation rule CRUD operations have a 5-minute caching delay before changes take effect.
{% endhint %}

## Create Tagging Rules <a href="#creating-tagging-rules" id="creating-tagging-rules"></a>

To create tagging rules:

1. Navigate to **Services** -> **Service Overview** -> select or search for your desired service.
2. In the extreme right, expand the accordion -> In Automation section, **View All**
3. In the Tagging Rules section, **Add Tagging Rules**
4. Select an **Alert Source** from the drop down -> **Add New Rule**

<figure><img src="/files/TMtA6HHD71x8XHvdRHPa" alt="Event Tagging by alert source in Squadcast"><figcaption></figcaption></figure>

6\. Tagging Rules can be added in three ways:

### **A.** UI-based Rule Builder (Beginner-friendly) <a href="#a-ui-based-rule-builder-beginner-friendly" id="a-ui-based-rule-builder-beginner-friendly"></a>

a. On the right, you can view the *payload of the **latest** alert* for the chosen Alert Source

b. The drop-downs in the Rule Builder contain values from the payload on the right. You can use them to easily create your Tagging Rules

You can create Tagging Rules using the following conditions:

| Operators        | Condition                                                        |
| ---------------- | ---------------------------------------------------------------- |
| ==               | if the payload value is equal to the given value                 |
| !=               | if the payload value is not equal to the given value             |
| matches/contains | if the payload value matches (***or** contains*) the given value |
| does not contain | if the payload value does not contain the given value            |

{% hint style="warning" %}
**Note**: All these operators are case-sensitive.\
\
If you want to make the rules *case insensitive*, then you have to do it with the regular expression method.
{% endhint %}

<figure><img src="/files/i76LjeTIcy9YNOaNhPxz" alt="Add Event Tagging via UI-based Rule Builder"><figcaption></figcaption></figure>

c. You can add more than 1 condition for a rule by selecting **Add Condition** (a logical AND is performed between all the conditions -> the entire Tagging Rule will evaluate to <mark style="color:red;">`True`</mark> only if all the conditions evaluate to <mark style="color:red;">`True`</mark>)

d. Map any <mark style="color:red;">`Key`</mark> and <mark style="color:red;">`Value`</mark> pair as a tag. Multiple tags can be defined for each rule. You can select different colours for each of your tags

<figure><img src="/files/mpblPPtB7U3rhd2UTHgR" alt="Map a tag based on condition rule in Squadcast"><figcaption></figcaption></figure>

{% hint style="warning" %}
**Important**

The key of the Tag label, "tag key" can only contain letters (both lowercase and uppercase) and numbers. Anything else will be ignored.
{% endhint %}

{% hint style="info" %}
**Note**: The search option under payload is not a free search, we have to search by JSON format, for example, type in payload.annotations to get annotations.

\
We also have an option for click-to search, wherein you can click on the keys in the payload to get their required values.
{% endhint %}

### B. Raw String Method <a href="#b-raw-string-method" id="b-raw-string-method"></a>

{% hint style="warning" %}
**Important**

Once you opt for the Raw String method for a rule, you cannot revert to the UI-based Rule Builder method.
{% endhint %}

a. On the right, you can view the payload of the latest alert for the chosen Alert Source

b. Click on **Edit** to enable the Raw String method

<figure><img src="/files/CWtqxS5mHhzNq8lvboIl" alt="Edit an Event Tagging Rule in Squadcast"><figcaption></figcaption></figure>

c. Write your custom Tagging Rule expression. Below are some examples to help you get started:

{% hint style="info" %}
**How to make rules&#x20;*****case-insensitive*****?**\\

1. Click **Edit** -> **Proceed**
2. You will see the rule in the regular expression. Now you need to add the command lc (lower\_case) before the individual parameters

**Here is an example**:

`re(payload["subscription"]["type"], "Subscription")`

The rule says if the payload\["subscription"]\["type"]contains the string "Subscription" in it then do some actions.

If you want to make the above rule case insensitive, you have to add the command lc before the individual parameters.

The case insensitive rule would look like this,

`re(lc(payload["subscription"]["type"]), lc("Subscription")) or`

`re(lc(payload["subscription"]["type"]), "subscription")`
{% endhint %}

### Supported Rules <a href="#supported-rules" id="supported-rules"></a>

The rule engine supports expressions with parameters, arithmetic, logical, and string operations.

#### **Basic Expressions**

<mark style="color:red;">`10 > 0`</mark>, <mark style="color:red;">`1+2`</mark>, <mark style="color:red;">`100/3`</mark>

#### **Parameterized Expressions**

<mark style="color:red;">`payload.metric == "disk"`</mark> The available parameters are <mark style="color:red;">`payload`</mark>: This parameter contains the JSON payload of an incident which will be the same as the JSON payload format for the future events for a particular alert source

#### **Regular Expressions**

<mark style="color:red;">`re(payload.metric, "disk.*")`</mark>

{% hint style="warning" %}
**Important**

When there are multiple Tagging Rules created, every single Tagging Rule will be evaluated. All the tags of the matching rules will be attached to the incoming incident. If you have more than 1 rule with the same "key" value in "Tag Mapping", the "value" of the tag will be that of the last matching rule’s Tag Mapping.\
\
For example:\
If you have 2 Tagging Rules for a Service:\
\- Rule 1 with Tag Mapping Environment: QA\
\- Rule 2 with Tag Mapping Environment: QA-INTER\
Say, if your "match" condition string is “healthcheckstatus-QA-INTER-TESTING“, tag "Environment:QA-INTER" is created. If you interchange the order of Rule 1 and Rule 2, tag "Environment:QA" is created instead.\
\
Therefore, always ensure that you write your Tagging Rules in the correct order for desired behaviour or try and make them as specific as possible.
{% endhint %}

### Available Predefined Commands <a href="#available-predefined-commands" id="available-predefined-commands"></a>

The below commands can be used to create Tagging Rules.

#### **Add tags to incidents directly from your payload**

* If you already have tags being carried within your incident payload, you can add them as tags to your incidents as well without having to define *Tag Mappings* again
* You can simply specify the values that need to be picked from the payload and added as tags to the incident (picked dynamically) rather than having to statically define these values as *Tag Mappings*

A. <mark style="color:red;">`addTag`</mark> - Add one specific tag from the payload

#### **General Format**

<mark style="color:red;">`addTag( "<tag key name>", <value that needs to be picked from payload for the key>, "#<hexadecimal equivalent color for tag>")`</mark>

* tag key: The key of the Tag label. Only letters and numbers are allowed. Anything else will be ignored
* payload selector or string: You can choose to set a tag value from the payload or you can set any custom string as the tag value
* color: You can set color as a valid HEX code. This is optional. If this parameter is omitted, the default color - #0F61DD will be used

**Example** Below is an example payload for demonstration:

```
{
   "payload": {
      “message”: “Error rates higher than usual”,
      “description”: “HTTP Error rates for srv_90 is above 90 counts/hour”,
      "severity": “critical”
   }
}
```

Add a tag with **key**: <mark style="color:red;">`severity`</mark> and its **value** picked dynamically from the <mark style="color:red;">`severity`</mark> parameter in the payload

```
addTag( "severity", payload.severity, "#037916")
```

This will add the tag <mark style="color:red;">`severity: critical`</mark> with color <mark style="color:red;">`#037916`</mark> to your incident.

{% hint style="info" %}
**Note**

The "addTag" function always returns a "true" value. So, this can be chained with other logical operators to set multiple tags from the payload.
{% endhint %}

B. <mark style="color:red;">`addTags`</mark> - Add multiple tags from the payload

#### **General Format**

<mark style="color:red;">`addTags(<object containing key-value pairs that should be added as tags from the payload>)`</mark>

**Example** Below is an example payload for demonstration:

```
{
   "payload": {
	   “message”: “Error rates higher than usual”,
      “description”: “HTTP Error rates for srv_90 is above 90 counts/hour”,
	   “tags” : {
         “severity”: “high”,
         “impact_level”: "5",
         “classification”: {
            “color”: “#FF0000”,
            “value”: “backend”
         }
 	   }
   }
}
```

Add all the tags contained within <mark style="color:red;">`tags`</mark> object in the payload

This will add the tags <mark style="color:red;">`severity:high`</mark> with default color <mark style="color:red;">`#0F61DD`</mark>, <mark style="color:red;">`impact_level:5`</mark> with default color <mark style="color:red;">`#0F61DD`</mark>, <mark style="color:red;">`classification:backend`</mark> with the color <mark style="color:red;">`#FF0000`</mark> to your incident.

{% hint style="info" %}
**Note**

The "addTags" function will add all the tags with the default colour only - #0F61DD.
{% endhint %}

{% hint style="warning" %}
**Important**

The UI-based Rule Builder method does not support any function calls like "addTag" and "addTags". In order to use them, you would have to opt for constructing the tagging expression in the Raw String method.
{% endhint %}

#### **Parse JSON content within the payload using `jsonPath`to add a tag**

**General Format**

<mark style="color:red;">`jsonPath(<the JSON string that should be parsed for JSON content>, <"the parameter that needs to be picked from the parsed JSON object">)`</mark>

**Example** Below is an example payload:

```
{
   "payload": {  
      "Type" : "Notification",
      "MessageId" : "5966c484-5b37-58df",
      "TopicArn" : "arn:aws:sns:us-east-1:51:Test",
      "Message" : "{\"AlarmName\":\"Squadcast Testing - Ignore\",\"AlarmDescription\":\"Created from EC2 Console\"}"
   }
}
```

```
jsonPath(payload.Message, "AlarmName")
```

This will pick out the value <mark style="color:red;">`AlarmName`</mark> from the Message object in the payload. To add this extracted value as a tag to an incident, use it [<mark style="color:blue;">within regex or addTag commands</mark>](#incorporating-multiple-commands-in-a-single-rule)<mark style="color:blue;">.</mark>

#### **Parse HTML content within the payload using `htmlUnescape` to add a tag**

**General Format**

<mark style="color:red;">`htmlUnescape(<the string that is encoded with HTML escape sequences>)`</mark>

**Example**

Below is an example payload:

```
{
   "payload": {
      "id": "Memory available alert",
      "message": "Memory available alert from Chronograf for Test Macbook Pro",
      "details": "{&#34;Name&#34;:&#34;mem&#34;,&#34;TaskName&#34;:&#34;chronograf-v1-07cb04d0-f1f5-4a3f-afce-68ebb2b05d44&#34;,&#34;Group&#34;:&#34;nil&#34;,&#34;Tags&#34;:{&#34;host&#34;:&#34;Test-Macbook-Pro.local&#34;},&#34;ServerInfo&#34;:{&#34;Hostname&#34;:&#34;localhost&#34;,&#34;ClusterID&#34;:&#34;5359c160-521e-4a16-615efb7460cb&#34;,&#34;ServerID&#34;:&#34;47f1c611-85cf-bc42702fd259&#34;},&#34;ID&#34;:&#34;Memory available alert&#34;,&#34;Fields&#34;:{&#34;value&#34;:23.566293716430664},&#34;Level&#34;:&#34;CRITICAL&#34;,&#34;Time&#34;:&#34;2020-12-22T12:22:20Z&#34;,&#34;Duration&#34;:20000000000,&#34;Message&#34;:&#34;&#34;}\n",
      "time": "2020-12-22T12:22:20Z"
   }
}
```

```
htmlUnescape(payload.details)
```

This will parse HTML content <mark style="color:red;">`details`</mark> objects from the payload. See the following section to know how this can be incorporated within a Tagging Rule.

#### **Incorporating multiple commands in a single rule**

**Example 1**

Below is an example payload:

```
{
   "payload": {
      "id": "Memory available alert",
      "message": "Memory available alert from Chronograf for Test Macbook Pro",
      "details": "{&#34;Name&#34;:&#34;mem&#34;,&#34;TaskName&#34;:&#34;chronograf-v1-07cb04d0&#34;,&#34;Group&#34;:&#34;nil&#34;,&#34;Tags&#34;:{&#34;host&#34;:&#34;Test-Macbook-Pro.local&#34;},&#34;ServerInfo&#34;:{&#34;Hostname&#34;:&#34;localhost&#34;,&#34;ClusterID&#34;:&#34;5359c160-521e-4a16-615efb7460cb&#34;,&#34;ServerID&#34;:&#34;47f1c611-85cf-bc42702fd259&#34;},&#34;ID&#34;:&#34;Memory available alert&#34;,&#34;Fields&#34;:{&#34;value&#34;:23.566293716430664},&#34;Level&#34;:&#34;CRITICAL&#34;,&#34;Time&#34;:&#34;2020-12-22T12:22:20Z&#34;,&#34;Duration&#34;:20000000000,&#34;Message&#34;:&#34;&#34;}\n",
      "time": "2020-12-22T12:22:20Z",
      "source": "kapacitor"
   }
}
```

To add <mark style="color:red;">`TaskName`</mark> as a tag from the payload coming in from <mark style="color:red;">`Kapacitor`</mark>:

```
source == "kapacitor" && addTag("taskName", jsonPath(htmlUnescape(payload.details), "TaskName"), "#272822")
```

**Example 2**

Below is an example payload:

```
{
  "payload": {
    "issue_description": "bug - 2",
    "issue_id": "10029",
    "issue_key": "HYD-30",
    "issue_labels": [],
    "issue_link": "http://13.233.254.18:8080/browse/HYD/issues/HYD-30",
    "issue_priority": "Medium",
    "issue_summary": "bug - 2",
    "issue_type": "Bug",
    "project_id": "10000",
    "project_key": "HYD",
    "project_name": "hydra"
  },
  "source": "jira-plugin"
}
```

Assuming a case where *disk usage events need to be prioritised*:

* When the disk usage is greater than 90% - <mark style="color:red;">`critical`</mark> and <mark style="color:red;">`state`</mark> tag is <mark style="color:red;">`alerting`</mark>
* When the disk usage is between 60 - 90% - <mark style="color:red;">`high`</mark>
* When the disk usage is less than 60% - <mark style="color:red;">`low`</mark>

Create *3 rules* with the following configuration

**Rules**

1. Critical:

   ```
   payload.value  > 90 && jsonPath(payload.tags, "state") == "alerting"
   ```
2. High:

   ```
   payload.value > 60 && payload.value < 90
   ```
3. Low:

   ```
   payload.value < 60
   ```

### C. Manual Method <a href="#c-manual-method" id="c-manual-method"></a>

Associate a tag while creating an incident manually from the Incident Dashboard

<figure><img src="/files/cXFizCwLOwZCe2MIHZ1o" alt="Manual Method for tagging in manual incident in Squadcast"><figcaption></figcaption></figure>

## Deleting Tagging Rules <a href="#deleting-tagging-rules" id="deleting-tagging-rules"></a>

1\. Click on the Tagging Rule for a selected Service

2\. Click on the **bin** icon to delete that rule and click on **Save**

<figure><img src="/files/ZMIg0Rezs6Lw8Y5V4PM6" alt="Deleting Tagging Rules in Squadcast"><figcaption></figcaption></figure>

## Updating Tags <a href="#updating-tags" id="updating-tags"></a>

Use **+Update Tags** within an incident to update tags for a specific incident

<figure><img src="/files/TpiKrwBpzc0TtWIxvKlg" alt="Update Tags within an incident in Squadcast"><figcaption></figcaption></figure>

## FAQs <a href="#faqs" id="faqs"></a>

1\. Where can I see the tags associated with incidents?

You will be able to clearly view tags associated with incidents in the[ <mark style="color:blue;">Incident List.</mark>](/incident-list/incident-list-view)

<figure><img src="/files/ReBtX1npsMNbdurPO97b" alt="View tags associated with incidents in the Incident List in Squadcast"><figcaption></figcaption></figure>

2\. Can I add tags from the payload automatically?

Yes, you can. Refer above [<mark style="color:blue;">here</mark>](#add-tags-to-incidents-directly-from-your-payload) for more information and examples.

3\. Can I create OR rules?

Yes, you can. The evaluation between different Tagging Rules is OR. Add multiple Tagging Rules to enable OR evaluation.

4\. Can a Tagging Rule be created for a specific alert source?

By default, any rule added for a Service will be executed for all its active alert source integrations. You can choose to isolate Tagging Rules for specific alert sources based on the <mark style="color:red;">`source`</mark> field in the payload visible on the right panel.

Example:

```
source == "api" && (<your_tagging_rule>)
```

This will ensure that this Tagging Rule will only be active for incidents triggered via that alert source for the service. This rule will not function for any other alert source.

5\. While adding a Tagging Rule, is the *search string* in the rule case sensitive?

Yes, that is correct. For example, if your search string is “ALERT” and your payload does not contain “ALERT” but contains “Alert”, this will not be matched. Your search string should be “Alert”.

6\. What kind of regex can be used to write custom rules?

The rule engine supports expressions with parameters, arithmetic, logical, and string operations. You can also check [<mark style="color:blue;">this</mark>](https://regex101.com/) out to get an idea of all the expression types accepted in Squadcast. Please do your regex [<mark style="color:blue;">here</mark>](https://regex101.com/) against <mark style="color:red;">`Golang`</mark> flavor as shown in the screenshot below and then, set them up in Squadcast:

![Regex used to write custom rules in Squadcast](/files/GcxrTzLO5Utxg3vwprEH)

7\. I have configured multiple rules for a particular Service. Can I search through the configured rules to find the rule I am looking for?

Yes, that is doable. You will notice a **Search** option on the left top of the rules modal. You can type in a word you recall from the rule itself or search by the mapped tags within the rules. Any matching results will yield a **narrowed-down** set of rules.

<figure><img src="/files/7WsCVVDhA8rZpdyUbZxu" alt="Search the event tag rules in Squadcast"><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Alert Routing

Route alerts to the right responder(s) based on the tags they carry.

{% embed url="<https://www.youtube.com/watch?v=zmentTMRYFA>" %}

Alert Routing allows you to configure *Routing Rules* to ensure that alerts are routed to the right responder with the help of <mark style="color:red;">`event tags`</mark> attached to them.

## Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* The User Role associated with the user in the Team must have required permissions to manage Services (ability to manage Routing Rules).
* Ensure you have <mark style="color:red;">`Tags`</mark> [<mark style="color:blue;">defined</mark>](https://support.squadcast.com/docs/event-tagging) for the Service.

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark>\
Automation rule CRUD operations have a 5-minute caching delay before changes take effect.
{% endhint %}

## Create Routing Rules <a href="#configuring-routing-rules" id="configuring-routing-rules"></a>

To configure Routing Rules:

1. Navigate to **Services** -> **Service Overview** -> select or search for your desired service.
2. On the extreme right, expand the accordion -> In the Automation section, **View All.**
3. In the Routing Rules section, **Add Routing Rules**.
4. You can add Routing Rules in three ways:

### UI-based Rule Builder (Beginner-friendly) <a href="#ui-based-rule-builder-beginner-friendly" id="ui-based-rule-builder-beginner-friendly"></a>

**(a)** This box displays all the <mark style="color:red;">`[event tags]`</mark>(<https://support.squadcast.com/docs/event-tagging>) defined for this Service, which can be used to define Routing Rules

**(b)** Select **Add new rule**

<figure><img src="https://github.com/solarwinds-cloud/sq-Gitbook/blob/main/.gitbook/assets/21spaces%2F8TaWz01jmUJl58p4ZVel%2Fuploads%2Fgit-blob-629cde36fa4719ce32b66194528e22d858141a39%2Falert_routing_3%20(1).png" alt="Add Routing Rules via UI-based rule builder"><figcaption></figcaption></figure>

**(c)** Pick the **event tag** <mark style="color:red;">`key`</mark> and <mark style="color:red;">`value`</mark> pair that you are checking for in an incident using the drop-downs

<figure><img src="https://github.com/solarwinds-cloud/sq-Gitbook/blob/main/.gitbook/assets/21spaces%2F8TaWz01jmUJl58p4ZVel%2Fuploads%2Fgit-blob-b44761bd9a10e1ce3026a4b5503e710b3396192e%2Falert_routing_4.png" alt="pick the event tag key and value pair for incident routing rules"><figcaption></figcaption></figure>

**(d)** **Add Conditions** to make your rules more granular

You can create Routing Rules using the following conditions:

| Operators        | Condition                                                        |
| ---------------- | ---------------------------------------------------------------- |
| ==               | if the payload value is equal to the given value                 |
| !=               | if the payload value is not equal to the given value             |
| matches/contains | if the payload value matches (***or** contains*) the given value |
| does not contain | if the payload value does not contain the given value            |

{% hint style="warning" %}
**Note**: All these operators are case-sensitive.\
\
If you want to make the rules *case insensitive*, then you have to do it with the regular expression method.
{% endhint %}

**(e)** You can route the incident containing the specific <mark style="color:red;">`event tags`</mark> to either a <mark style="color:red;">`User`</mark>, <mark style="color:red;">`Squad`</mark> or an <mark style="color:red;">`Escalation Policy`</mark>. Pick the same from the drop-down

**(f)** Click on **Save**

<figure><img src="https://github.com/solarwinds-cloud/sq-Gitbook/blob/main/.gitbook/assets/21spaces%2F8TaWz01jmUJl58p4ZVel%2Fuploads%2Fgit-blob-41e3f20b51d21c82c649e9ed0d96ad1d83a5bc91%2Falert_routing_5.png" alt="route the incident containing the specific event tags to user squad or Escalation Policy"><figcaption></figcaption></figure>

{% hint style="info" %}
**Default Service Escalation Policy Override**

The Alert Routing Rules will take precedence (override) over the default Escalation Policy for the Service if any of the rules match (evaluate to True) an incoming incident.
{% endhint %}

{% hint style="info" %}
**Note**: The search option under payload is not a free search, we have to search by JSON format, for example, type in payload.annotations to get annotations.

\
We also have an option for click-to-search, wherein you can click on the keys in the payload to get their required values.
{% endhint %}

### Raw String Method <a href="#raw-string-method" id="raw-string-method"></a>

{% hint style="info" %}
**Note**

Once you opt for the Raw String method, you cannot revert to the UI-based Rule Builder method for that rule.
{% endhint %}

**(a)** This box displays all the <mark style="color:red;">`event tags`</mark> [<mark style="color:blue;">defined</mark>](https://support.squadcast.com/docs/event-tagging) for this Service

**(b)** Select **Add new rule**

<figure><img src="https://github.com/solarwinds-cloud/sq-Gitbook/blob/main/.gitbook/assets/21spaces%2F8TaWz01jmUJl58p4ZVel%2Fuploads%2Fgit-blob-629cde36fa4719ce32b66194528e22d858141a39%2Falert_routing_31.png" alt="incident routing rules by raw string method in Squadcast"><figcaption></figcaption></figure>

**(c)** Click on **Edit** to enable **the** Raw String method

<figure><img src="https://github.com/solarwinds-cloud/sq-Gitbook/blob/main/.gitbook/assets/21spaces%2F8TaWz01jmUJl58p4ZVel%2Fuploads%2Fgit-blob-ec029c57298a5f48f30c7310e2f905c6b6469f88%2Falert_routing_7.png" alt="how to enable the incident routing rules by Raw String method in Squadcast"><figcaption></figcaption></figure>

{% hint style="info" %}
**How to make rules&#x20;*****case-insensitive*****?**\\

1. Click **Edit** -> **Proceed**
2. You will see the rule in the regular expression. Now you need to add the command lc (lower\_case) before the individual parameters

**Here is an example**:

`re(payload["subscription"]["type"], "Subscription")`

The rule says if the payload\["subscription"]\["type"]contains the string "Subscription" in it then do some actions.

If you want to make the above rule case insensitive, you have to add the command lc before the individual parameters.

The case insensitive rule would look like this,

`re(lc(payload["subscription"]["type"]), lc("Subscription")) or`

`re(lc(payload["subscription"]["type"]), "subscription")`
{% endhint %}

**(d)** Write your custom Tagging Rule expression and select **Route To** accordingly

**(e)** Click on **Save**

<figure><img src="https://github.com/solarwinds-cloud/sq-Gitbook/blob/main/.gitbook/assets/21spaces%2F8TaWz01jmUJl58p4ZVel%2Fuploads%2Fgit-blob-fbb334620ebe17473d3e260f51b87ca213d905bf%2Falert_routing_6.png" alt="select custom Tagging Rule expression in incident routing rules in Squadcast"><figcaption></figcaption></figure>

### Supported Rules <a href="#supported-rules" id="supported-rules"></a>

The rule engine supports expressions with parameters, arithmetic, logical, and string operations.

#### **Basic Expressions**

<mark style="color:red;">`10 > 0`</mark>, <mark style="color:red;">`1+2`</mark>, <mark style="color:red;">`100/3`</mark>

#### **Parameterized Expressions**

<mark style="color:red;">`tags.severity == "high"`</mark>

The available parameters are <mark style="color:red;">`tags`</mark>

* <mark style="color:red;">`tags`</mark>: This parameter contains all the configured tags for a given Service.

#### **Regular Expressions**

<mark style="color:red;">`re(tags.severity, "high.*")`</mark>

This can be used to check if a particular tag field matches a regular expression.

#### **Example**

Below is the set of <mark style="color:red;">`event tags`</mark> defined for a Service (as shown in the right panel of the configuration space)

```
{
	"tags": [
		{
			"severity": "critical"
		},
		{
			"severity": "high"
		},
		{
			"severity": "low"
		}
	]
}
```

#### **Use-case for Routing Rules**

When:

* <mark style="color:red;">`severity`</mark> is <mark style="color:red;">`critical`</mark> : Route to a **Squad**
* <mark style="color:red;">`severity`</mark> is <mark style="color:red;">`high`</mark> : Route to an **Escalation Policy**
* <mark style="color:red;">`severity`</mark> is <mark style="color:red;">`low`</mark> : Route to a **User**

#### **Routing Rules are as follows:**

* <mark style="color:red;">`tags.severity == "critical"`</mark> *route* to a <mark style="color:red;">`squad`</mark>
* <mark style="color:red;">`tags.severity == "high"`</mark> *route* to an <mark style="color:red;">`escalation policy`</mark>
* <mark style="color:red;">`tags.severity == "low"`</mark> *route* to a <mark style="color:red;">`user`</mark>

## FAQs <a href="#faqs" id="faqs"></a>

1\. How do I know if an incident gets routed due to a Routing Rule?

In the Incident’s Activity Timeline the reason for routing, and to which entity it gets routed to, is displayed.

<figure><img src="https://github.com/solarwinds-cloud/sq-Gitbook/blob/main/.gitbook/assets/21spaces%2F8TaWz01jmUJl58p4ZVel%2Fuploads%2Fgit-blob-c510b89b49dac8c015d99283b9fa9663292aa3e5%2Frouting_reason.png" alt="select custom Tagging Rule expression in incident routing rules in Squadcast"><figcaption></figcaption></figure>

2\. What kind of regex can be used to write custom rules?

The rule engine supports expressions with parameters, arithmetic, logical, and string operations. You can also check [<mark style="color:blue;">this</mark>](https://regex101.com/) out to get an idea of all the expression types accepted in Squadcast. Please do your regex [<mark style="color:blue;">here</mark>](https://regex101.com/) against <mark style="color:red;">`Golang`</mark> flavor as shown in the screenshot below and then, set them up in Squadcast:

![Regex used to write custom rules in Squadcast](/files/mnRpjfht99wKfbQ6VYlq)

3\. Can I create OR rules?

Yes, you can. The evaluation between different Routing Rules is <mark style="color:red;">`OR`</mark>. Add multiple Routing Rules to enable <mark style="color:red;">`OR`</mark> evaluation.

4\. While adding a Routing Rule, is the *search string* in the rule case sensitive?

Yes, that is correct. For example, if your **search** string is “ALERT” and your payload does not contain “ALERT” but contains “Alert”, this will not be matched. Your search string should be “Alert”.

5\. Do Routing Rules have priority?

Yes, you can specify Execution Rule Priority for the rules defined by moving them <mark style="color:red;">`Up`</mark> or <mark style="color:red;">`Down`</mark> the list of rules.

<figure><img src="/files/Wc0N8UrneDPplxC4VUrG" alt="Move execution priority of Routing Rules in Squadcast"><figcaption></figcaption></figure>

6\. I have configured multiple rules for a particular Service. Can I search through the configured rules to find the rule I am looking for?

Yes, that is doable. You will notice a **Search** option on the left top of the rules modal. You can type in a word you recall from the rule. Any matching results will yield a narrowed-down set of rules.

<figure><img src="/files/fY0h5yGqGsykPi3wrg0C" alt="Search through configured Routing Rules in Squadcast"><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Alert Suppression

Fight alert fatigue with Alert Suppression - Learn how to optimize incident management by effectively suppressing non-actionable notifications. Take control today!

{% embed url="<https://www.youtube.com/watch?v=Uzu6Yk-VjSY>" %}

Alert Suppression can help you avoid alert fatigue by suppressing notifications for non-actionable alerts.

Squadcast will suppress the incidents that match any of the Suppression Rules you create for your Services. These incidents will go into the `Suppressed` state and you will not get any notifications for them.

These are useful in situations where you would like to *view* your all your informational alerts in Squadcast but do not want to get notified for them.

## Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* The User Role associated with the user in the Team must have required permissions to manage Services (ability to manage Suppression Rules).
* Integrate with an Alert Source and ensure that the Alert Source has started sending alerts to Squadcast before setting up Suppression Rules.

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark>\
Automation rule CRUD operations have a 5-minute caching delay before changes take effect.
{% endhint %}

## Create Alert Suppression Rules <a href="#creating-suppression-rules" id="creating-suppression-rules"></a>

1. Navigate to **Services** -> **Service Overview** -> select or search for your desired service.
2. In the extreme right, expand the accordion -> In Automation section, **View All**.
3. In the Suppression Rules section, **Add Suppression Rules**.
4. Select an **Alert Source** from the drop down -> **Add New Rule**.

<figure><img src="/files/BzkOCLPW3xKwa9AcJjUZ" alt="how to create alert suppression rules in Squadcast" width="563"><figcaption></figcaption></figure>

5\. Suppression Rules can be added in two different ways:

### A. UI-based Rule Builder (Beginner-friendly) <a href="#a-ui-based-rule-builder-beginner-friendly" id="a-ui-based-rule-builder-beginner-friendly"></a>

1\. On the right, you can view the *payload of the **latest** alert* for the chosen Alert Source

2\. The drop-downs in the Rule Builder contain values from the payload on the right. You can use them to easily create your Suppression Rules. As you build the expression from these drop-downs, you can also see the corresponding *raw string* being auto-populated for the same under **String Expression**.

You can create Suppression Rules using the following conditions:

| Operators        | Condition                                                        |
| ---------------- | ---------------------------------------------------------------- |
| ==               | if the payload value is equal to the given value                 |
| !=               | if the payload value is not equal to the given value             |
| matches/contains | if the payload value matches (***or** contains*) the given value |
| does not contain | if the payload value does not contain the given value            |

{% hint style="warning" %}
**Note**: All these operators are case-sensitive.\
\
If you want to make the rules *case insensitive*, then you have to do it with the regular expression method.
{% endhint %}

<figure><img src="/files/NZ26Iq57qGtFYwqL5QwN" alt="create your Alert Suppression Rules via UI-based Rule Builder in Squadcast" width="563"><figcaption></figcaption></figure>

3\. You can add more than 1 condition for a rule by selecting **Add Condition** (a logical AND is performed between all the conditions -> the entire Suppression Rule will evaluate to <mark style="color:red;">`True`</mark> only if all the conditions evaluate to <mark style="color:red;">`True`</mark>)

<figure><img src="/files/wzzVtPm9BFMYpl4XdAgy" alt="Adding more than one condition for Alert Suppression in Squadcast" width="563"><figcaption></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>**:**

The drop-down blocks only support the logical <mark style="color:red;">`AND`</mark> operator between 2 expressions. If you want to have a logical <mark style="color:red;">`OR`</mark> operation between 2 expressions, then you would have to create a new Suppression Rule.
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Comparison Operators within Suppression Rules**</mark>

You can also leverage comparison operators such as <mark style="color:red;">`==, <, <=, >, >=`</mark> within your rules using the drop-down blocks, when the parameter you are evaluating against, is a **numerical value from the payload** to reduce alert noise.

<img src="/files/qP5Pz0Fs7Lb9NuuFFExI" alt="Alert Suppression Rules in Squadcast" data-size="original">
{% endhint %}

4\. You can suppress incidents based on time as well. To do so, check to **Suppress by time**. Add details for your suppression time slots like **Timezone**, **Duration** and **Repetition**.

Under **Duration**, you can specify **Start and End Dates** and choose **Start and End Time** as well or simply run it for the entire day.

You can add **Repetition** for your slot, to do so, you can choose from the **drop-down list**, while specifying the end for this repetition, as a particular date/time or never.

{% hint style="info" %}
**Note:** You can add multiple suppression time slots for a single Suppression Rule.
{% endhint %}

{% hint style="info" %}
**Note:** Users can select a timezone as per which the time slot needs to be active.
{% endhint %}

{% hint style="info" %}
**Note**: The search option under payload is not a free search, we have to search by JSON format, for example, type in payload.annotations to get annotations.

\
We also have an option for click-to search, wherein you can click on the keys in the payload to get their required values.
{% endhint %}

<figure><img src="/files/bLdBH9PL8AyT2L3Aqiju" alt="Set Alert Suppression based on time in Squadcast" width="563"><figcaption></figcaption></figure>

### B. Raw String Method <a href="#b-raw-string-method" id="b-raw-string-method"></a>

{% hint style="warning" %}
**Important**

Once you opt for the Raw String method, you cannot revert to the UI-based Rule Builder method.
{% endhint %}

(a) On the right, you can view the payload of the latest alert for the chosen Alert Source

(b) Click on **Edit** to enable **the** Raw String method

<figure><img src="/files/fDAT594BD40slaFk9NDy" alt="Edit Alert Suppression Rules in Squadcast" width="563"><figcaption></figcaption></figure>

(c) Write your custom Suppression Rule expression

{% hint style="info" %}
**How to make rules&#x20;*****case-insensitive*****?**\\

1. Click **Edit** -> **Proceed**
2. You will see the rule in the regular expression. Now you need to add the command lc (lower\_case) before the individual parameters

**Here is an example**:

`re(payload["subscription"]["type"], "Subscription")`

The rule says if the payload\["subscription"]\["type"]contains the string "Subscription" in it then do some actions.

\
If you want to make the above rule case insensitive, you have to add the command lc before the individual parameters.

\
The case insensitive rule would look like this,

`re(lc(payload["subscription"]["type"]), lc("Subscription")) or`

`re(lc(payload["subscription"]["type"]), "subscription")`
{% endhint %}

(d) You can suppress incidents based on time as well. To do so, check to **Suppress by time**. Add details for your suppression time slots like **Timezone**, **Duration** and **Repetition**.

Under **Duration**, you can specify **Start and End Dates** and choose **Start and End Time** as well or simply run it for the entire day.

You can add **Repetition** for your slot, to do so, you can choose from the **drop-down list**, while specifying the end for this repetition, as a particular date/time or never.

{% hint style="info" %}
**Note:** You can add multiple suppression time slots for a single Suppression Rule.
{% endhint %}

{% hint style="info" %}
**Note:** Users can select a timezone as per which the time slot needs to be active.
{% endhint %}

<figure><img src="/files/pUBSeD5o3RoZ19kaMXeT" alt="custom Alert Suppression Rule expression raw string method in Squadcast" width="563"><figcaption></figcaption></figure>

### Supported Rules <a href="#supported-rules" id="supported-rules"></a>

The rule engine supports expressions with parameters, arithmetic, logical, and string operations. You can also check out this [<mark style="color:blue;">link</mark>](https://regex101.com/) to get an idea of all the expression types accepted in Squadcast.

#### **Basic Expressions**

<mark style="color:red;">`10 > 0`</mark>, <mark style="color:red;">`1+2`</mark>, <mark style="color:red;">`100/3`</mark>

#### **Parameterized Expressions**

<mark style="color:red;">`payload.metric == "disk"`</mark> The available parameters are <mark style="color:red;">`payload`</mark>: This parameter contains the JSON payload of an incident which will be the same as the JSON payload format for the future events for a particular alert source <mark style="color:red;">`payload`</mark>: This parameter contains the JSON payload of an incident which will be the same as the JSON payload format for the future events for a particular alert source <mark style="color:red;">`payload`</mark>: This parameter contains the JSON payload of an incident which will be the same as the JSON payload format for the future events for a particular alert source <mark style="color:red;">`incident_details`</mark>: This contains the content of the <mark style="color:red;">`message`</mark> and <mark style="color:red;">`description`</mark> of the incoming event <mark style="color:red;">`source`</mark>: This denotes the associated alert source for the current/incoming event

#### **Regular Expressions**

<mark style="color:red;">`re(payload.metric, "disk.*")`</mark>

#### **Parse JSON content within the payload using `jsonPath` to add a tag**

#### **General Format** <mark style="color:red;">`jsonPath(<the JSON string that should be parsed for JSON content>, <"the parameter that needs to be picked from the parsed JSON object">)`</mark>

#### **Example**

Below is an example payload:

```
{
	"payload": {
   "payload": {
	"payload": {
		"Type": "Notification",
		"MessageId": "5966c484-5b37-58df",
		"TopicArn": "arn:aws:sns:us-east-1:51:Test",
		"Message": "{\"AlarmName\":\"Squadcast Testing - Ignore\",\"AlarmDescription\":\"Created from EC2 Console\"}"
	}
}
```

```
jsonPath(payload.Message, "AlarmName");
```

This will pick out the value <mark style="color:red;">`AlarmName`</mark> from the Message object in the payload based on which, you can suppress the incident.

#### **Example**

{% hint style="info" %}
**Multiple Alert Sources**

We can see alert payloads of past events from different alert sources for the service by selecting the respective alert source from the dropdown on the right-half side.

Since the payload format is fixed for a given alert source, it is usually preferable to have suppression rules on a per-alert source basis. This can be done by making use of the `source` field which lets you know the alert source that triggered the incoming event.

For example, if you want to have a suppression rule for a service, only for alerts coming from **`grafana`** alert source, then the corresponding rule would look something like this:

```
source == 'grafana' && (<your_suppression_rule>)
```

{% endhint %}

Below is an example payload for demonstration:

```
{
	"payload": {
		"issue_description": "bug - 2",
		"issue_id": "10029",
		"issue_key": "HYD-30",
		"issue_labels": [],
		"issue_link": "http://13.233.254.18:8080/browse/HYD/issues/HYD-30",
		"issue_priority": "Medium",
		"issue_summary": "bug - 2",
		"issue_type": "Bug",
		"project_id": "10000",
		"project_key": "HYD",
		"project_name": "hydra"
	},
	"incident_details": {
		"message": "[Bug] bug - 2",
		"description": "+ Project: HYDRA \n+Issue Type: Bug ..."
	},
	"source": "grafana"
}
```

To suppress any incoming alert when:

* The alert message contains: <mark style="color:red;">`[Bug]`</mark>
* The alert source is <mark style="color:red;">`grafana`</mark>

**Suppression Rule:**

```
re(payload.incident_details.message, "[Bug]") && source == "grafana";
```

## Discarding suppressed incidents <a href="#discarding-suppressed-incidents" id="discarding-suppressed-incidents"></a>

To discard incoming alerts and stop them from being triggered as incidents in Squadcast, use the <mark style="color:red;">`discard()`</mark> function in conjunction with Suppression Rules.

### Example <a href="#example-1" id="example-1"></a>

Suppression Rule:

```
source == "grafana" && re(payload["message"], "Notification Message");
```

Suppression Rule with <mark style="color:red;">`discard()`</mark>:

```
source == grafana &&
	re(payload["message"], "Notification Message") &&
	discard();
```

{% hint style="info" %}
**Avoid hitting Rate Limits**

The `discard()` function can be used to avoid hitting the [<mark style="color:blue;">**Incident Rate Limits**</mark>](https://support.squadcast.com/docs/incident-rate-limiting) as **Suppressed events that are discarded** don’t get counted against the allowed rate limits.
{% endhint %}

## Viewing Suppressed Incidents <a href="#viewing-suppressed-incidents" id="viewing-suppressed-incidents"></a>

You can view <mark style="color:red;">`suppressed`</mark> incidents on the[ <mark style="color:blue;">Incidents</mark>](/incident-list/incident-list-view) page by clicking on **All Incidents** and choosing **Suppressed** as highlighted in the screenshot below.

<figure><img src="/files/RKdrke8z0vqpUMG61k4K" alt="how to view Suppressed Incidents in Squadcast" width="563"><figcaption></figcaption></figure>

{% hint style="info" %}
**Note**

* **`Suppressed`** and **`Resolved`** are the final states for incidents in Squadcast. You will not be able to take any action on incidents that are in these states.
* Incident information will be available on the Squadcast platform even if they are suppressed.
  {% endhint %}

## FAQs <a href="#faqs" id="faqs"></a>

1\. What kind of regex can be used to write custom rules?

The rule engine supports expressions with parameters, arithmetic, logical, and string operations. You can also check [<mark style="color:blue;">this</mark>](https://regex101.com/) out to get an idea of all the expression types accepted in Squadcast. Please do your regex [<mark style="color:blue;">here</mark>](https://regex101.com/) against <mark style="color:red;">`Golang`</mark> flavour as shown in the screenshot below and then, set them up in Squadcast:

![Regex used to write custom rules](/files/OzlSr0FzbemRgvzvRMsV)

2\. Can I create OR rules?

Yes, you can. The evaluation between different Suppression Rules is <mark style="color:red;">`OR`</mark>. Add multiple Suppression Rules to enable <mark style="color:red;">`OR`</mark> evaluation.

3\. While adding a Suppression Rule, is the *search string* in the rule case sensitive?

Yes, that is correct. For example, if your search string is “ALERT” and your payload does not contain “ALERT” but contains “Alert”, this will not be matched. Your search string should be “Alert”.

4\. How do I know if an incident gets suppressed due to a Suppression Rule?

In the Incident’s Activity Timeline, the reason for suppression is displayed.

<figure><img src="/files/0XQwIcoz7yrQZ6XU3FCJ" alt="Alert Suppression notification in the Incident Activity Timeline" width="563"><figcaption></figcaption></figure>

5\. I have configured multiple rules for a particular Service. Can I search through the configured rules to find the rule I am looking for?

Yes, that is doable. You will notice a **Search** option on the left top of the rules modal. You can type in a word you recall from the rule description or the rule itself. Any matching results will yield a narrowed-down set of rules.

<figure><img src="/files/3Gm8wb4nArxlJhyH71ZX" alt="Search through configured Alert Suppression Rules" width="190"><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Custom Content Templates

Streamline incident management with customizable message and description templates. Define personalized alerts using payload from configured sources, and enhance response efficiency.

Custom Content Templates empower users to define personalized Incident messages and description templates by utilizing the payload of a configured alert source for this service. If there is a template configured, the incoming Incident will have a customized message and description.

In the absence of user-defined templates, the system will default to using the Incident message and description templates defined by Squadcast, which is the current behavior.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: This feature is available only in the Premium and Enterprise [<mark style="color:blue;">plans</mark>](https://www.squadcast.com/pricing).
{% endhint %}

## Prerequisites

The User Role associated with the user in the Team must have required permissions to manage Services (ability to manage Custom Content Templates).

## Create Custom Content Templates

To add a custom content template,

1. Navigate to **Services** -> **Service Overview** -> Select or search for your desired service.
2. Expand the accordion -> **View Service Details.**
3. In the **Custom Content Templates** section -> Click **+ Template**
4. Select an **Alert Source** from the drop-down -> **Define Templates**

{% hint style="info" %}
**Note**: For additional information on how to write templates, refer [<mark style="color:blue;">Go’s standard library</mark>](https://developer.hashicorp.com/nomad/tutorials/templates/go-template-syntax).
{% endhint %}

5. Establish the template for the **Incident Message** and **Description** -> Refer to the **Output** section to preview the appearance of your configured template.

<details>

<summary><mark style="color:blue;">Here are some illustrative examples that demonstrate how to define a template for an Incident Message and Description</mark>.</summary>

![](/files/ZKwKoH7D6KwXyb5Cb86L) ![](/files/xMYpbWMMpdg1ZNal0yCt)

</details>

6. Click **Save**.

<details>

<summary><mark style="color:blue;"><strong>Regular Expression-Based Extraction in Go Template</strong></mark></summary>

Our system supports regular expression-based extraction using regex rules. It allows for multiple name captures but only retains the first match for a specific named group. Additionally, when the passed expression is not valid, the function returns empty match results.

<pre class="language-go"><code class="lang-go"><strong>{{- with $matches := ("(?m)^Container: (?P&#x3C;container>.*)|Alertname: (?P&#x3C;alertname>.*)|Summary: (?P&#x3C;summary>.*)$" | reExtract .description) -}}
</strong>    {{$matches.container}}-{{$matches.alertname}}
{{- end -}}
</code></pre>

This code snippet is a template written in Go's text templating language, used to parse alert descriptions. It extracts specific details like container name, alert name, and summary from the descriptions using regular expressions and presents them in a concise format.

Here's a breakdown:

1. Regular Expression (`(?m)^Container: (?P<container>.*)|Alertname: (?P<alertname>.*)|Summary: (?P<summary>.*)$`):
   * `(?m)` enables multiline matching.
   * `^Container: (?P<container>.*)` captures everything after "Container: " into a named group "container".
   * `|Alertname: (?P<alertname>.*)` captures everything after "Alertname: " into a named group "alertname".
   * `|Summary: (?P<summary>.*)$` captures everything after "Summary: " into a named group "summary" and ensures it matches the end of the line (`$`).
2. Template Processing (`{{$matches := ...}}`):
   * The code defines a variable `$matches` using the regular expression to extract details from the description string `.description`.
3. Output Formatting (`{{$matches.container}}-{{$matches.alertname}}`)
   * The template accesses the captured container name (`$matches.container`) and alert name (`$matches.alertname`) from the `$matches` variable.
   * It combines them with a hyphen (-) for a one-line description format.

</details>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: Please keep in mind that notifications for these incidents will feature the provided custom incident message and will follow applicable notification guidelines.
{% endhint %}

## Delete Custom Content Templates

To delete a custom content template,

1. Click on the **Custom Content Template** for a selected Service.
2. On the right-hand side, click **More Options** -> **Delete Template**
3. A confirmation modal will appear -> Click **Delete** again to confirm.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Intelligent Alert Grouping (IAG)

Automatically group incoming alerts with a similar open incident and save your team from alert noise

Intelligent Alert Grouping (IAG) employs a real-time algorithm based on machine learning to consolidate interconnected alerts into a unified, active incident. This proves especially beneficial for incident responders by minimizing the volume of distracting information, enabling them to concentrate on their immediate responsibilities. As time progresses, the grouping algorithm evolves to comprehend emerging alert patterns and respond to human actions, enhancing the precision of its grouping choices and contributing to even swifter incident resolution.

Intelligent Alert Grouping (IAG) looks at alerts from a single Service. If you want alerts from different Services to be grouped, you may need to reconfigure your Service to send all related alerts to the same Service.

{% @storylane/embed subdomain="app" url="<https://app.storylane.io/share/y2ymk3e8npol>" linkValue="y2ymk3e8npol" %}

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> This feature will be available for accounts in the [<mark style="color:blue;">Enterprise plan</mark>](https://www.squadcast.com/pricing).
{% endhint %}

## Enable Intelligent Alert Grouping

1. While creating a new Service:
   1. Navigate to the Services tab where you can start creating a new Service. Among other details given as inputs necessary for creating the Service, enable the toggle for Intelligent Alert Grouping (IAG).
   2. Next, choose a time interval as the Grouping Window. Available options are shown in the drop-down.
   3. By clicking **Save and Continue**, you can proceed with Service creation which will result in the immediate enablement of Intelligent Alert Grouping (IAG).

<div><figure><img src="/files/bh2Egshq99bHJzxNMI3c" alt=""><figcaption><p>Image. Setting Grouping Window</p></figcaption></figure> <figure><img src="/files/17QP61DvphL9erAQ87i7" alt=""><figcaption><p>Image. Enable IAG</p></figcaption></figure></div>

2. For an existing Service:
   1. Navigate to the Services tab. For the selected Service, click the **More** action and select **Edit** **Service**.
   2. Here, you can enable the toggle for Intelligent Alert Grouping (IAG).
   3. Next, choose a time interval as the Grouping Window. Available options are shown in the drop-down.
   4. By clicking **Save Changes**, Intelligent Alert Grouping (IAG) will be enabled for the Service.

<div><figure><img src="/files/bQSkD028qP9jrR2TJOJO" alt=""><figcaption><p>Image. Edit Service</p></figcaption></figure> <figure><img src="/files/hLhuQhvXDOQ7UknaIXut" alt=""><figcaption><p>Image. Enable IAG</p></figcaption></figure></div>

## View Auto-grouped Alerts for an Incident

When enabled, you can identify the incidents that have auto-grouped alerts in the Incident List with the help of the highlighted icon in the image below.

<figure><img src="/files/kRtmH1pSwMjSL72AH0MI" alt="" width="563"><figcaption><p>Image. View incidents that have auto-grouped alerts</p></figcaption></figure>

When you click the incident with auto-grouped alerts and head into the Details page, you can view all the grouped alerts under the **Auto Grouped** tab.

This tab houses all the alerts as deemed similar to this incident by the Intelligent Alert Grouping (IAG) analyzer with the below information for the alert:

1. Alert Title
2. Alert Source
3. Created At
4. Tags

<figure><img src="/files/WEwmR5cjE6y5F5zLbTLW" alt="" width="563"><figcaption><p>Image. View Auto Grouped Incidents</p></figcaption></figure>

By clicking the alert title, you will be able to view additional details for the alert.

<figure><img src="/files/iSUS1hspwyndarI1iAr3" alt="" width="563"><figcaption><p>Image. View alert details</p></figcaption></figure>

## Intelligent Alert Grouping (IAG) Analyzer

The Intelligent Alert Grouping (IAG) analyzer is designed to monitor real-time alert data and incident history. It adjusts dynamically as new alerts are triggered on a Service. Once you activate Intelligent Alert Grouping (IAG) for a Service, there's no need for explicit configuration, apart from selecting the Grouping Window itself.

Intelligent Alert Grouping (IAG) analyzer will group an alert into an existing open incident when the following criteria are met:

1. The most recent alert was created within the specified grouping window. This works on a rolling basis, i.e., we will compare the timestamp on the alert in question to the most recently grouped alert.
2. The Intelligent Alert Grouping (IAG) analyzer deems the alerts similar.

Alerts that do not meet these criteria will not be grouped and will trigger a new incident.

## Feedback Mechanism

Users can either vote up or vote down an auto-grouped alert by simply hovering over the alert in the list of alerts for the incident.

If you notice that an auto-grouped alert should not have been grouped with this incident, you can click the thumbs-down icon. This feedback once submitted, cannot be undone.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: When a vote down is given, it will not re-open the alert. It is simply feedback given to the Intelligent Alert Grouping (IAG) analyzer to not consider this association in the future. Users have to manually trigger an incident reflecting this alert to work on it.
{% endhint %}

<figure><img src="/files/nUCjNxiiqvGLorpy0S4a" alt="" width="563"><figcaption><p>Image. Feedback Mechanism</p></figcaption></figure>

* Not just vote downs, users can also let the Intelligent Alert Grouping (IAG) analyzer know that the right alerts were grouped with the incident in question. This can be done by clicking the thumb-up icon by hovering over the alert.
* Any feedback that is given by users is logged in the incident’s Activity Timeline.

<figure><img src="/files/xkQd3idSVLBLQ6FEKHCC" alt="" width="563"><figcaption><p>Image. Feedback logged in the incident activity timeline</p></figcaption></figure>

* Users can also provide implicit feedback by manually merging incidents. This behavior is captured by the Intelligent Alert Grouping (IAG) analyzer and is used for auto-grouping in the future.

## Disable Intelligent Alert Grouping (IAG) for a Service

1. Navigate to the Services tab. For the selected Service, click the **More** action and select **Edit Service**.
2. Here, you can disable the toggle for Intelligent Alert Grouping (IAG).

<div><figure><img src="/files/qeoAAFoLevCDf6i838y1" alt=""><figcaption><p>Image. Edit Service</p></figcaption></figure> <figure><img src="/files/kOm9fDmBaQ9SOR4hIp8H" alt=""><figcaption><p>Image. Disable IAG</p></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> Doing so will immediately stop the algorithm from being active, which means users can expect a high number of alert notifications reaching them (which would have not been the case previously).
{% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Auto Pause Transient Alerts (APTA)

Automatically pause notifications for transient alerts, giving time for them to auto-resolve before notifying responders.

The Auto Pause Transient Alerts (APTA) feature will detect alerts that typically auto-resolve within a short time period and it will temporarily pause notifications for such transient alerts.

During the pause period, new alerts will be viewable on the Incident List page in the Suppressed state with an icon to indicate transitoriness (refer to screenshot below). Users can choose to trigger these suppressed alerts during the pause period if these alerts are actually actionable. If a suppressed alert does not auto-resolve within the configured pause time period, APTA will trigger an incident and notify responders as per set Escalation Policies.

{% @storylane/embed subdomain="app" url="<https://app.storylane.io/share/y2ymk3e8npol>" linkValue="y2ymk3e8npol" %}

{% hint style="info" %}
Note: This feature will be available for accounts in the [<mark style="color:blue;">Enterprise plan</mark>](https://www.squadcast.com/pricing).
{% endhint %}

## What do we mean by transient alerts?

For Auto Pause Transient Alerts (APTA), a transient alert is an alert that typically auto-resolves via the configured alert source integration within a short time period of time from its trigger.

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark> Alerts that receive a resolve action made manually by a responder will not be classified as transient.
{% endhint %}

## How are alerts determined to be transient?

Data science techniques assess the frequency of similar alerts demonstrating transient behavior in the past. If an alert is frequently classified as transient, the Auto Pause Transient Alerts (APTA) system will suspend alert notifications for the pause period set for that given Service.

## Understanding the feedback mechanism

With Auto Pause Transient Alerts (APTA), users are not only benefiting from the reduced alert noise coming from transient alerts but are also being given the ability to make the feature more efficient by capturing feedback.

Users can give two types of feedback to Auto Pause Transient Alerts (APTA):

1. Letting Auto Pause Transient Alerts (APTA) know that a certain alert type needs to be flagged as transient going forward.
   * When a triggered alert is not flagged as transient, but it should have been, users can explicitly let the system know by clicking the **Mark Transient** action button on the Details page.\\

     <div><figure><img src="/files/9lcaNFXHtz9LWABCgw3f" alt="" width="563"><figcaption><p>Image. Marking an Incident as transient</p></figcaption></figure> <figure><img src="/files/Uk3JwsF3akDwtFW1mpIV" alt="" width="563"><figcaption><p>Image. Confirm action</p></figcaption></figure></div>
   * Once marked, this particular alert will not be considered as transient immediately. This is just to inform the system that future occurrences of similar alerts to this one must be flagged as transient.
2. Letting Auto Pause Transient Alerts (APTA) know that what was flagged as a transient alert is actually not transient.

   * This feedback is given to the system when the user clicks the **Not Transient** action button on the Details page of a transient alert.\\

   <div><figure><img src="/files/VyTJPGQ8F4RRxQ12JMrh" alt="" width="563"><figcaption><p>Image. Marking an Incident as not-transient</p></figcaption></figure> <figure><img src="/files/vVIVhMeZrNQYbEVUKBQJ" alt="" width="563"><figcaption><p>Image. Confirm action</p></figcaption></figure></div>

   * This feedback does 2 things:
     1. Instantly triggers an incident by moving the state from Suppressed to Triggered and the default Escalation Policy or specific Routing Rule targets of the affected Service is executed, notifying responders.
     2. Additionally, feedback is also sent to the Auto Pause Transient Alerts (APTA) system to not consider similar instances of this alert in the future as transient.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> The feedback provided by the users to the Auto Pause Transient Alerts (APTA) system may take some time (also means repeated feedback in some cases) to be fully effective.
{% endhint %}

## Enabling Auto Pause Transient Alerts (APTA) for a Service

### While creating a new Service

1. Navigate to the **Services** tab where you can start creating a new Service. Among other details given as inputs necessary for creating the Service, enable the toggle for **Auto Pause Transient Alerts (APTA)**.
2. Next, choose a **Timeout Window**. This is the time window (in minutes) for which an alert flagged as transient will remain in the Suppressed state. You can choose to proceed with the recommended time window or make a custom selection. The system recommends this time window based on the median TTR of past auto-resolved incidents for the Service.\
   \
   Such an alert can either be:
   1. Auto-resolved by the alert source integration within the time window, moving the alert to the Resolved state.
   2. Be triggered as an incident and moved to the Triggered state notifying responders if it was not auto-resolved by the alert source integration within the time window.
3. By clicking **Save and Continue**, you can proceed with Service creation which will result in immediate enablement of Auto Pause Transient Alerts (APTA).

<figure><img src="/files/5EcmKVoM8FmBNWcsJxVG" alt="" width="563"><figcaption><p>Image. Enable APTA while creating a new service</p></figcaption></figure>

### For an existing Service

1. Navigate to the **Services** tab -> For the selected Service, click the **More** action and select **Edit Service**.

<figure><img src="/files/AsVliDgdNlXNexPI6P2s" alt="" width="563"><figcaption><p>Image. Edit Service Details</p></figcaption></figure>

2. Here, you can enable the toggle for **Auto Pause Transient Alerts (APTA).**
3. Next, choose a **Timeout Window**. This is the time window (in minutes) for which an alert flagged as transient will remain in the Suppressed state. You can choose to proceed with the recommended time window or make a custom selection.

<figure><img src="/files/FnykyZbL0hdFjaXGnBip" alt="" width="563"><figcaption><p>Image. Enable APTA for an existing service</p></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> Auto Pause Transient Alerts (APTA) system uses heuristics to recommend the most suitable pause time window for the Service by looking at historical alerts that may have been transient in nature in the past.
{% endhint %}

## Disabling Auto Pause Transient Alerts (APTA) for a Service

1. Navigate to the **Services** tab -> For the selected Service, click the **More** action and select **Edit Service**.

<figure><img src="/files/NZH92b6xqZTTCMq77S5P" alt="" width="563"><figcaption><p>Image. Edit Service details</p></figcaption></figure>

2. Here, you can disable the toggle for **Auto Pause Transient Alerts (APTA**). Doing so will immediately stop the system from being active, which means users can expect a high number of alert notifications reaching them (which would have not been the case previously).

## FAQs

<details>

<summary><mark style="color:blue;">Do we need to create a new Service to enable this feature?</mark></summary>

No, that would not be necessary. Auto Pause Transient Alerts (APTA) can be enabled (and disabled) for any (existing / new) Service at any point in time.

</details>

<details>

<summary><mark style="color:blue;">I am unable to view the “Mark Transient” action button for my triggered alert. What am I missing?</mark></summary>

This happens when Auto Pause Transient Alerts (APTA) is not enabled for the Service for which the triggered alert has come in for. Squadcast checks for feature enablement while displaying allowed actions for an alert. You can simply head over to the Service details page and into the edit flow to enable this. Once done, you will be able to view the “Mark Transient” action button for the triggered alert.

</details>

<details>

<summary><mark style="color:blue;">All the feedback that is given by users for incidents for Auto Pause Transient Alerts (APTA), is there a log for us to view at a later point in time?</mark></summary>

Any feedback action by the users or even marking of an alert as transient, the alert is triggered by the system after the pause period if not auto-resolved, etc. will be captured within the Activity Timeline for that alert in real-time. Users can always view the Activity Timeline at any point in time to go through the logs.

Logs for Auto Pause Transient Alerts (APTA) in the alert Activity Timeline would include:

1. When alert is flagged as transient by Auto Pause Transient Alerts (APTA).
2. When a user gives feedback to consider a future occurrence of the alert as transient by Auto Pause Transient Alerts (APTA).
3. When a user gives feedback to not consider a future occurrence of the transient alert as transient by Auto Pause Transient Alerts (APTA).
4. When the transient alert is auto-resolved by the alert source integration.
5. Auto Pause Timeout Breach: When the transient alert completes the pause period and is not auto-resolved by the alert source integration and Squadcast triggers an incident and sends out notifications.

</details>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Delayed Notifications

Delay notifications outside of business hours and opt for a summary of pending incidents at the beginning of the next business hour.

With Delayed Notifications, you can defer the delivery of incident notifications during non-business hours by configuring Service business/working hours. Configured Users, Squads, or Escalation Policies will receive a comprehensive notification digest via Push and Email at the start of the next business hours. Stay in control of notification fatigue and optimize your communication flow with Delayed Notifications.

{% @storylane/embed subdomain="app" url="<https://app.storylane.io/share/y2ymk3e8npol>" linkValue="y2ymk3e8npol" %}

## Enable Delayed Notifications

### For a new Service

To enable Delayed Notifications while creating a new Service,

1. Navigate to the **Services tab** where you can start creating a new Service -> Enable the **toggle for Delayed Notifications.**
2. Next, define the **business/working days and hours** for this Service -> Select the **timezone** for the delay config to run in.
3. Select who should receive the notification digest at the start of the next business hour.
   * You can assign incidents to (and hence, notify) a User / Squad / Escalation Policy. If you want the default Escalation Policy for the Service to be picked, you can simply select that option.
4. That’s it. The assigned entity will receive the notification digest via Email and Push simultaneously at the start of the next Service business/working hours.

<div><figure><img src="/files/8J9wehfpIxQzuiEgvORp" alt=""><figcaption><p>Image. Create new service</p></figcaption></figure> <figure><img src="/files/mOZo4qKdq0mD6qra0m9q" alt=""><figcaption><p>Image. Configure delayed notifications</p></figcaption></figure></div>

### For an existing Service

To enable Delayed Notifications for an existing Service,

1. Navigate to the **Services tab**. For the selected Service, click the **More** action and select **Edit Service**.
2. Next, define the **business/working days and hours** for this Service -> Select the **timezon**e for the delay config to run in.
3. Select who should receive the notification digest at the start of the next business hour.
   * You can assign incidents to (and hence, notify) a User / Squad / Escalation Policy. If you want the default Escalation Policy for the Service to be picked, you can simply select that option.
4. Click **Save** and that’s it. The assigned entity will receive the notification digest via Email and Push simultaneously at the start of the next Service business/working hours.

<div><figure><img src="/files/pcvJtjGjeHW02AsSIrI5" alt=""><figcaption><p>Image. Edit service</p></figcaption></figure> <figure><img src="/files/HjwgdaBWI9S3ShwTJfX0" alt=""><figcaption><p>Image. Configure delayed notifications</p></figcaption></figure> <figure><img src="/files/mi9U2GbBJzXy4rAA6A9U" alt=""><figcaption><p>Image. Save configuration</p></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

1. All users in the selected Escalation Policy will simultaneously receive a notification digest via Email & Push at the start of the next Service working hours. Please note that escalations will not be followed in the traditional sense of regular incident notifications.
2. Delayed Notifications will not work for incidents that are manually created. The configuration setup will work only for incidents created via email and webhook integrations.
   {% endhint %}

## Disable Delayed Notifications

If for any reason you want to set your Service business/working hours as “all time”, then simply disable the toggle. With this, for any new incoming incident, notifications will be sent out to the default assigned entity (User, Squad, or Escalation Policy).

<figure><img src="https://lh7-us.googleusercontent.com/Rk-1tGDmNnLJGwnvw7NjI2SsNeBos4vmvvGfnhYGdABLaHYyGA64hJ5sy4kYBieOcXeL_Ql7FE4Fi9m_DTIbNSK-ZyqTveGyGZbV9fD4UI3nrmetVTyIbn-mk7yLNCazBiBmcsbzPRD1qqk-_Ac8KbE" alt="" width="375"><figcaption><p>Image. Disable Delayed Notifications</p></figcaption></figure>

## View Delayed Incidents <a href="#view-delayed-incidents-on-the-incident-list-page" id="view-delayed-incidents-on-the-incident-list-page"></a>

When Delayed Notifications is enabled for a Service, and notifications are delayed for incidents of that Service, you can identify those incidents in the Incident List with the help of the highlighted icon in the image below.

<figure><img src="/files/xAi66GPLzLziw8mr5SMz" alt="" width="188"><figcaption></figcaption></figure>

For an incident that came in during the non-business hour, its Activity Timeline will indicate:

1. Until when the notifications for this incident are delayed (which is the same as the start of the next business hour).
2. Who this incident will be assigned to (and hence, notified) at the start of the next business hour.

<figure><img src="/files/OwQA9fpUgt70vg9ojMfp" alt="" width="188"><figcaption></figcaption></figure>

## Notification Digest

The digest notification for delayed incidents will be sent to the assigned entity (User, Squad, Escalation Policy) at the start of the next business hour via Push and Email.

{% tabs %}
{% tab title="Push" %}
Here is an example of a Push notification digest:

<figure><img src="https://lh7-us.googleusercontent.com/VFW6or2__XWCjivd8RKf1ej76GZKytpLwd6uVnjuY6bOmnVXC9dyOffpUJPBr8F2rRHJ5lGjBO2q6xI5X3wZtPsuZ8lzbHzoqgdBOmbhXsbkOL8QcS8DgipRJRrqtmt5XLT3us_6dmwUw-kWAu4O3kk" alt="" width="188"><figcaption></figcaption></figure>
{% endtab %}

{% tab title="Email" %}
Here is an example of Email notification digest:

<figure><img src="/files/NrQdcmnmN48xTGEVAIzX" alt=""><figcaption></figcaption></figure>

<figure><img src="https://lh7-us.googleusercontent.com/AM2mZqdRGLZN7mBnb-FYLylGypoiy-g58iUIBubdy1hbLihcfTJ61OOaESR9GR0iIkU01QBMkGz-h18MVR3D7jF0HI8crWvCVRaJX2z5QNyj0Wn9Nm1ZODfWzh3J8p8swrBtG6V6uVwQM0vYOvJBvdM" alt="" width="563"><figcaption></figcaption></figure>
{% endtab %}
{% endtabs %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Schedules (Legacy)

We have released a new version of Schedules.

## **What’s new?**

A ground-up revamp of Schedules with a completely new UI and improved UX, along with new features added.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>:\
This is a phased release. All the new users will experience the new Schedules while our old users will be gradually moved from their existing Schedules set up to the new ones.
{% endhint %}

{% hint style="success" %} <mark style="color:green;">**Terms Used**</mark>**:**\
\
**Schedules (Legacy)** - Refers to the old version.\
**Schedules (New)** - Refers to the new version.
{% endhint %}

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>:\
\
Schedules (Legacy) will be deprecated for existing users post-migration into Schedules (New). For more queries, please reach out to our [<mark style="color:blue;">Support Team</mark>](mailto:support@squadcast.com).
{% endhint %}

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><mark style="color:blue;"><strong>Schedules (Legacy)</strong></mark></td><td></td><td>If you’re looking for documentation on Schedules (Legacy), click <mark style="color:blue;">here</mark>.</td><td><a href="/pages/h4czUM4gPF7xPTV0HI4Z">/pages/h4czUM4gPF7xPTV0HI4Z</a></td></tr><tr><td><mark style="color:blue;"><strong>Schedules (New)</strong></mark></td><td></td><td>If you’re a new user or looking for documentation on Schedules (New), click <mark style="color:blue;">here</mark>.</td><td><a href="/pages/ZDIldG8nvyLFBI5LeVs4">/pages/ZDIldG8nvyLFBI5LeVs4</a></td></tr></tbody></table>


# Create and Manage On-Call Schedules

Create and manage on-call schedules and rotations for your team, using Squadcast.

{% embed url="<https://www.youtube.com/watch?v=POEKe2x2Mco>" %}

### Creating an On-call Schedule <a href="#creating-an-on-call-schedule" id="creating-an-on-call-schedule"></a>

Ensure that the right Team is selected from the team picker present at the top.

1. Click on **Schedules** in the primary navigation

<figure><img src="/files/BlFfsi6fhMLlfbXLqWhJ" alt="how to create an On-call schedule in Squadcast"><figcaption></figcaption></figure>

2\. Click on **Add Schedule** on the right-hand side of the screen

<figure><img src="/files/jPAErKrgxDu35hcbzDTY" alt="how to create and manage an On-call schedule in Squadcast"><figcaption></figcaption></figure>

3\. Enter the following information:

* **Schedule Name**: Give the schedule a name which you can use while adding the on-call schedule to the calendar
* **Schedule Description**: This is a short description of the schedule explaining what it is and why it exists
* **Schedule Color**: You can also set a colour for a specific schedule, which will be used while rendering the on-call on the calendar

![On-call schedule name, description and color in Squadcast](/files/J0uhgWyyHVSayRyTgrdA)

4\. Pick **any day** of the calendar by clicking on it, to create an on-call shift starting from that day. You can also drag your cursor from one day to another, to automatically set the **Start Date** and **End date**

<figure><img src="/files/tM608e5TBQidwoSsxnG7" alt="Pick start and end date for an on-call schedule in Squadcast"><figcaption></figcaption></figure>

5\. **Shift Name** indicates the name of the particular *Shift* being set up within the Schedule. This is a mandatory field and the user needs to enter a value for this before proceeding further.

![Set a shift name in Squadcast](/files/RPmVcLfSC9py7pZm9GcZ)

6\. Choose the **Schedule** you want to create this on-call shift for, from the drop-down

![Choose the Schedule to create on-call shift in Squadcast](/files/kZG6WwGiOylw3eDjG7Vm)

7\. Input the **Start date**, **Start time**, **End date** and **End time** to determine when the shift begins and when it ends respectively

![create an on-call shift starting time and end time in Squadcast](/files/PYiO6japRsQs3iOIgQ1B)

{% hint style="danger" %}
Do not check the <mark style="color:red;">`Is Override`</mark> box if you want to create a normal shift.
{% endhint %}

8\. **Repeats**- Repetitions can be daily, weekly or monthly. You can also restrict the schedules to specific times of the day or during specific days of the week, based on your need

Now, choose the appropriate option:

* **Everyday** - Use this to create a daily schedule (applicable for all 7 days of the week)

![On-call repetition daily schedule in Squadcast](/files/4ZgCXarqcEz8BbdzquSf)

* **Weekly – Once a week** - Select this option to create a schedule that occurs only on one day of the week. You can select the day on which this shift will be active

![On-call repetition one day of the week in Squadcast](/files/fyGkWCTu7NWEDsvtnR51)

* **Weekly – Particular Days Of a Week** - Select this option to create a schedule that occurs on particular days of the week. You can select the days on which this shift will be active

![On-call repetition Weekly – particular days of a week in Squadcast](/files/pd49nQTDMCqqIYOTRZ0f)

* **Custom** - Select this option to create any other custom shift of your choice. You can customize the number of days/weeks/months you want the on-call to repeat for

![](/files/E30Me1J3cFDNTczFnL0b)

{% hint style="info" %}
To create a *recurring schedule*, mark **Ends** as **Never** (enable the checkbox). **Never** is enabled by default. If you do not want a recurring schedule, disable the checkbox and specify the end date.
{% endhint %}

9\. Add in the users who would be on call for this shift under the **Assignee Groups** section. Each group behaves as a different rotation. Use **Add Group** to add multiple such groups

![](/files/A4z0JmUjQH3EFTTK5P4E)

{% hint style="info" %}
Adding **Squads** within an **Assignee Group** would mean every member of the Squad is on-call based on the shift defined. Squadcast does not pick members one by one from within a Squad and **rotates** between them. For a rotation to happen *between 1 or more entities (Users or Squads)*, add them to different Assignee Groups instead.
{% endhint %}

10\. Select the number of shifts after which you want to switch between the Assigned Groups

**Example 1**: <mark style="color:red;">`Buzz Lightyear`</mark> is part of the <mark style="color:red;">`#1 Group`</mark> and <mark style="color:red;">`Charlie Stark`</mark> is part of the <mark style="color:red;">`#2 Group`</mark>.

* If **Every Shift** is chosen then <mark style="color:red;">`#1 Group`</mark> and <mark style="color:red;">`#2 Group`</mark> would be on-call on alternate days
* If **Every 7 Shifts** is chosen then <mark style="color:red;">`#1 Group`</mark> would be on-call the first 7 days and <mark style="color:red;">`#2 Group`</mark> would be on-call the following 7 days and so on

![Switch assigned group in on-call schedules](/files/EdjPumIicnt3EgoPjpJm)

11\. That’s it! Click on **Create** to save the schedule

{% hint style="info" %}
**Adding Schedules to Escalation Policies**

You will need to add a Schedule to an Escalation Policy for the on-call users to be notified when an incident is triggered for a Service
{% endhint %}

### Gaps in your Schedule <a href="#gaps-in-your-schedule" id="gaps-in-your-schedule"></a>

It is important to ensure that there are no gaps in your Schedules.

* If you have any gaps in your Schedules configuration, the system will prompt the banner **You have gaps in your schedule** right above the Schedules calendar view
* To know more details about the gaps, you can click on the **You have gaps in your schedule** banner and it will show you the name of the Schedule along with the date and time during which the gap has been detected

![Gaps in on-call schedule](/files/aLbQNLgVoGDzF4dMBU6B)

### Manage an Existing On-call <a href="#manage-an-existing-on-call" id="manage-an-existing-on-call"></a>

#### Update <a href="#update" id="update"></a>

1. Select an existing on-call by clicking over any assigned User/Squad on the calendar

<figure><img src="/files/VlCdf67oNwYvoBp2jtej" alt="Update your on-call schedule"><figcaption></figcaption></figure>

2\. Click on **Edit**

3\. Select the appropriate **Update method**:

![update on-call shift in Squadcast](/files/pnqvcjmzKxQeMAFEcn7U)

* **This Event Only** - to update only that particular event When this choice is made, you will not see the option to *Repeat* as this is considered a one-off necessity to update. Also, this will only show the assignees of the current event picked for the update
* **This and proceeding events** - to update the selected event and all the events that come afterwards

In the last two **Update methods**, the modal shows the **Repeats** checkbox and also, shows all the Assignee Groups in the series.

{% hint style="danger" %}
You cannot update past events as it is meant to serve as an accurate record of the past on-call Schedule.
{% endhint %}

#### Choosing a different starting Group <a href="#choosing-a-different-starting-group" id="choosing-a-different-starting-group"></a>

Starting Group determines the Group that starts the defined Rotation. This can only be defined when the update method chosen is **This and the Following Shifts** option is selected in the update method.

![Choose different starting group of an On-Call Schedule](/files/llWfrNaRIGDsqcdtIa2g)

{% hint style="info" %}
**Note:**

By Default #1 Group will be the starting Group.

<img src="/files/3HVEgL5Lf3Zx4cJXrHQ4" alt="default group for on-call schedule in Squadcast" data-size="original">
{% endhint %}

### Deleting an On-call <a href="#deleting-an-on-call" id="deleting-an-on-call"></a>

1. Delete an existing on-call by clicking the **Delete** button at the bottom right corner of the **Update on-call shift** dialogue box

![How to delete an on-call schedule](/files/zPRIbsNWdR9NkacXJRFP)

2\. Choose the appropriate option:

* **This event only** - It will delete only the selected event of the series
* **This and proceeding events** - It will delete the event selected as well as all the future events belonging to that series

![](/files/1iXGntCs3wQGwgdZDlwe)

### FAQs <a href="#faqs" id="faqs"></a>

**Q:** How can I add users in different time zones to the Schedule?

**A:** The selected timezone will default to the local machine timezone. This is especially beneficial for geography-based on-call rotations. The Team members will be able to view any created on-call schedule in their local time.

**Q:** Can I send on-call reminder notifications?

**A:** Yes, users can choose to receive on-call reminder notifications ahead of their shifts. They can set this up according to their preference as mentioned [<mark style="color:blue;">here</mark>](https://support.squadcast.com/docs/oncall-reminder-rules). If a created override shift has less than the time specified to begin, the notification will go out immediately after the override creation.

**Q:** Why cannot Stakeholders be added to the on-call Schedules?

**A:** *Stakeholders or Users with Observer roles* are read-only users in Squadcast. Hence they cannot be added to an on-call schedule. When you try adding them you would see an error message as shown below.

<figure><img src="/files/e7VLvBhHtYvijyOnubAF" alt="Stakeholders can not be added to an on-call schedule"><figcaption></figcaption></figure>


# Who is On-Call?

Find out who is on-call at any given instant

This document will help you understand how you can find out who is on call at any given instant.

### On the Squadcast Web App <a href="#on-the-squadcast-web-app" id="on-the-squadcast-web-app"></a>

* At any given point, you will be able to see the current on-call users on the top right corner of your screen

![Which user is currently on-call in Squadcast](/files/B3H40fTpndXO8rDaAHgk)

* You can click on the **On-call** icon to see the Schedule name and the on-call engineer is associated with

![Details of current on-call user in Squadcast](/files/LdTqo3k3rOSg1L7Myoc4)

* Click on the on-call engineer’s name to see their Profile, Schedules, Squads and Escalation Policies that they are a part of

<figure><img src="/files/jyH7z4iXYSkAjpJr93et" alt="View Profile Page of current on-call engineer in Squadcast"><figcaption></figcaption></figure>

### View On-Call Schedules on the Web App <a href="#view-on-call-schedules-on-the-web-app" id="view-on-call-schedules-on-the-web-app"></a>

You can click on **Schedules** from the left side navigation sidebar to view the ongoing and upcoming schedules along with shift length and details of members on the shift.

The platform provides multiple views of your on-call calendar - monthly, weekly, daily and list formats.

#### On-call Schedules: Monthly View <a href="#on-call-schedules-monthly-view" id="on-call-schedules-monthly-view"></a>

<figure><img src="/files/taUKQD4wkF3dgYAM0KKW" alt="Monthly View of an On-Call Schedule"><figcaption></figcaption></figure>

#### On-call Schedules: Weekly View <a href="#on-call-schedules-weekly-view" id="on-call-schedules-weekly-view"></a>

<figure><img src="/files/OqcaEFhgK8gyqddSuldD" alt="Weekly View of an On-Call Schedule"><figcaption></figcaption></figure>

#### On-call Schedules: Day View <a href="#on-call-schedules-day-view" id="on-call-schedules-day-view"></a>

<figure><img src="/files/wwUJqgidL1VOPc9gfRbG" alt="Daily View of an On-call Schedule"><figcaption></figcaption></figure>

#### On-call Schedules: List View <a href="#on-call-schedules-list-view" id="on-call-schedules-list-view"></a>

You will be able to view a list of people with their on-call timings for the next 30 days.

<figure><img src="/files/Xt9szpvSHFobDfbGSPMO" alt="List View of an On-Call Schedule"><figcaption></figcaption></figure>

### View Schedules on the Mobile App <a href="#view-schedules-on-the-mobile-app" id="view-schedules-on-the-mobile-app"></a>

Click on **Schedules** from the left side navigation sidebar to view the ongoing and upcoming schedules along with shift length and details of members on the shift.

<div><figure><img src="/files/Kr1KVxUqPvikd62GNAWb" alt="View Schedules in the Mobile App"><figcaption></figcaption></figure> <figure><img src="/files/CFEGg5JTnLDDIV3CIgcM" alt="View On-Call Schedules in the Squadcast App"><figcaption></figcaption></figure></div>


# My On-Call Shifts

My On-Call Shifts allows users to view their shifts across all Escalation Policies and Schedules in a single, easy-to-use view

My On-Call Shifts displays whether a user is on call now, a list of their associated shifts and what their upcoming schedule looks like. This feature is available as a widget in the Profile Page. You can also view the on-call shifts of other users by navigating to their Profile Page.

### My On-Call Shifts in the Profile Page <a href="#my-on-call-shifts-in-the-profile-page" id="my-on-call-shifts-in-the-profile-page"></a>

<figure><img src="/files/ES2sjQ8WszI3TML5c0xQ" alt="View My-Call Shifts Widget in Squadcast"><figcaption></figcaption></figure>

To access the My On-Call Shifts widget:

1. Navigate to the **Profile Page** from the top right corner of the screen -> My On-Call Shifts.

The following information is displayed here:

* **Time**: The time for which you are on-call
* **Name**: The name of the Schedule you’re on-call for
* **Users**: The users who are on-call along with you

### On-Call Filtered Views <a href="#on-call-filtered-views" id="on-call-filtered-views"></a>

You can view the on-call shifts for today, this week, and any custom range you select.

![Filter views of My On-Call Shifts in Squadcast](/files/P9bjgxWI3RBeYRkf19X7)

### View Another User’s On-Call Shifts <a href="#view-another-users-on-call-shifts" id="view-another-users-on-call-shifts"></a>

Go to Settings -> Users and select another User to visit their Profile Page. Select the On-Call Shifts tab.

<figure><img src="/files/T0d6EEldRal4nRB5KgDU" alt="View another user&#x27;s on-call shift widget in Squadcast"><figcaption></figcaption></figure>


# Schedule Overrides

This feature allows you to create schedules which will override your normal schedules

Make one-time adjustments to existing on-call schedules and help on-call engineers with planned vacations, unplanned illnesses, or other events that happen during their on-call shifts. This way, only the users in override schedules will get notified of incidents during the scheduled time period.

### Creating a Schedule Override <a href="#creating-a-schedule-override" id="creating-a-schedule-override"></a>

Ensure that the right Team is selected from the team picker present at the top.

**(1)** Click on **Schedules** in the primary navigation

<figure><img src="/files/TLn012WiOuqV8ZFeFzgD" alt="How to create on-call schedule override in Squadcast"><figcaption></figcaption></figure>

**(2)** On the calendar, click on a date or drag over the date(s) on which you’d like to create the override shift

<figure><img src="/files/jVVJnr1bUjc5Sh8MhW62" alt="How to create on call override on call shift in squadcast"><figcaption></figcaption></figure>

**(3)** Select the Schedule for which this override shift will be implemented from the dropdown

![Select the schedule for which this override shift in Squadcast](/files/6Vm9mpBnJzCkfRBoc7qr)

**(4)** Fill in the Override Shift details i.e. Start date, Start time, End date and End time

![Override Shift details i.e. Start date, Start time, End date and End time](/files/sQFLH3lrhGHNOmX5Dl0e)

**(5)** Check the **Is Override** box

![Check the Is Override box in Squadcast](/files/TzCb1VQ02T6bSKxsyvRc)

**(6)** **Optional** - Fill in the repetition configuration as per the requirement

![How to configure repeats for override shifts in Squadcast](/files/cLj3kw3EIxJCRk7k55RD)

**(7)** Add the User(s) who would take over the shift

![How to add user for override shifts in Squadcast](/files/uS14027szeIxATqs1bx4)

**(8)** Click on **Create** to save this as an override shift. The Override shift would be displayed for the selected date(s)

<figure><img src="/files/IxGpL48IHHW2rB9J9b3M" alt="Create to save this as an override shift in Squadcast"><figcaption></figcaption></figure>

#### Points to note about Scheduled Overrides <a href="#points-to-note-about-scheduled-overrides" id="points-to-note-about-scheduled-overrides"></a>

* Creating an override shift is identical to normal shifts, except for the fact that they are marked as **Override**
* If an override shift overlaps with one or more shifts in the same on-call schedule, **only the assignees in the override shift are notified**
* If an override shift does not overlap with any other shift, it behaves like a normal shift. It will still be marked as an **Override**. If a new normal schedule is created during an existing override shift period, the override shift will continue to override the new schedule for the scheduled override period
* If two or more override shifts overlap, assignees from all of the override shifts will be notified when an incident is triggered


# Videos - How to set up common use-cases?

### Business and Non-Business Hours <a href="#business-and-non-business-hours" id="business-and-non-business-hours"></a>

{% embed url="<https://squadcast.wistia.com/medias/g4x9xq01q5>" %}

### Daily Schedule <a href="#daily-schedule" id="daily-schedule"></a>

{% embed url="<https://squadcast.wistia.com/medias/tqxirigv8n>" %}

### Weekly Schedule <a href="#weekly-schedule" id="weekly-schedule"></a>

{% embed url="<https://squadcast.wistia.com/medias/rcnj6dw486>" %}

### Weekend Schedule <a href="#weekend-schedule" id="weekend-schedule"></a>

{% embed url="<https://squadcast.wistia.com/medias/0ug7v033ez>" %}

### Daylight Saving Changes <a href="#daylight-saving-changes" id="daylight-saving-changes"></a>

{% embed url="<https://squadcast.wistia.com/medias/722f2bb7xq>" %}

### Override Schedules <a href="#override-schedules" id="override-schedules"></a>

{% embed url="<https://squadcast.wistia.com/medias/a6l9mrunu9>" %}


# Schedules

Enhance incident response with effective on-call scheduling. Connect services to on-call schedules, ensuring timely notifications and streamlined incident resolution.

An **on-call rotation / schedule** is essential for effective incident management, ensuring trained personnel are always available to resolve issues. This involves setting clear schedules to distribute workload evenly, considering factors like time zones and expertise to prevent burnout. Utilizing automated tools like Squadcast helps manage complex rotations and escalation paths, ultimately reducing incident resolution times and maintaining service availability around the clock.

***

**Best practices** are crucial for maximizing an on-call system's effectiveness. This includes establishing clear [escalation policies](https://support.squadcast.com/escalation-policies/create-and-manage-escalation-policies), thorough documentation for common issues, and regular training. Fostering continuous improvement, providing robust monitoring and alerting tools, and prioritizing engineers' well-being are key to a sustainable and efficient on-call program.

***

The **advantages** of a well-executed on-call system like Squadcast, are significant. It guarantees **24/7 coverage** if needed, and rapid incident response, minimizing downtime and boosting customer satisfaction. This approach fosters shared responsibility within the team, improves knowledge sharing, and leads to a more resilient system. By proactively managing incidents, organizations can turn challenges into opportunities for system enhancement.


# Adding a Schedule

Create and manage on-call schedules and rotation for your team, using Squadcast.

An On-call Schedule is a staff rota that defines which team members are available to handle incoming incidents at all hours of the day/night.

When an incident impacts a Service, notifications are sent to the user mentioned in the Service’s Escalation Policy. These users will be the first contact when dealing with issues such as major bugs, capacity issues, or product downtime.

With Squadcast, a default schedule is automatically created when an account gets created.

## Prerequisites

* The User Role associated with the user in the Team must have required permissions to manage Schedules.

## Create a Schedule

To create an on-call schedule,

Navigate to **Schedules** -> **Add Schedule**. On the next screen, you will be guided through three creation steps. Navigate between these steps by clicking on any of the steps on the top bar.

### 1. Add Schedule Details

Enter the **Name**, **Timezone**, **Owner**, **Tags**, and an optional **Description** for the schedule.

#### How to pick a Time Zone?

Each schedule can be configured for a specific timezone. Helps in the case of a distributed team to ensure you get the shift timings right. Add a tag for the timezone to any schedule to denote which timezone is affected by the schedule, such as L1 APAC On-call.

#### How do Schedules adapt to Daylight Savings Time (DST) changes across the world?

* Our system handles the changes corresponding to the start and end of DST for the time zones that it is applicable for.
* Rotation shifts and Gaps get re-calculated and displayed accordingly.
* No user intervention is expected for manual changes corresponding to DST

In case any observation needs to be reported that does not adhere to the points above, do reach out to us at <support@squadcast.com>

#### How to pick an Owner?

A schedule owner is someone who can be contacted to understand, modify or delete the Schedule.

{% hint style="info" %}
**Note:**\
By default, the user who creates the Schedule is it's owner. You may change it using the drop-down.
{% endhint %}

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 You can assign a user or a squad as a schedule owner.

🔹 **Best Practice Tip** 🔹 Give your schedules meaningful names that reflect the pattern it follows (24x7, Business, Non-Business, Weekend), the team it is defined for (24x7 L1), and the timezone it affects (L1 APAC on-call).
{% endhint %}

#### How to use Tags?

Use tags to organize, classify and add context to your schedules. Adding tags such as Type: 24x7 Business, Environment: Prod, and Team: 24x7 L1 can help structure and add more context to your schedules.

<figure><img src="/files/D5o4CB4PnsQZmWp2VocP" alt=""><figcaption></figcaption></figure>

Click **Next: Choose Rotation Template**, and navigate to the next step.

### 2. Choose a Rotation Pattern

Next, choose a rotation pattern from the predefined templates listing some of the most common use cases, or you can set up rotations from scratch using the **Add one or more custom rotations or events** option.

By default, the Daily 24x7 rotation is selected for a schedule.

{% hint style="info" %}
**Note:**

If you want to add one-off stand-alone on-call events or a custom template, then, add a custom event and configure the same in the next step.
{% endhint %}

{% hint style="info" %}
**Note:**\
You can change rotation timings & add users in the next step.
{% endhint %}

<figure><img src="/files/VGMZ6fW0r8Jo1U6nSyhj" alt=""><figcaption></figcaption></figure>

Click **Next: Customize Rotation Pattern**, and navigate to the next step.

### 3. Customize Rotations

* **Add Participants**: Enter the participant groups in the order of the rotation. Add more participant groups using the **Add participant group** button.\
  \
  Each participant group contains one or more users or squads. The rotations happen across participant groups, not within each group's participants.

  \
  To reorder participant groups, you can simply drag and drop and the changes will be reflected in the preview.
* **Start Date**: Enter the **Start Date** of the rotation.
* **Repeats**: Repetitions can be daily, weekly, monthly, or custom. You can also restrict the schedules to specific times of the day or during specific days of the week, or month based on your need.\
  \
  Now, choose the appropriate option:
  * **None** - Use this to create a stand-alone event. (Note: This is not an override, overrides can be set up separately).
  * **Daily** - Use this to create a daily schedule (applicable for all 7 days of the week).
  * **Weekly** - On-call repeats every day, weekly
  * **Monthly** - On-call repeats every day, monthly
  * **Custom** - Use this to create any other custom shift of your choice. You can customize the number of days/weeks/months you want the on-call to repeat.
    1. On-call repeats once every few days
    2. On-call occurs and repeats on the selected day(s), weekly. Additionally, time intervals (via slots) can be defined, to define the active on-call hours for the chosen day(s)
* **Change Participants**: You can change participants according to the repeat rotation function, i.e., change participants for every new rotation
* **On-call Start and End Time**: Select the Start and End Time for the rotation. This period can span a maximum of 24 hours. This means that the on-call start time can be 9 PM the current day till 9 PM the next day. If the schedule extends into the next day it's represented by a "+1". Users also have the option to manually enter the time range.

  \\

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: You can edit both the On-Call Start and End Time using the dropdown.
{% endhint %}

* **On-call hours/ Day**: Select the number of hours you want this rotation to be on-call per day.

{% hint style="info" %}
**Note:**

On-call Start and End Time and On-call hours/day fields are available for configuration only for repetition options other than “Custom” are selected by the user. When “Custom” is chosen, these parameters will be configured within the specific options chosen.
{% endhint %}

* **End Date**: Add the End Date for the rotation. You can choose from:
  1. **Never** - this rotation never ends
  2. **On** - this rotation ends on the selected date
  3. **After** - this rotation ends after repeating the specified number of times
* **Rotation Name**: Enter a name for the rotation.
* **Rotation Colour**: Choose a color for your rotation. By default, each of the rotations of every schedule has a color selected (as shown in the preview). Users can choose other color options via the color picker to distinguish between rotations in the schedule.

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Keep your rotations as simple as possible, preferably with a continuous rotation of the same users to make your on-call schedule easy to manage.

🔹 **Best Practice Tip** 🔹 You can leverage scheduled overrides to address holidays or schedule conflicts.
{% endhint %}

<figure><img src="/files/xLeeG0H8JQpdhf70h7RB" alt=""><figcaption></figcaption></figure>

Click **Save** to complete creating the Schedule.

{% hint style="warning" %}
**Important:**

Add the Schedule to an Escalation Policy to activate it.
{% endhint %}

## Gaps in your Schedule

It is important to ensure that there are no gaps in your Schedule.

You will be able to view gaps both in the creation flow and on the details page of the Schedule, just use the **View Gaps** toggle.

The Schedule view will show red highlights for all identified gaps in the Schedule. You can consequently make edits to your On-call Schedule.

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Use the View Gaps toggle during Schedule creation to ensure there are no gaps.
{% endhint %}

## Pause a Schedule

Sometimes you might want to stop using a schedule without deleting it.

For example:

* The schedule is a draft that you are not ready to implement.
* The schedule is only used for particular occasions, such as on-call shadowing.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> Paused schedules are marked grey and they are only shown in the 2-week view.
{% endhint %}

To pause your schedule,

1. Navigate to **Schedules** -> Click on the **Pause Schedule** icon, against the schedule you wish to pause.
2. Click **Pause**. Your Schedule has been halted until you resume it again.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> To resume a halted On-Call Schedule, click on the same button and Click Resume.
{% endhint %}

<figure><img src="/files/JAg8PfMO044lCQ8a6JY8" alt="Pause a Schedule in Squadcast for Incident Management" width="563"><figcaption><p>Pause a Schedule</p></figcaption></figure>

## Export a Schedule

You can sync your Squadcast schedule with other calendar tools you use such as Outlook, iCal, and Google Calendar. You can sync either your individual on-call schedule or the entire on-call schedule.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> For any changes that occur in your schedule, we recommend that users generate a new export link and add it to their respective calendar app.

Please be aware that overriding or modifying schedule changes may take up to 24 to 48 hours in your calendar app, a process beyond Squadcast’s control.
{% endhint %}

To sync Squadcast schedules with your calendar tools,

1. Navigate to **Schedules** -> Click on the **Export Schedule** icon, against the schedule you want to export.
2. Choose between exporting your own on-call schedule or the entire on-call schedule -> A Calendar link will be available, which can be copied and used in the calendar app of your choice.

<figure><img src="/files/fY55TRQhf280knmlFVH7" alt="Export a Schedule in Squadcast for Incident Management" width="563"><figcaption></figcaption></figure>

## Clone a Schedule

Cloning an existing schedule to make a new one with the same users and settings is an easy way to create new schedules at scale.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> The cloned schedule will display both the date and time when it was cloned, along with the name of the schedule. You can always choose to edit the schedule name.
{% endhint %}

To clone a schedule,

1. Navigate to **Schedules** -> Click on the **Clone Schedule** icon, against the schedule you wish to clone.
2. A copy of the schedule you cloned with a toast message indicating the same.

<figure><img src="/files/uGTvOiorOqngBZ3u4lC6" alt="Clone a Schedule" width="563"><figcaption></figcaption></figure>

## Edit participants of an existing schedule

### Add users to an existing schedule:

1. Navigate to **Schedules** -> Click on the **Edit Participants** icon against the schedule you wish to add users to.
2. Add users to the Schedule using the **type participant’s name** option.

You can reorder the participants of the schedule using the **drag icon** against the participant name.

### Remove users from an existing schedule:

1. Navigate to **Schedules** -> Click on the **Edit Participants** icon against the schedule you wish to add users to.
2. Hover over the participant group, click **Edit** -> Remove the participants individually, and click **Save**.

<figure><img src="/files/LBfRx2VcfXp3RHqcxjWF" alt="" width="563"><figcaption></figcaption></figure>

## Edit Rotations

To edit rotations,

1. Navigate to **Schedules** -> Click on the **Edit Rotations** icon, against the schedule you wish to edit.
2. Edit the details of the rotations of the schedule selected -> Click on **Save**.

<figure><img src="/files/rC4k1ra5CSzapu37tq5H" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

1. Schedule Start Date Dependency:
   * The Schedule Start Date depends on the Rotation Start Date.
   * In cases of multiple rotations within a Schedule, the Schedule Start Date is determined by the earliest Start Date among the rotations.
2. Rotation Start Date Modification:
   * Changes in the Start Date of a rotation affect only that specific rotation.
   * For rotations with altered Start Dates, events will be deleted and re-populated based on the newly selected Start Date.
   * Other rotations and their events remain unchanged.
3. Override History:
   * The history of overrides is preserved, regardless of whether the Start Date is edited.
   * Overrides, once created, are not deleted, ensuring a comprehensive historical record.
     {% endhint %}

## Delete a Schedule

You can delete a schedule if it is no longer needed.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> If a schedule is referred to in an escalation policy, users will be required to substitute it with another user, squad, or schedule to maintain the continuity of the escalation process

If the schedule is not linked to any escalation policy, deleting a schedule is a one-step process.
{% endhint %}

To delete a schedule,

1. Navigate to **Schedules** -> Click on the **Delete Schedule** icon, against the schedule you wish to delete.
2. Click on **Delete**. Your Schedule will be deleted.

<figure><img src="/files/DaSLCCYkER9rBJuUOW56" alt="" width="563"><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Schedules Overview

Use Schedules Overview to drill into relevant information and perform actions on schedules.

The Schedules Overview provides a list of every Schedule where users can see at a glance who is currently on-call, what Escalation Policy the Schedule uses, and upcoming shifts. Users can filter all schedules by date range, participants, and escalation policies, and they can easily search and compare schedules.

## Parameters

### Date

To filter all schedules in the list by date, you may use the following options:

1. Click the Time Period dropdown to select one of the following:
   * 2 weeks View
   * List View
   * Month View
2. Click the **<** button to move back an iteration of the time period (specified above), or click the **>** button to move forward an iteration of the time period.\
   \
   For example, if you selected 2 Week from the Time Period dropdown, clicking **>** would move you forward by two week.
3. Click Today to view all schedules from today’s date.

<figure><img src="https://lh7-us.googleusercontent.com/8LfKfCK-LRbqg1OPD4G8C9aR70QscRJxyoPIBPE1q9_qn1glt56GepHqDa2GdNFBIS68mLxpZyAA0yQtwKgXMyAC1gJ1nj2vwuOwbr6awKBDqVn3iXBgnS6yF2m_CvsLkyp6L_1oMYhHQhhaRVgJHQc" alt="" width="563"><figcaption><p>Filter schedules by date</p></figcaption></figure>

<table><thead><tr><th width="207.33333333333331">View Type</th><th>Descirption</th><th>Image</th></tr></thead><tbody><tr><td>2 Weeks</td><td>It is a 2-week grid view of all the Schedules in the timezone associated with the Schedule's timezone.</td><td><img src="/files/EKojwbja8LlRksrO5kvt" alt=""></td></tr><tr><td>Month</td><td>It is a month-wise view of all the Schedules in the timezone associated with your profile.</td><td><img src="/files/Y704VBqHo4K2Mh5vGbIB" alt=""></td></tr><tr><td>List</td><td>It is a list view of all the Schedules in the timezone associated with your profile.</td><td><img src="/files/6DieO6ew5Ct8DaJWka52" alt=""></td></tr></tbody></table>

<table><thead><tr><th width="127">View Type</th><th width="234">Calendar timezone display</th><th width="171.33333333333331">Option to override</th><th width="228">Listing Paused Schedules</th></tr></thead><tbody><tr><td>2 Weeks</td><td>Schedule Timezone</td><td>✅</td><td>✅</td></tr><tr><td>Month</td><td>User's Timezone</td><td>✅</td><td>❌</td></tr><tr><td>List</td><td>User's Timezone</td><td>❌</td><td>❌</td></tr></tbody></table>

### Participants

1. To filter by participants (user or squad), click on the **Filter icon** in the Schedule’s Listings page -> **Participants.**
2. Enter the name or select participants (users or squads) from the dropdown list -> click **Apply**, and you’re done.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> You can add up to 5 participants to the filter.
{% endhint %}

<figure><img src="/files/RnC62gvkgslIgFK9iN8S" alt="" width="563"><figcaption></figcaption></figure>

1. To filter by your on-call shifts, click on the Filter icon in the Schedule’s Listings page.
2. Switch the **Show My On-Call** toggle -> click **Apply**, and you’re done.

### Escalation Policy

1. To filter by escalation policies, click on the **Filter** icon in the Schedule’s Listings page -> **Escalation Policy.**
2. Enter the name or select the escalation policies from the dropdown list -> click **Apply**, and you’re done.

<figure><img src="/files/ZXb3A0yKks8iWvDcIOZy" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark><mark style="color:blue;">:</mark>

To filter schedules without escalation policies, click on the Filter icon in the Schedule’s Listings page -> switch the **Schedules without Escalation Policy** toggle -> click **Apply**, and you’re done.
{% endhint %}

### Owner

1. To filter by owner click on the **Filter** icon in the Schedule’s Listings page -> **Owner**.
2. Enter the name of the user, or squad, or select the options from the dropdown list -> click **Apply**, and you’re done.

<figure><img src="/files/PrVy86RjsVO1oRwGhXmV" alt="" width="563"><figcaption></figcaption></figure>

## Search

To search for a specific schedule, enter the schedule’s name or any other related keywords in the Search field and hit enter.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> Paused schedules do not appear in the search.
{% endhint %}

## View Details

1. **Schedules**: Click the schedule’s name to view its full details.
2. **On Call Now**: The user on call will be listed with a Now pill to the right of their name.\\

   Click the user’s name to view their details.\
   \
   \&#xNAN;*On-call representation:*

   * If there is a gap in rotations, it shows "None"
   * If there is no event in rotations, it shows "None"
   * If the schedule is paused, it shows "None"
   * If there is anyone on call, the name of the user/ squad is displayed\\
3. **Shifts**: Click a shift to view its full details or to create an override.
4. **Escalation Policies**: If the schedule has only one escalation policy, click the escalation policy name to view its details.

## Actions

Users may also take the following actions from this page:

* [<mark style="color:blue;">Create a New Schedule</mark>](/schedules/schedules-new/adding-a-schedule#create-a-schedule)
* [<mark style="color:blue;">Pause an Existing Schedule</mark>](/schedules/schedules-new/adding-a-schedule#pause-a-schedule)
* [<mark style="color:blue;">Export a Schedule</mark>](/schedules/schedules-new/adding-a-schedule#export-a-schedule)
* [<mark style="color:blue;">Clone a Schedule</mark>](/schedules/schedules-new/adding-a-schedule#clone-a-schedule)
* [<mark style="color:blue;">Add Participants</mark>](/schedules/schedules-new/adding-a-schedule#edit-participants-of-an-existing-schedule)
* [<mark style="color:blue;">Edit Rotations</mark>](/schedules/schedules-new/adding-a-schedule#edit-rotations)
* [<mark style="color:blue;">Delete a Schedule</mark>](/schedules/schedules-new/adding-a-schedule#delete-a-schedule)

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Who is On-Call?

Find out who is on-call at any given instant

This document will help you understand how you can find out who is on call at any given instant.

### On the Squadcast Web App <a href="#on-the-squadcast-web-app" id="on-the-squadcast-web-app"></a>

At any given point, you will be able to see the current on-call users in the top right corner of your screen.

![Which user is currently on-call in Squadcast](/files/Y8AzmtkTppeua6q3PV49)

* You can click on the **On-call** icon to see the Schedule name and the on-call engineer is associated with it.

<img src="/files/s0StdPrJpM2seRnhrY9O" alt="Details of current on-call user in Squadcast" data-size="original">

* Additionally, you have the option to search for a specific schedule and view the individuals participating in it.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# My On-Call Shifts

My On-Call Shifts allows users to view their shifts across all Escalation Policies and Schedules in a single, easy-to-use view

My On-Call Shifts displays whether a user is on call now, a list of their associated shifts, and what their upcoming schedule looks like. This is available as a widget on the Profile Page. You can view the on-call shifts of other users by navigating to their Profile Page.

## My On-Call Shifts in the Profile Page

To access the My On-Call Shifts widget:

Navigate to the **Profile Page** from the top right corner of the screen -> **My On-Call Shifts**

The following information is displayed here:

* **Time**: The time for which you are on-call
* **Name**: The name of the Schedule you’re on-call for
* **Users**: The users who are on-call along with you

<figure><img src="https://lh4.googleusercontent.com/jOcfJEKN9x2QfvUporMjZaxNekDbugdC5MBwOQFDLH5ftJwI0-x0h4b1sOAqX_UyI636Lw8cwDS_lpDR4INS8EG8IM2e48CZrrDdwY9cS6bIXLSOH2OaALbWPanj_yMrIFy_nJUIEH67pmMcZKxotLzgQfPcZqnhUCh5RBDKuMgjkmoZkOlgUcuXAX_jaA" alt=""><figcaption></figcaption></figure>

## On-Call Filtered Views

You can view the on-call shifts for today, this week, and any custom range you select.

![](https://lh6.googleusercontent.com/6QDKkXGfjQ7oHLHfuMN3LQ_uBRzTDEMsV-0k7bY3dM0kEqi93OXH_yViUPS_DG990UpejRrgAwANcuhUlL2FPlkcTbOEX-w0ziRhMj-8TwIqZvvbohG_jtR38ft0QVMHoJH1Kzy7Ty6ktTcbeiT7ECSJ-IR_CsPj3ErjjkBDnJQg2qU8AMnYMDB0sKOrNw)

## View Another User’s On-Call Shifts

Go to **Settings** -> Users and select another User to visit their Profile Page. Select the On-Call Shifts tab.

<figure><img src="https://lh4.googleusercontent.com/D1oUjXHgls9hDpgLwvevY8-eBVcU1LBy5uJ6mvwevbPg0EuRpiSJLw8DIx6ngsLSW8lNE-CEUkKG_cPX1UcZCJL2uoDjATVgEEgasHgVVgyBEHXQpbAHBwCBbpfdF3iQ4AyzgoEnl9pxX4ICtUdQOiQx8KS7kiMuZVjB-Ms6hN6S3rZhyfaG2mA11Z28nQ" alt=""><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Overrides

You can leverage scheduled overrides to address holidays or schedule conflicts

Make one-time adjustments to existing on-call schedules and help on-call engineers with planned vacations, unexpected illnesses, or other events during their on-call shifts. This way, only the users in override schedules will get notified of incidents during the scheduled time period.

{% embed url="<https://www.youtube.com/watch?v=CQOwinnSWyA>" %}

## Create an Override

Configuring Overrides will assign all slots of the existing users to selected users. Overrides will appear as per the Schedule's timezone.

To create an override,

1. Navigate to **Schedules** -> Click on any participant group from the schedule, click **Override.**
2. Enter the duration for which you’re creating an override -> Select **Reason** from one of the prompts or type your own.
3. Select the user your want to assign all your slots in this duration -> Click **Save**.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

* You can create an override by clicking on a rotation from the Schedules Overview page as well.
* Override assigns all slots of a user to someone else.
* You can create empty overrides to designate holidays on the schedule.
  {% endhint %}

<figure><img src="/files/IjW0L750y8QplzvGm9Os" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark>

1. In the case of a **complete override**, where the original on-call participant is overridden for the entire duration, only the override participant will receive on-call reminder notifications.

In the following example, only "PK" will receive on-call reminders.

<img src="/files/bfv81iscLbQYSKinwYwD" alt="" data-size="original">

2. In the case of a **partial override**, on-call reminder notifications are sent to both the original on-call participant and the override participant.

In the following example, both "DT" and "PK" will receive the on-call reminders.

<img src="/files/mEhp2gDI7gB6mcbbMt3Y" alt="" data-size="original">
{% endhint %}

## Edit an Override

To edit an override,

1. Navigate to **Schedules** -> Expand the Schedule and click on the rotation for which you want to edit the override.
2. Click **Edit Override** -> Edit the override details -> Click **Save**.

## Remove an Override

To remove an override,

1. Navigate to **Schedules** -> Expand the Schedule and click on the rotation for which you want to remove the override.
2. Click **Remove Override** -> A confirmation modal will open -> Click **Confirm**.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> By removing this override, the previous participant of this rotation will be reassigned.
{% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Videos: How to set up common use cases?

## Weekly Business and Non-Business Hours

{% embed url="<https://www.youtube.com/watch?v=ZsIlRRKlOp4>" %}

## Weekly Schedules

{% embed url="<https://www.youtube.com/watch?v=ejzNCWVYZcY>" %}

## Weekend Schedules

{% embed url="<https://www.youtube.com/watch?v=And9tlOAeBw>" %}

## Daily Schedules

{% embed url="<https://www.youtube.com/watch?v=rDfgATlcQsg>" %}

## Schedule Overrides

{% embed url="<https://www.youtube.com/watch?v=CQOwinnSWyA>" %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Create and Manage Escalation Policy

Enhance incident response with effective escalation policies. Connect services to on-call schedules, ensuring timely notifications and streamlined incident resolution.

{% embed url="<https://www.youtube.com/watch?v=L2o3JH4EIJg>" %}

Escalation Policies ensure that the right people are notified at the right time. Incident notifications can be configured to escalate to Users, Squads or Schedules in a given order and time. You can create different Escalation Policies for different Services.

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* The User Role for the user in the Team must have the necessary permissions in order to manage Escalation Policies.

### Creating an Escalation Policy <a href="#creating-an-escalation-policy" id="creating-an-escalation-policy"></a>

Ensure that the right Team is selected using the team picker at the top of the screen.

1. Click on **Escalation Policies** from the navigation sidebar

<figure><img src="/files/pjI1dV1eN6hH1G2JI2OU" alt="" width="563"><figcaption></figcaption></figure>

2. Click on **Add Escalation Policy** to create one from scratch

<figure><img src="/files/VHMj7WBBz9KLSRTjkhyU" alt="" width="375"><figcaption></figcaption></figure>

3. Give the Escalation Policy a **Name** and an optional **Description**

<figure><img src="/files/tDogitDuPjG3ILCoaHtR" alt="" width="375"><figcaption></figcaption></figure>

4. Add <mark style="color:red;">`Users`</mark>, <mark style="color:red;">`Squads`</mark> or <mark style="color:red;">`Schedules`</mark> as recipients of notifications at any level of the Escalation Policy

<figure><img src="/files/1umwQrOyip4e5OWbFlJK" alt="" width="375"><figcaption></figcaption></figure>

5. Enter the appropriate time for **Escalate After**, giving enough notice for your recipients to acknowledge the alert after which it will escalate to the next level (if defined)

<figure><img src="/files/JNFBgqd91ZsSeUUzcRV5" alt="" width="375"><figcaption></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Notify your team members as soon as an incident is triggered in Squadcast**</mark>

If you want to notify your team members as soon as an incident is triggered in Squadcast, set the **Escalate After** time for the first layer of escalation (first Escalation Rule) to **0 mins**. As and when an alert reaches Squadcast for the Service, an incident is created for it and the mapped users as in the Escalation Policy will get notified **of** it immediately based on the notification channels selected.<img src="/files/NEWKW4Te4s240BAt0Sz8" alt="" data-size="original">
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Escalate After and the Order of Rules**</mark>

The time in (mins) input in the `Escalation After` text box takes the absolute time from the time of the incident creation.

That is, the time input in all the levels of escalation is calculated from the time of the incident trigger.

The order of the rules will be carried out based on the time input. That is, from the shortest to the longest time, irrespective of the order in which the rules are placed while defining.
{% endhint %}

6. There are two ways to add the medium of notification under **Notification Rules**:

From the dropdown, you can select either **Personal** or **Custom**

<figure><img src="/files/IS8dD8Ew8X98n6AuLxst" alt="" width="375"><figcaption></figcaption></figure>

(a) **Custom** - As an Admin, you can select one or more of the available notification channels **(Email, Push, SMS, and Phone)** to explicitly specify the channel via which the mapped users need to receive the incident notifications

<figure><img src="/files/3aGCu0158NTwMU40Ou2J" alt="" width="375"><figcaption></figcaption></figure>

(b) **Personal Notification Rules** - Allow users to **set up** their preferred medium of notification for incidents

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>**:**

By default, **Personal Notification Rules** (as indicated by **the Personal** option in the dropdown) are enabled for all the mapped users in the Escalation Rule.
{% endhint %}

7. Use **Add Rule** to add a new Escalation Rule (layer of escalation) in the policy

<figure><img src="/files/bWcjNp88q8SyKcIWHirK" alt="" width="375"><figcaption></figcaption></figure>

8. **Actions For Unacknowledged Incidents**\
   \
   **Repeat the \_entire policy**\_ if no one acknowledges the incident even after the Escalation Policy has been executed fully once

<figure><img src="/files/WsMwfWipLGReSIXTS7iN" alt="" width="375"><figcaption></figcaption></figure>

{% hint style="warning" %}
**Maximum Repeats Possible**

You can repeat any Escalation Policy for a **maximum of 3 times** only.

<img src="/files/rP94isvv43T6OpILjQS9" alt="" data-size="original">
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>**:**

Time input can be between 1 and 48 hours (inclusive).
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>**:**

There will be two types of logs under notification logs, differentiated by the icon in the first column:

* Incident Alert
* Acknowledgment Reminder Alert

<img src="/files/ExCArNJUdq0SO79rKnqV" alt="" data-size="original">

* Incident Alerts - Alert notifications are sent out for incidents to on-calls, users, or squads based on Escalation Policies or Routing Rules.

<img src="/files/mVyQfrNHHvZqCSZw3QCH" alt="" data-size="original">

* Acknowledgment Reminder Alerts - Reminder notifications are sent out for acknowledged incidents to the user who acknowledged the incident.

<img src="/files/hlsIbB6vUpWjqiBdcs5U" alt="" data-size="original">
{% endhint %}

8. Click on **Save** to save and view the Escalation Policy

<figure><img src="/files/hg5Zi8BC6fiMX2spr3Nw" alt="" width="375"><figcaption></figcaption></figure>

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>**:**

If the incident has transitioned away from the **Triggered** state when it was assigned to a specific Escalation Policy, then the rest of the rules in the Escalation Policy will not be executed.
{% endhint %}

### Editing/Deleting an Escalation Policy <a href="#editingdeleting-an-escalation-policy" id="editingdeleting-an-escalation-policy"></a>

1. To edit an existing Escalation Policy, click on **More Options** for that particular Escalation Policy
2. Choose **Edit** to modify the existing Escalation Policy or **Delete** to delete the Escalation Policy entirely

<figure><img src="/files/kKNn7zvvRNvwESeSBmQm" alt="Editing/Deleting an Escalation Policy" width="563"><figcaption></figcaption></figure>

3. After modifying the Escalation Policy, click on **Save**

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>**:**

Before deleting an Escalation Policy, **ensure that it is not associated with any of the Services or that there are no open incidents associated with the Escalation Policy**, otherwise you will be prohibited from deleting it.
{% endhint %}

### FAQs <a href="#faqs" id="faqs"></a>

1. Can I add members from different Teams to an Escalation Policy for my Team?

No, adding members from across Teams into an Escalation Policy is not allowed. Any member that needs to be added to the Escalation Policy for a Team must be a part of the same Team.

2. Is there a way to introduce Round Robin assignment of incidents to different entities within an escalation level?

Yes, please refer to the documentation [<mark style="color:blue;">here</mark>](https://support.squadcast.com/docs/round-robin-advanced-escalations)<mark style="color:blue;">.</mark>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Round Robin & Advanced Escalations

Round Robin & Advanced Escalations help users configure more granular and customised escalation rules

{% embed url="<https://www.youtube.com/watch?v=L2o3JH4EIJg>" %}

Round Robin & Advanced Escalations allow users to set up round-robin rotations, granular escalation levels with sub-escalations, individual escalation level repetitions with timeouts, and much more.

{% hint style="info" %}
**Note:**

These features are available in the Premium and Enterprise [<mark style="color:purple;">plans</mark>](https://www.squadcast.com/pricing).
{% endhint %}

### Round Robin Escalations <a href="#round-robin-escalations" id="round-robin-escalations"></a>

Round Robin Escalation is an incident assignment strategy where users are placed in a ring and assigned to incidents sequentially. This strategy can help ensure that incidents are equitably distributed. It can also lower incident response time if a service experiences concurrent incidents since the incidents will not all be assigned to the same responder.

### Understanding Round Robin Escalation <a href="#understanding-round-robin-escalation" id="understanding-round-robin-escalation"></a>

**Assignment Ring**

Users, Squads and Schedules are placed in an order in which they are assigned to an incident, within an Assignment Ring. This order is followed to reach out to assignees when an incident is triggered, with the start pointer then pointing to the one next-in-line in the assignment ring.

{% hint style="info" %}
**Note:** The starting point of the ring is determined by the assignee order when the Escalation Policy is created.
{% endhint %}

**Start Pointer**

While the Round Robin rotation is enabled, you will see a green arrow pointer next to the User, Squad or Schedule who is next in line for incident assignment. The pointer visually indicates who will be notified next in the Assignment Ring for an incident. By default, when an Escalation Policy with Round Robin rotation is created and configured, it will point to the first User, Squad or Schedule of the Assignment Ring.

{% hint style="info" %}
**Note:**

Round Robin and Advanced Escalations would work as configured even when an Escalation Policy is called as part of incident reassignment or via Tagging & Routing Rules.
{% endhint %}

### Enabling Round Robin Escalation for a Policy <a href="#enabling-round-robin-escalation-for-a-policy" id="enabling-round-robin-escalation-for-a-policy"></a>

Create an Escalation Policy as desired. For each of the levels, Round Robin rotation can be enabled.

1. To enable simple Round Robin rotation, check the option that says **Enable Round Robin assignment for this layer**
2. To enable rotation through the entire Assignment Ring and then jump to the next escalation level, check the option that says **Enable rotation within the Assignment Ring**
3. Additionally, you can also specify after what time (in minutes) should the next person in the Assignment Ring be notified.

When an incident is triggered that uses this Escalation Policy, the incident will be assigned in sequential order to the Users, Squads or Schedules participating in the Round Robin rotation.

![How to enabling round robin escalation for a policy in Squadcast](/files/DsQ7F5k0whAaMrU8jQb5)

### Enabling Round Robin for an Existing Escalation Policy <a href="#enabling-round-robin-for-an-existing-escalation-policy" id="enabling-round-robin-for-an-existing-escalation-policy"></a>

1\. Navigate to **Escalation Policies**. For an Escalation Policy, click on the **top-right** icon and select **Edit**

![Enabling Round Robin for an Existing Escalation Policy](/files/w6kHM1RZ3g36rZS5D8ot)

2\. In the level(s) where you would like to enable Round Robin, check the option **Enable Round Robin assignment for this layer**.

Add additional Users, Squads or Schedules if not added already. In case of a Schedule, whoever is on-call at the time, will be notified of the incident. Then, click **Save.**

![How to Enable Round Robin assignment for this layer](/files/FkiOoTZrxkAL5zIOS9mr)

You can further enable and configure other options as needed even for existing Escalation Policies.

### Advanced Escalations <a href="#advanced-escalations" id="advanced-escalations"></a>

Escalation Policies can be configured granularly to further suit custom requirements within organizations. In addition to the basic Escalation Policy and Round Robin Escalations, users can configure:

* Each of the individual escalation levels to repeat with a repetition timeout

<figure><img src="/files/DHQI14iv9UGpsYyWk9Sn" alt="Advanced Escalations policy in Squadcast"><figcaption></figcaption></figure>

* The entire Escalation Policy **is** to repeat with a repetition timeout

<figure><img src="/files/oEMVWwaE0EUBnmyFLHjk" alt="Round Robin Assignment repeats in Squadcast"><figcaption></figcaption></figure>

### Post Acknowledgement Reminders

For incidents that have been acknowledged and left unresolved, you can configure notification rules to notify the users who have acknowledged an incident but have not resolved it. Typically, organisations classify incidents and have time bound limitations for incident resolutions. Sending out these reminders can help teams live up to the time-bound incident resolution upkeep.

<figure><img src="/files/T8QH1IiE5zu63BHeqy0V" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %} <mark style="color:blue;">**Important:**</mark>

1. Re-Notification starts from the time of the latest acknowledgment.
2. Only the user who acknowledges will get the reminder.
3. Users will stop receiving notifications after 48 hours of acknowledgment.
   {% endhint %}

### Re-trigger Incidents <a href="#persistent-notifications" id="persistent-notifications"></a>

Sometimes, when an incident has been open for too long and teams want to re-trigger the incident with the same escalation, they can set it up using the re-trigger incident rule. The time interval mentioned will be the time for re-trigger from the latest acknowledgement of the incident.

<figure><img src="/files/ZZnlrx3x3BoqG8mi64Gh" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %} <mark style="color:blue;">**Important:**</mark>

* It can be set to a maximum of 48 hrs from the time of the first trigger.
* An incident can only be re-triggered once.
  {% endhint %}

### Persistent Notifications <a href="#persistent-notifications" id="persistent-notifications"></a>

Every Escalation Policy can have up to 12 levels. Each level can be repeated a maximum of 5 times (when the Round Robin assignment is disabled). Additionally, the entire Escalation Policy can be repeated a maximum of 3 times. This would mean you can have up to 180 iterations persistently generating notifications for a triggered incident.

While the system is generous on this front, we would recommend users set up notifications responsibly for them to be suitably persistent.

### FAQs <a href="#faqs" id="faqs"></a>

**1. When a Squad is added to the escalation level and Round Robin Escalation is enabled, how would it work?**

Every user within the Squad would be notified when the Squad is added to the Assignment Ring for Round Robin rotation. Round Robin rotation is applicable to the entities in the Assignment Ring - Users, Squads, and Schedules. Round Robin rotation is not applied to users present within Squads and Schedules.

**2. When a Schedule is added to the escalation level and Round Robin Escalation is enabled, how would it work?**

Every on-call User/Squad within the Schedule would be notified when the Schedule is added to the Assignment Ring for Round Robin rotation. Round Robin rotation is applicable to the entities in the Assignment Ring - Users, Squads, and Schedules. Round Robin rotation is not applied to users present within Squads and Schedules.

**3. How are coverage gaps in Schedules handled when the Schedule is part of a Round Robin escalation?**

When a Schedule is due for the assignment next, it is assigned to whoever is currently on-call in that Schedule. In case no one is on-call due to a coverage gap, it will skip the assignment to either the next entity in the Assignment Ring or escalate to the next level of the Escalation Policy (depending on how the rules are configured). This ensures that the coverage gap in the Schedule does not cause any incident to be missed.

**4. What happens to the Round Robin Escalation when Users, Squads, and Schedules are added or removed?**

Any Users, Squads, or Schedules removed from the Assignment Ring, the Start Pointer is reset and points to the first User, Squad, or Schedule again. One can easily drag and drop to rearrange the order of placement of the User, Squad, and Schedule within the Assignment Ring. Note that the position of the Start Pointer will reset to the first User, Squad, or Schedule upon rearrangement (drag & drop) as well.

**5. Which of the time inputs added are absolute versus relative?**

* The **Escalate After** input field for each escalation level is **absolute** (this time is calculated from the time of incident trigger)
* The input for repetition of the entire Escalation Policy field is **absolute** (the input at the bottom of the Escalation Policy)
* Every other time input within the Escalation Policy would be calculated **relative** to the **Escalate After** time for that level

**6. How can I understand if Round Robin rotation is enabled for an Escalation Policy or not?**

On the Escalation Policies page, due to the indication, you can easily view which of the levels within an Escalation Policy have Round Robin rotation enabled.

<figure><img src="/files/c1StAtcTgAbRUq5P6qRS" alt="View which Escalation Policy has been enabled in Squadcast"><figcaption></figcaption></figure>

**7. Scenario:** There are 2 users - user 1 and user 2 in the first level of the Escalation Policy. Round Robin rotation is enabled for this layer. The second level has 2 users - user 3 and user 4. The entire policy is set to repeat an additional 2 times (after 0 mins timeout) if the incident remains unacknowledged.

**How would this work?**

The notifications to be sent out would be scheduled in this way:

* Iteration 1:

  Level 1: user 1 is notified

  Level 2: user 3 and user 4 are notified
* Iteration 2: (first round of repetition of the entire policy)

  Level 1: user 1 is notified

  Level 2: user 3 and user 4 are notified
* Iteration 3: (second round of repetition of the entire policy)

  Level 1: user 1 is notified

  Level 2: user 3 and user 4 are notified

At this point, the start pointer is now pointing to user 2 (the next user to be notified in the Assignment Ring for the following incident).

**8. I have enabled rotation within the Assignment Ring of Round Robin within an escalation level. What happens if the&#x20;*****Escalate After*****&#x20;timeout occurs before every member of the Assignment Ring could be notified of the current incident?**

Assume there are 10 users in the first level of the policy (with **Escalate After** a time of 0 minutes), who are set to be notified with a gap of 1 minute before the next member is notified. Also, assume the second level is set to be called after an **Escalate After** a time of 5 minutes.

Now, the notifications to be sent out would be scheduled in this way (assume, the incident triggered at time T=0 minutes):

T=0 minutes: Notify user 1 (level 1)

T=1 minute: Notify user 2 (level 1)

T=2 minutes: Notify user 3 (level 1)

T=4 minutes: Notify user 4 (level 1)

**T=5 minutes: Notify user 5 (level 1)**

**T=5 minutes: Notify user 6 (level 2)**

**9. When does the Start Pointer increment to point to the next assignee (User, Squad, or Schedule) in the Assignment Ring?**

The Start Pointer aims to visually indicate *starting from which assignee (User, Squad, Schedule) in the Assignment Ring would the notifications for the newly triggered incident be sent out for*

The Start Pointer *increments* when:

* The Escalation Policy is called for a newly triggered incident (including when the Escalation Policy is called as part of *incident reassignment*)

**Note:** The Start Pointer *does not increment* across repetitions when the entire Escalation Policy is set to repeat (i.e., between 1 and 3 times)

**10. Where can I check what notifications went out (when Round Robin rotation is enabled, or otherwise)?**

Every incident has [<mark style="color:blue;">Notification Logs</mark>](/notifications/understanding-incident-notifications#notification-details-and-logs) within its Details page. What notifications were scheduled and to whom, and how many of them were attempted - the status, notification channels, and timestamp information would be included in these logs.

**11. How do individual rule/level rotation and repetition work?**

When Round Robin Assignment is enabled, you can enable rotation within the Assignment Ring and specify the time gap between each of the assignees being notified.

<figure><img src="/files/TRMm4lIign53nUJS4OpF" alt="How individual rule/level rotation and repetition work in Squadcast"><figcaption></figcaption></figure>

{% hint style="info" %}
**Note:** You cannot make a Round Robin Assignment enabled layer repeat more than once.
{% endhint %}

When Round Robin Assignment is disabled, you can specify how many times the particular layer needs to be executed, along with the timeout between each repetition.

<figure><img src="/files/m3WIPiihqhuBv2hEMktO" alt="Escalation layers when round robin assignment is disabled in Squadcast"><figcaption></figcaption></figure>

**12. Is there a limit on the number of times an escalation level can be repeated?**

Yes, individual escalation levels can be repeated a maximum of 5 times, while the entire Escalation Policy can be repeated an additional maximum of 3 times.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Reassign an Incident

Reassigning an Escalation Policy

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* The User Role for the user in the Team must have the necessary permissions in order to reassign incidents.

### Reassigning Incidents <a href="#reassiging-incidents" id="reassiging-incidents"></a>

An incident in the <mark style="color:red;">`Triggered`</mark> or <mark style="color:red;">`Acknowledged`</mark> state can be reassigned to a different **User**, **Squad,** or **Escalation Policy**.

1\. Open an incident that you wish to reassign from the **Dashboard** or **Incidents** page

<figure><img src="/files/WOiUn1S1bDW28P6dYmFG" alt="Reassigning Incidents in Squadcast"><figcaption></figcaption></figure>

2\. Click on **Reassign**

<figure><img src="/files/7OiINtDuOhb2ulQdAicA" alt="Reassigning Incidents in Squadcast"><figcaption></figcaption></figure>

3\. Select a **User**, **Squad,** or an **Escalation Policy** from the drop-down

<figure><img src="/files/inOugm3dyZuziyf4dlkf" alt="Reassigning Incidents Policy in Squadcast"><figcaption></figcaption></figure>

{% hint style="info" %}
**Note:**

When an incident is reassigned to a User or Squad then the user(s) are notified based on their Personal [<mark style="color:blue;">Notification Rules</mark>](/manage-users/notification-rules) set up under their Profile settings.
{% endhint %}

4\. Click on **Reassign** to complete the action

<figure><img src="/files/1fgQpoBQH79R64d4FrNz" alt="Reassigning Incidents Policy in Squadcast"><figcaption></figcaption></figure>

5\. The reassigned action is auto-recorded in the **Incident Activity Timeline** of the incident and the same can be viewed in the **Responders** section

{% hint style="info" %}
**Note:**

The Incident Activity Timeline will show incident reassignment, mentioning both the assigned and assignee.
{% endhint %}

<figure><img src="/files/J0jpmOV0cbZlud2c99an" alt="The Incident Activity Timeline - incident reassignment"><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Understanding Incident Notifications

Understanding the available incident notification channels in Squadcast

When an incident is assigned to on-call users, they receive incident notifications. These notifications are triggered or escalated when an incident occurs and can be delivered through various channels such as Push notifications, Email, SMS, and Phone calls.

It's important to note that these notifications are specifically generated for incidents created within Squadcast and cannot be created manually.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: You can also choose to be notified of incidents via [<mark style="color:blue;">Slack</mark>](/chatops/slack) and [<mark style="color:blue;">Google Chat</mark>](/chatops/google-hangouts).
{% endhint %}

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>:\
\
Incident notifications are exclusively sent to users holding the Organization Roles of [<mark style="color:blue;">Account Owner</mark>](/quickstart-guide/get-started-as-an-account-owner) and [<mark style="color:blue;">User</mark>](/quickstart-guide/get-started-as-a-user). Users with Stakeholder Organization roles, however, will not receive these incident notifications. If stakeholders wish to stay informed about incidents, they can follow the steps outlined [here](/incidents-page/incident-watchers) to add themselves as incident watchers.
{% endhint %}

## Prerequisites

1. To begin receiving Push notifications, it is essential for all users to verify their phone numbers. Additionally, we highly recommend ensuring that the Squadcast mobile app on your device is regularly updated.
2. In order to begin receiving email notifications, it is necessary for all users to verify their email addresses.
3. To ensure receipt of SMS and Phone call notifications for incidents, users need to complete the following steps:
   1. [<mark style="color:blue;">Verify</mark>](/manage-users/manage-your-profile) the phone number associated with their Profile.
   2. [<mark style="color:blue;">Enable</mark>](https://support.incidents.cloud.solarwinds.com/notifications/pages/FSMPuuuM2vwQvIAkxHgv#3.-how-can-i-enable-sms-and-phone-calls-for-my-account) SMS and Phone call notifications for the Organization.

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>:\
\
It's important to note that on the <mark style="color:blue;">Free Plan</mark>, after surpassing the allocated [<mark style="color:blue;">free limits</mark>](/managing-your-squadcast-account/billing-faqs) and exhausting the one-time allowance of 100 notifications (SMS and Phone Calls) for an account, SMS and Phone call notifications will no longer be received. However, users will still continue to receive Email and Push Notifications.
{% endhint %}

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 Verify your phone number to receive push notifications. The app gives you instant access to all details and actions. We highly recommend ensuring that the Squadcast mobile app on your device is regularly updated.\
\
🔹 **Best Practice Tip** 🔹 Apple and Google Docs, push notifications operate on a "best effort" basis. Consider setting up backup contact methods (SMS, email, phone) for reliability if push notifications fail.\
\
🔹 **Best Practice Tip** 🔹 Furthermore, push notifications may also be impacted by energy-saving modes, low battery levels, or when the app is force-stopped.\
\
🔹 **Best Practice Tip** 🔹 We highly recommend you include multiple channels in your notification rules. In the event that a third-party SMS or voice carrier has an outage, another channel, such as Push, you can ensure that you will still receive timely notification\
\
🔹 **Best Practice Tip** 🔹 Your primary notification rule should be the most attention-grabbing notification method. We recommend using a diverse notification rule (Push, SMS, Phone, Email) with multiple steps to avoid single points of notification failure.\
\
🔹 **Best Practice Tip** 🔹 Use a custom notification rule during business hours, that may not require aggressive notifying.\
\
🔹 **Best Practice Tip** 🔹 Include a phone call in the last step of your notification rule, as a surefire way of getting alerted and acknowledging the incident.
{% endhint %}

## Notification Phone Numbers <a href="#notification-phone-numbers" id="notification-phone-numbers"></a>

Squadcast phone and SMS notifications can come from varying numbers based on your country and other variables.

<details>

<summary>Phone Call Notifications</summary>

1. +17076844278
2. +17072447799
3. +18038848378

</details>

<details>

<summary>SMS Notifications</summary>

1. +17076844278
2. +17072447799
3. +18038848378

</details>

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 We highly recommend downloading the [<mark style="color:blue;">Squadcast Contact Card</mark>](https://vcard.link/card/D4QS.vcf), to add all the numbers we use to send phone and SMS notifications.\
\
🔹 **Best Practice Tip** 🔹 Moreover, you can star the contact so that they can enable DND override for starred contacts.
{% endhint %}

{% embed url="<https://vcard.link/card/D4QS>" %}

## Notification Details and Logs <a href="#notification-details-and-logs" id="notification-details-and-logs"></a>

To access the Notification Logs for a specific incident, follow these steps:

1. Go to the **Incident Details** page.
2. In the Responders section, locate and click on **Notification Logs**.
3. The Notification Logs will provide you with information about the source of each incident notification.

<figure><img src="/files/93nDEUPqZYaZy5yqFOf3" alt="Notification Logs for an incident in Squadcast" width="563"><figcaption><p>Notification Logs for an incident</p></figcaption></figure>

The Notification Logs include:

1. **Cause**: Indicates the cause of the notification, such as:
   1. <mark style="color:red;">`Incident Alert`</mark>: Notifications are sent out for incidents triggered.
   2. <mark style="color:red;">`Acknowledgment Reminder Alerts`</mark>: Reminder notifications are sent out for unresolved incidents (if set up in the Escalation Policy).
   3. <mark style="color:red;">`Incident Watcher Notification`</mark>: Email notifications are sent out when a user/squad has subscribed to watch the incident
   4. <mark style="color:red;">`@mentions`</mark>: Email and Push notifications are sent out when a user/squad is @mentioned in the Notes section for the incident.
2. **Name**: User to whom the notification has been sent
3. **Channel**: Indicates the notification channel followed by the destination.
4. **Status**: Indicated the status of the notification, such as:
   1. <mark style="color:red;">`scheduled`</mark>: When the notification is scheduled to be sent out from Squadcast.
   2. <mark style="color:red;">`dispatched`</mark>: When the notification is dispatched from Squadcast and has been accepted by our providers for further delivery.
   3. <mark style="color:red;">`sent`</mark>: When the notification is dispatched from the providers’ platform to the user.
   4. <mark style="color:red;">`delivered`</mark>: When the notification has been delivered successfully to the user.
   5. <mark style="color:red;">`canceled`</mark>: When an incident has been acknowledged or resolved, the rest of the scheduled notifications will not be dispatched. The notification status of these notifications will be set to <mark style="color:red;">`cancel.`</mark>
   6. <mark style="color:red;">`failed`</mark>: When Squadcast is unable to send out the notification.
5. **Time**: Indicates the time at which the notification was sent (or is yet to be sent).

You can filter the notification logs based on the Causes, Type, and Status of the notification.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>**:**\
To export the Notification Logs for an incident in .CSV format, click on the download icon next to the refresh icon on the top.
{% endhint %}

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>**:**

In some cases, even when notifications might have been *delivered* to users, the status could still be set to *sent/dispatched*.\
\
We depend on our vendors, who in turn depend on hundreds of carriers worldwide, to get notification delivery information. In rare cases, these logs might not be completely reliable. We might have to look further into it to understand certain situations.\
\
If you wish to receive more details on the notifications sent out for an incident, you can reach out to our [<mark style="color:blue;">Support team</mark>](mailto:support@squadcast.com) with the `Incident ID` of the incident.
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**More on push notifications**</mark>**:**

1. You might see multiple push notifications being scheduled/dispatched if you have logged in to your Squadcast account on multiple mobile devices
2. You will not see any push notifications in the logs if you have not installed and logged into the Squadcast mobile app even though you have push as a notification channel in your notification rule(s).
   {% endhint %}

## Permission for Push Notifications <a href="#bypass-do-not-disturb-dnd-for-sms-and-phone-call-notifications" id="bypass-do-not-disturb-dnd-for-sms-and-phone-call-notifications"></a>

Please verify if the necessary permissions for Push Notifications have been granted.

{% tabs %}
{% tab title="Android" %}
To ensure you receive regular notifications and bypass the Do Not Disturb (DND) feature, please follow these instructions:

1. **Granting permissions for regular notifications:**
   * During the onboarding process of the mobile app, you will have the option to grant permissions for regular notifications. Please make sure to enable this feature.
   * Alternatively, you can navigate to the **Settings** menu on your device.
   * Locate and select **App and Notifications**
   * Look for the **Squadcast** app and select **Notifications**
   * Toggle the switch for all the types of notifications you wish to receive.
2. **Bypassing Do Not Disturb:**
   * Follow the steps provided [<mark style="color:blue;">here</mark>](#bypass-do-not-disturb-dnd-for-squadcast-mobile-app) to bypass the Do Not Disturb setting.
     {% endtab %}

{% tab title="iOS" %}
To ensure you receive regular notifications and bypass the Do Not Disturb (DND) feature, please follow these instructions:

1. **Granting permissions for regular notifications:**
   * During the onboarding process of the mobile app, you will have the option to grant permissions for regular notifications. Please make sure to enable this feature.
   * Alternatively, you can navigate to the **Settings** menu on your device.
   * Locate and select **App and Notifications**
   * Look for the **Squadcast** app and select **Notifications**
   * Toggle the switch for all the types of notifications you wish to receive.
2. **Bypassing Do Not Disturb:**
   * Follow the steps provided [<mark style="color:blue;">here</mark>](#bypass-do-not-disturb-dnd-for-squadcast-mobile-app) to bypass the Do Not Disturb setting.
     {% endtab %}
     {% endtabs %}

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: We send push notifications for the following:\\

* Incident notifications
* On-Call Reminder notifications
* @mentions in Incident Notes
  {% endhint %}

## Bypass Do Not Disturb (DND) for SMS and Phone Call Notifications <a href="#bypass-do-not-disturb-dnd-for-sms-and-phone-call-notifications" id="bypass-do-not-disturb-dnd-for-sms-and-phone-call-notifications"></a>

Bypassing Do Not Disturb is a powerful feature to receive Push, SMS, and Phone call notifications for incidents even when your phone has the Do Not Disturb mode turned on.

Download the Squadcast vCard to create a contact for Squadcast, then follow the instructions below for mobile devices running on either Android or iOS.

### **Android**

To ensure uninterrupted SMS and phone call incident notifications on your Android device, follow these steps after downloading the vCard and creating a Squadcast contact:

1. Create a Squadcast contact using the downloaded vCard.

<figure><img src="/files/QWFS415LSdgls2qSBHAD" alt="" width="152"><figcaption></figcaption></figure>

2. **Star** the Squadcast contact.
3. Go to Settings and locate the section for configuring **Apps & Notifications** or Sounds (the exact location may vary depending on your device).
4. In our example device, access the **Do Not Disturb** section.
5. Open the **Exceptions** settings and allow notifications for the **starred** Squadcast contact, even when Do Not Disturb mode is enabled.

By completing these steps, your Android device will continue to receive SMS and phone call incident notifications, even when in Do Not Disturb mode.

### **iOS**

To ensure uninterrupted SMS and phone call incident notifications on your iOS device, follow these steps after downloading the vCard and creating a Squadcast contact:

1. Launch the **Contacts** app and locate the **Squadcast contact**. Tap on it to open the contact details.

<figure><img src="/files/nkWGBeEy3pZ8LeUZYWUM" alt="" width="188"><figcaption></figcaption></figure>

2. Scroll down until you find the entries for **Ringtone and Text Tone**. Tap on either Ringtone or Text Tone, whichever you prefer to configure.
3. At the top of the menu, you will see an option for **Emergency Bypass**. Toggle it on for each of the desired notification methods for this contact.

By following these steps, even if your iOS device is in Do Not Disturb mode, you will continue to receive SMS and phone call incident notifications without any interruptions.

## Bypass Do Not Disturb (DND) for Push Notifications <a href="#bypass-do-not-disturb-dnd-for-squadcast-mobile-app" id="bypass-do-not-disturb-dnd-for-squadcast-mobile-app"></a>

Users can choose to override the DND settings on their mobile phones and receive critical incident notifications from Squadcast via Push.

### **Android**

On an Android device, follow the steps as indicated below:

1. Navigate to **My Profile** -> Toggle **Allow DND Access**
2. Next, you'll be navigated to this screen in settings -> Toggle **Override Do Not Disturb** o&#x6E;**.**

<div><figure><img src="/files/n4a49892sqQnRskDHlwR" alt="" width="188"><figcaption></figcaption></figure> <figure><img src="/files/4oUOHpqmBSFzgQWYobID" alt="" width="188"><figcaption></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>:

To override DND Mode on Samsung and Redmi devices,

1. Navigate to the **Do Not Disturb** settings screen in your device’s Settings App
2. Add **Squadcast** to your Device’s DND exceptions

<img src="/files/VM3xPgdLzy45zv1YKCpW" alt="" data-size="original"><img src="/files/o36EVnTsv83fdGm6baQp" alt="" data-size="original">
{% endhint %}

### iOS

To override DND Mode for Squadcast Push Notifications, you will have to add Squadcast to your DND exceptions in your **device's Settings App**.

Refer to the flow as shown in the images below.

<div><figure><img src="/files/fVeuEcig5UJKiCUehjpC" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="/files/a1p9f1KdGb6NTYHOn8J0" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="/files/kY25pX14i4a6IZorBUB4" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="/files/Orkw9IE9pVkpVG7VBC7A" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="/files/gQXYPWVfYvBiJGlQESMc" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="/files/8u7P8V9KFmFSzFrniR8w" alt="" width="563"><figcaption></figcaption></figure></div>

### Custom Notification Sounds (iOS)

To customize the push notification sounds for your iOS device,

1. Navigate to **My Profile** -> **Alert Settings** -> **Push Notification Sounds**
2. You can choose notification sounds for **Incident Alerts** and **Other Notifications** (On-Call Reminders and Notes @mentions) from the list of available sounds.

<div><figure><img src="/files/Vmde4c108ZImgiiZEQ5w" alt="" width="188"><figcaption><p>Image. Customize Notification Sounds</p></figcaption></figure> <figure><img src="/files/cgN8FDL5DYAeyE3qtaJ9" alt="" width="188"><figcaption><p>Image. Select Custom Sound</p></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>:

1. The notification sound you select is device-specific. This means you can customize notification sounds for individual devices you're logged into.
2. Please note that if you uninstall the app or clear its data, your notification sound will be reset to the default tone.
3. This functionality has been introduced in iOS app version 3.1.0.
   {% endhint %}

> Sound Credits: Thanks to the folks at [Pixabay](https://pixabay.com/), [Mixkit](https://mixkit.co/free-sound-effects/), and [Freesound](https://freesound.org/) for the royalty-free sound effects.

## **Push Notification Sound and Volume**

Push Notification Sound and Volume settings vary for Android and iOS devices:

### **Android**

1. By default, notifications will play in your device’s default notification sound. To customize Push Notification Sound, follow the steps [<mark style="color:blue;">here</mark>](/mobile-app/using-the-mobile-app#custom-notification-sounds-for-android-app)<mark style="color:blue;">.</mark>

### Override System Volume (Android)

To ensure that Incident Notifications play at a volume you set, even when your device is in silent or Do Not Disturb mode, follow these steps:

1. Navigate to **Settings**.
2. Activate the '**Override System Volume**' toggle.

<figure><img src="/files/eboyB3fWI6g4rWVijXRT" alt=""><figcaption></figcaption></figure>

When Volume Override is enabled, incident notification sounds will play through both the Alarm and Notification channels

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

* **Speaker playback with headphones connected:** On some devices, sound may also play through the speaker even if headphones are connected. This is default Alarm behavior on most Android devices.
* **Double sound:** You may occasionally hear a double sound for the same notification. This is more likely when the Notification channel volume is higher than the Alarm channel volume.
* To receive sounds during Do Not Disturb, alarms must be allowed in your device's Settings app. The steps to enable this may vary depending on your device.
  {% endhint %}

### **iOS**

1. If you’d like Incident Notifications to override your device’s volume, you should enable **Critical Alerts** for Squadcast. If you don't enable Critical Alerts for Squadcast, you will receive Squadcast Push Notifications at the volume you have set for your device.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>:\
When critical alerts are enabled, you’ll receive Incident Notifications at 100% volume, even if your device is on Mute mode or DND Mode (Check out [<mark style="color:blue;">this</mark>](https://developer.apple.com/documentation/usernotifications/unauthorizationoptions/2963120-criticalalert) iOS Doc for more).
{% endhint %}

Refer to the flow as shown in the images below.

<div><figure><img src="/files/v1lHeT6aaRpd7X85UYTB" alt="" width="185"><figcaption></figcaption></figure> <figure><img src="/files/4c3L97ODeIZ6k7jiRbEg" alt="" width="188"><figcaption></figcaption></figure> <figure><img src="/files/GMFd8So7AwaSOajMM1wO" alt="" width="188"><figcaption></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>:\
If you don’t want to receive Incident Notifications at 100% volume, you’ll have to disable critical alerts for Squadcast.
{% endhint %}

### Custom Notification Sounds (iOS)

To customize the push notification sounds for your iOS device,

1. Navigate to **My Profile** -> **Alert Settings** -> **Push Notification Sounds**
2. You can choose notification sounds for **Incident Alerts** and **Other Notifications** (On-Call Reminders and Notes @mentions) from the list of available sounds.

<div><figure><img src="/files/Vmde4c108ZImgiiZEQ5w" alt="" width="188"><figcaption><p>Image. Customize Notification Sounds</p></figcaption></figure> <figure><img src="/files/cgN8FDL5DYAeyE3qtaJ9" alt="" width="188"><figcaption><p>Image. Select Custom Sound</p></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>:

1. The notification sound you select is device-specific. This means you can customize notification sounds for individual devices you're logged into.
2. Please note that if you uninstall the app or clear its data, your notification sound will be reset to the default tone.
3. This functionality has been introduced in iOS app version 3.1.0.
   {% endhint %}

> Sound Credits: Thanks to the folks at [Pixabay](https://pixabay.com/), [Mixkit](https://mixkit.co/free-sound-effects/), and [Freesound](https://freesound.org/) for the royalty-free sound effects.

## Excluded Countries <a href="#phone-calls-and-sms-support" id="phone-calls-and-sms-support"></a>

We use third-party providers to send out SMS and Phone call incident notifications. SMS and Phone call notifications are supported for all the countries across the world except for:

* Cuba
* Democratic People's Republic (North Korea)
* Russia
* Crimea
* Belarus
* Syrian Arab Republic (Syria)
* Kazakhstan

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>**:**

1. **We do not support creation of accounts or onboarding of users based out of most of the above countries. Even if onboarding happens, notifications through SMS and Phone will not be supported.**
2. <mark style="color:orange;">**SMS and Phone Notifications to Iran**</mark>**:**\
   While we do send SMS and Phone call incident notifications to users in **Iran**, we cannot assure its 100% deliverability.
3. <mark style="color:orange;">**SMSs to China**</mark>**:**\
   Incident notification SMSs sent to users of Squadcast in China will contain only the `Incident Title`. Incident URL is not included due to government policies against the presence of any URLs in SMSs. However, users can quickly view and take action on an incident using the Squadcast mobile app.
   {% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Incident Management Dashboard

Streamline operations with our centralized incident management dashboard designed for every team. Monitor and respond swiftly to incidents with ease. Elevate your incident management process today!

The **Incident Management Dashboard** is shown as soon as you log into the web application. This is the central console displaying all the incidents which have occurred for **a team** in the Organization along with their current status.

By default, all the incidents are displayed for the Team that is selected using the team picker on the top. You can switch the toggle to **Yours** to view incidents assigned to you in this Team.

<figure><img src="/files/8rvbRRAQm6wr83YyNQuV" alt="Incident Dashboard central console in Squadcast"><figcaption></figcaption></figure>

You can filter your incidents by their status (<mark style="color:red;">`Triggered`</mark>, <mark style="color:red;">`Acknowledged`</mark>, <mark style="color:red;">`Resolved`</mark> or <mark style="color:red;">`Suppressed`</mark>) by using the tab-based navigation in the list section.

<figure><img src="/files/PIGA52zA8hfjo8x9M1aj" alt="Incident dashboard status filter in Squadcast"><figcaption></figcaption></figure>

You can filter incidents by time using the quick filter options or by using the time range selector on the top right corner of the page. By default, incidents from the past week are displayed.

<figure><img src="/files/szYaQr4nHX2inRMerf39" alt="View of incident dashboard time filter in Squadcast"><figcaption></figcaption></figure>

You can also filter incidents by the impacted **Service**, associated **Alert Sources** and **Incident Assignees**.

<figure><img src="/files/KeYI4iDABbYWxZgtpPc9" alt="Filters in the Incident Dashboard in Squadcast"><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Dashboard Metrics

Decode incident management metrics: Understand meanings and calculation methods behind dashboard metrics. Gain insights into essential performance indicators.

Squadcast dashboard is the first screen that your Web App and Mobile App open. This document will guide you through how these metrics are calculated and what they mean.

First, select a Team using the team picker on the top.

<figure><img src="/files/qh4wKSgAmwJEkm5JSic7" alt="Incident dashboard in Squadcast"><figcaption></figcaption></figure>

### Incident State Metrics

Incident state metrics give you a single view calculation of the number or volume of incidents in each of the respective states on Squadcast.

<figure><img src="/files/ZpZBKZzoSTo5vkuKmbeQ" alt="Incident State Metrics in Squadcast"><figcaption></figcaption></figure>

#### Triggered <a href="#triggered" id="triggered"></a>

An incident is considered to be in the **triggered** state before any user responds to the incident notification. Once an incident is triggered it will notify the on-call user(s) based on their notification rules. This also means that the incident is in an **open** state.

#### Acknowledged <a href="#acknowledged" id="acknowledged"></a>

An incident is considered to be in the **acknowledged** state when a user has acknowledged an incident and is working on resolving it.

#### Resolved <a href="#resolved" id="resolved"></a>

An incident is considered **resolved** when the user has fixed the issue and wants the incident to be closed. Once an incident is resolved, no additional notifications will be sent and the incident cannot be opened again. This is one of the two final incident states in Squadcast.

#### Suppressed <a href="#suppressed" id="suppressed"></a>

All incidents that evaluate to be true for any of the Suppression Rules configured for a Service (or incidents that come in for the Service when it is under maintenance) will automatically go into the **suppressed** state. This, and **resolved** are the two final states in Squadcast.

### Response Metrics <a href="#response-metrics" id="response-metrics"></a>

Response metrics indicate the time taken to acknowledge and resolve a triggered incident. Typically, response metrics are used as a baseline to improve your incident response processes.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: Analytics data such as MTTA, MTTR, and incident counts across different states in the Dashboard are the best effort real-time. In case of delays, the data is auto-refreshed to reflect the latest analytics.
{% endhint %}

#### MTTA <a href="#mtta" id="mtta"></a>

Mean Time To Acknowledge is the average time taken to acknowledge incidents. When the dashboard is toggled to **Yours**, the incident metrics summary shows your MTTA and when it is toggled to **All**, the MTTA for the whole Team is shown.

{% hint style="info" %}
**Note:**

The MTTA is calculated as a separate metric for every Team that you are a part of in Squadcast. It auto-refreshes every 30 seconds.
{% endhint %}

#### MTTR <a href="#mttr" id="mttr"></a>

Mean Time To Resolve is the average time taken to resolve incidents. When the dashboard is toggled to **Yours**, the incident metrics summary shows your MTTR and when it is toggled to **All**, the MTTR for the whole Team is shown.

{% hint style="info" %}
**Note:**\
The MTTR is calculated as a separate metric for every Team that you are a part of in Squadcast. It auto-refreshes every 30 seconds.
{% endhint %}

### Percentage calculation for each metric <a href="#percentage-calculation-for-each-metric" id="percentage-calculation-for-each-metric"></a>

You will notice a percentage calculation under each of these metrics with an arrow that denotes if there is an increase or decrease in volume/performance.

This percentage indicates a comparative calculation of the performance/volume of the metric in the selected time period versus the performance/volume of the metric for the same time duration in the past.

That is, if you have chosen the <mark style="color:red;">`Last Week`</mark> dashboard view, the percentages shown will be calculated this way:

* Incident States Percentages = (Total number of incidents in each state this week / Total number of incidents from last week that are still in the respective states) \* 100

{% hint style="info" %}
**Example Percentage Calculation:**

If you have 6 incidents in the Triggered state this week and you still have 2 incidents from last week which are still in the Triggered state when you are viewing the dashboard, then the percentage under Triggered should be:

\
Triggered% = 6 (This week) / 2 (Last Week) \* 100 = 300%
{% endhint %}

* Response Metrics Percentages = (MTTR/MTTA recorded for this week / MTTR/MTTA recorded for last week) \* 100

{% hint style="info" %}
**Metrics Change with Dashboard View:**

Based on the dashboard view that you have chosen, that is, Last week, Last Month, or a Custom Date Range, the metrics change as per the calculation stated above.\
\
If a custom range view is chosen, the percentages are calculated the same way keeping in mind the window of the time period selected by the user (in days) is considered as the window of past metric comparison.\
\
That is if the custom date range chosen is between 14th Feb - 17th Feb, then the time period selected here would be 4 days. So, this will be compared against the volume of incidents that have come in, in the past 4 days, that is, 10th Feb - 13th Feb.\
\
The calculations would be as follows:\\

* Incident States Percentages = (Total number of incidents from 14th Feb - 17th Feb / Total number of incidents from 10th - 13th) \* 100
* Response Metrics Percentages = (MTTR/ MTTA recorded for 14th Feb - 17th Feb / MTTR/ MTTA recorded for 10th - 13th) \* 100
  {% endhint %}

{% hint style="danger" %}
**What does it mean when a response metric percentage is in red?**

Typically, the aim of an incident response system is to ensure that your MTTA and MTTR reduce. When the MTTA or MTTR percentage is in red, it means that there is an increase in the time taken to Acknowledge or Resolve incidents in comparison to the MTTA and MTTR performances in the past (same time duration considered as chosen in the dashboard view).\
\
This is shown in order to improve the response times and is not meant to alarm the Teams or Users.
{% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Take Bulk Actions

Bulk actions help you change the incident states of multiple incidents at one go

Bulk actions are a way for you to change the Incident Statuses for multiple incidents at one shot. You can do this by following the steps below.

**(1)** Pick a **Team** from the team picker on the top of the screen. Move over to the status-wise filters in the **Incident Dashboard**. Click on the incident state for which you need the incidents either **Acknowledged** or **Resolved**.

In this example, we have clicked on the **Triggered** state and will be moving these incidents to the **Acknowledged** state.

<figure><img src="/files/DFpi45CvTo4SmHGyOaHQ" alt="Moving incidents from Triggered state to the Acknowledged state"><figcaption></figcaption></figure>

**(2)** Check the box under the **Actions** button to select **all** the incidents that are shown in the view. You can also choose to select specific incidents for which you want to take the action.

{% hint style="info" %}
**Note:**

You will only be able to view a maximum of 20 incidents at once. So, you will only be able to select a maximum of 20 incidents at once. For a more detailed view of incidents, navigate to the [<mark style="color:blue;">Incident List</mark>](/incident-list/incident-list-view) page.
{% endhint %}

![](/files/cmTAevBQtlTeVOmHOoRf)

**(3)** Click on the **Actions** dropdown and select the new incident state that you want the selected incidents to reflect. In this example, we are choosing **Acknowledge**.

![Actions dropdown for incidents in Squadcast](/files/Cfx59yFOS9lAnRF1Snb2)

**(4)** This will then open a pop-up with the details of the incidents that are selected. You can review and then click **Confirm & Acknowledge**.

![Confirm & Acknowledge the bulk actions on incidents](/files/qA2cQdNV9AJ7RH1bAQXb)

Now, the selected incidents will reflect the new incident state.

Similarly, you can also choose to do this to incidents in the Acknowledged state.

{% hint style="info" %}
**Note:**

When you delete a service, you will have to ensure that there are no incidents in the <mark style="color:red;">`Triggered`</mark> or <mark style="color:red;">`Acknowledged`</mark> states. All incidents should be <mark style="color:red;">`Resolved`</mark>.
{% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Squadcast Search

Use the global search bar to look for incidents, documentation or other entities for your Team within the platform

### Basic commands <a href="#basic-commands" id="basic-commands"></a>

Search requires some basic commands to work with.

* Once in search, autocompletes can be provided with <mark style="color:red;">`Tab`</mark>
* Use <mark style="color:red;">`CTRL + SPACE`</mark> to view autocomplete
* Access search helps within search by typing in <mark style="color:red;">`?:`</mark>
* To execute a command use <mark style="color:red;">`CMD + ENTER`</mark> for Mac and <mark style="color:red;">`CTRL + ENTER`</mark> for Windows

![Squadcast search basic commands](/files/UrSmyJxkRlawGJausoim)

### goto <a href="#goto" id="goto"></a>

<mark style="color:red;">`goto`</mark> enables *instant navigation* when used along with <mark style="color:red;">`profile`</mark>.

* Activate the global search bar using <mark style="color:red;">`CMD/CTRL + SHIFT + K`</mark>
* Type in <mark style="color:red;">`goto`</mark> and enter
* Type in <mark style="color:red;">`profile`</mark> and then search for users by their email address
* <mark style="color:orange;">`CMD/CTRL + Return/Enter`</mark> to navigate to the user’s profile

<div><figure><img src="/files/3Qm2ZSJi4z6jXBjmacY7" alt="Squadcast search goto commands"><figcaption></figcaption></figure> <figure><img src="/files/Dh9qciV7vSl3te0Vrb3n" alt="Squadcast search goto commands"><figcaption></figcaption></figure></div>

### Help <a href="#help" id="help"></a>

Now you can navigate to alert source integration documents directly through the search. Type in <mark style="color:red;">`help:`</mark> and then the keyword or name of the documentation you want to search for.

![Squadcast search help commands](/files/a6mmUbRpaElVVbw2cor8)

### Search through Incidents <a href="#search-through-incidents" id="search-through-incidents"></a>

Search incidents with queries. We support a set of tokens to fine-tune the results. Supported tokens can be viewed in the search help by typing <mark style="color:red;">`?:`</mark>

![Search incidents with queries](/files/kzAqEN71H9bQjpdcsWFV)

### Search through Postmortems <a href="#search-through-postmortems" id="search-through-postmortems"></a>

Search postmortems with queries from the **Global Search Bar**

We support a set of tokens to fine-tune the results. Supported tokens can be viewed in the search help by typing <mark style="color:orange;">`?:`</mark>

![](/files/gA9UibJwFwuKUBy4rnrV)

You can search for **Postmortems** through **Postmortem Title**, **Postmortem Content**, **Impacted Service**, **Created After**, and **Created Before**.

{% hint style="info" %}
**Note: The `message`** **query**

The <mark style="color:red;">`message`</mark> query looks for a string match in the Incident Title and the Postmortem Content.
{% endhint %}

Example Use Case:

I want to look for a postmortem that contains the string <mark style="color:red;">`JIRA`</mark> in its Incident Message.

* Type in <mark style="color:red;">`?:`</mark> if you want to look up the query token
* Type <mark style="color:red;">`in: postmortems message "jira"`</mark>
* Hit <mark style="color:red;">`Command + Enter`</mark>

Your search results that match this query will be populated as shown below

![Squadcast search result](/files/brYcMBiqgyefWVxXOf6Q)

Search also provides history of queries. Search history is specific to a user with respect to the Organization.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Incident List View

A bird's-eye view of all the incidents your team has encountered

Incidents signify problems or issues that require attention and resolution. When triggered on services, an escalation policy prompts notifications to be sent to on-call responders, who are responsible for promptly mitigating the issue.

The Incident List provides a convenient, single-glance view of all your incidents and their relevant information.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: To view the Incident List for a specific team, simply select the desired team from the team picker located at the top.
{% endhint %}

## Incident Status Sections

{% tabs %}
{% tab title="All" %}
This section lists all the incidents of your team for the selected time period. You can select one or more incidents to perform bulk actions.\
\ <mark style="color:blue;">**Note**</mark>: This also includes all the Suppressed incidents.
{% endtab %}

{% tab title="Open" %}
This section lists all the Triggered and Acknowledged incidents of your team for the selected time period. You can select one or more incidents to perform bulk actions.\\

<mark style="color:blue;">**Note**</mark>: You have the option to switch to the respective sections to exclusively view incidents specific to those states.
{% endtab %}

{% tab title="Triggered" %}
This section lists all the Triggered incidents of your team for the selected time period. You can select one or more incidents to perform bulk actions.\
\ <mark style="color:blue;">**Note**</mark>: You have the ability to perform actions such as Acknowledge, Reassign, Resolve, and Update Tags for individual incidents or in bulk.
{% endtab %}

{% tab title="Acknowledged" %}
This section lists all the Acknowledged incidents of your team for the selected time period. You can select one or more incidents to perform bulk actions.\
\ <mark style="color:blue;">**Note**</mark>: You have the ability to perform actions such as Reassign, Resolve, and Update Tags for individual incidents or in bulk.
{% endtab %}

{% tab title="Resolved" %}
This section lists all the Resolved incidents of your team for the selected time period.\
\ <mark style="color:blue;">**Note**</mark>: Once resolved, this action cannot be changed or undone.\
\
Moreover, you have the ability to perform actions such as Update Tags, and Start/View Postmortem for individual incidents. Bulk actions are not supported for Resolved incidents.
{% endtab %}

{% tab title="Suppressed" %}
This section lists all the Suppressed incidents of your team for the selected time period.\
\ <mark style="color:blue;">**Note**</mark>: You have the ability to Update Tags for individual incidents. Bulk actions are not supported for Suppressed incidents.
{% endtab %}
{% endtabs %}

## Trigger an Incident <a href="#bulk-actions" id="bulk-actions"></a>

Depending on your specific use case, there are multiple methods available to trigger incidents in Squadcast:

<table><thead><tr><th width="319">Method</th><th>Manner</th></tr></thead><tbody><tr><td><a href="/pages/ukeyDoL4wVmCU92eaOcb"><mark style="color:blue;"><strong>Trigger an Incident via Integration</strong></mark></a></td><td><p>A common practice is to integrate with third-party platforms, like monitoring tools, and configure them to trigger incidents in Squadcast when certain conditions are met.</p><p>To learn more, visit our Integrations Library.</p></td></tr><tr><td><a href="#bulk-actions-1"><mark style="color:blue;"><strong>Trigger an Incident via Web App</strong></mark></a></td><td>You can trigger an incident and promptly notify the on-call responder by manually opening an incident on a service.<br><br>This method is commonly used to test notification rules or to directly inform the on-call person about an issue with a particular service.</td></tr><tr><td><a href="/pages/saiRLbCLWGiFswbWK7wn#create-incidents"><mark style="color:blue;"><strong>Trigger an Incident via Mobile App</strong></mark></a></td><td>By leveraging the ability to create incidents from the mobile app, you have the ability to trigger an incident on the go.</td></tr><tr><td><a href="/pages/T7cKeVRgItG0jhqwyjx8"><mark style="color:blue;"><strong>Trigger an Incident via Webhooks</strong></mark></a></td><td>We natively integrate with various tools. If you're using an integration that isn't listed, but the tool supports webhook-based integration, you can utilize our incident webhook integration.<br><br>This integration can also be leveraged for triggering incidents in your internal services based on your specific use case.</td></tr><tr><td><a href="/pages/032BKRYuB3C8VVRHO1xa"><mark style="color:blue;"><strong>Trigger an Incident via Webforms</strong></mark></a></td><td>You can expand your customer support, by letting your stakeholders &#x26; customers report issues that trigger incidents in Squadcast.</td></tr><tr><td><a href="/pages/gvX6uilXXAvzZaazIlMQ"><mark style="color:blue;"><strong>Trigger an Incident via Email Integration</strong></mark></a></td><td>By leveraging email integration for a service, you have the ability to trigger an incident simply by sending an email to the designated email address associated with the integration.</td></tr><tr><td><a href="/pages/tf3HBvLw0RKIUQ9SqaV1#trigger-incidents-from-slack"><mark style="color:blue;"><strong>Trigger an Incident via Slack</strong></mark></a></td><td>If your account has the <a href="/pages/KJpQrRZ9C5Q4vqI9dEN8"><mark style="color:blue;">Slack integration</mark></a> configured, you may also trigger an incident using Slack slash commands.</td></tr></tbody></table>

### Create Incident Manually <a href="#bulk-actions" id="bulk-actions"></a>

To create a new incident using the web app,

1. Navigate to the **Incidents List** page -> Click **Create New Incident** on top right.
2. In the side panel, enter the **Incident Title**, *optional* **Description**, select the **Service**, specify who should be notified under **Assign To**, add **Tags.**
3. Click on **Create** to complete.

<figure><img src="/files/cuRpFzu1CcGbxEwagXvV" alt="Create Incident Manually in Squadcast for Incident Management" width="563"><figcaption><p>Image. Create Incident Manually</p></figcaption></figure>

## Search <a href="#bulk-actions" id="bulk-actions"></a>

To search for a specific incident, enter its **Incident Message** in the Search field and hit enter.

## Bulk Actions

To perform bulk actions, please select one or more incidents.

<table><thead><tr><th width="226">Status Section</th><th>Permissible Bulk Actions</th></tr></thead><tbody><tr><td><strong>All</strong></td><td>Based on the selection you make, you can perform actions similar to those displayed for each section.</td></tr><tr><td><strong>Open</strong></td><td><p>✅ Acknowledge</p><p>✅ Reassign</p><p>✅ Resolve</p><p>✅ Update Priority</p><p>✅ Merge Incidents<br><br><mark style="color:blue;"><strong>Note</strong></mark>: If you choose one or more Acknowledged incidents in the bulk selection, performing bulk Acknowledgement won't be possible.</p></td></tr><tr><td><strong>Triggered</strong></td><td><p>✅ Acknowledge</p><p>✅ Reassign</p><p>✅ Resolve<br>✅ Update Priority</p><p>✅ Merge Incidents</p></td></tr><tr><td><strong>Acknowledged</strong></td><td><p>✅ Reassign</p><p>✅ Resolve<br>✅ Update Priority</p><p>✅ Merge Incidents</p></td></tr><tr><td><strong>Resolved</strong></td><td>✅ Update Priority</td></tr><tr><td><strong>Suppressed</strong></td><td>Bulk actions are not supported for Suppressed incidents.</td></tr></tbody></table>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>:

* Bulk actions for updating Tags are unavailable.
* Users will receive email notifications in the event of individual or bulk reassignment.
  {% endhint %}

<figure><img src="/files/9I8ieTwIZJ4wayDmK3mz" alt="Perform Bulk Actions on Incidents in Squadcast for Incident Management" width="563"><figcaption><p>Image. Perform Bulk Actions</p></figcaption></figure>

## Star Incidents

When you star incidents in Squadcast, you mark them as important. This helps you remember to look at them later.

<figure><img src="/files/o0PZuN9Uflgu3gkPrNC5" alt="Star Important Incidents in Squadcast for Incident Management" width="563"><figcaption><p>Image. Star Important Incidents</p></figcaption></figure>

### Star an Incident

To star an incident,

1. Navigate to the **Incidents List** page -> navigate to your desired **Status Tab**.
2. Click on the :star: next to the Incident message, to mark the incident as important.

### Search for Starred Incidents

To search for Starred Incidents,

1. Navigate to the **Incidents List** page -> click on **Filters** icon.
2. Under Show Starred Incidents, click **Yes** -> Click **Apply.**

## Download Incidents

To download incidents,

1. Navigate to the **Incidents List** page -> add the **Filters** of your choice.
2. Click **Download All** -> Select the export format option (CSV or JSON) from the drop-down.
3. Click **Download** to complete.

<figure><img src="/files/pYjaXaqT970qpslraMSH" alt="Download Incidents in Squadcast for Incident Management" width="563"><figcaption><p>Image. Download Incidents</p></figcaption></figure>

{% hint style="warning" %} <mark style="color:orange;">**Incident Export Limit**</mark>**:**

Please note, currently, the export of incidents is limited to a maximum of 1000 per export. Please adjust your filters to ensure the listed incidents remain within this limit for each export. There are no restrictions on the number of exports you can perform.

\
For unlimited incident exports, you can utilize our Export Async API. Upon completion, you will receive an email notification with the download link. For further details, refer to our [<mark style="color:blue;">Export Async API Documentation</mark>](https://apidocs.squadcast.com/#15f17e18-af02-4835-a4a4-59c840e19e16).
{% endhint %}

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 For enhanced efficiency, we encourage utilizing our public API to export incidents in CSV or JSON format. Please refer to the API documentation available [<mark style="color:blue;">here</mark>](https://apidocs.squadcast.com/#3d00d5c6-6b9b-410c-a11b-0da72c60d419).
{% endhint %}

<details>

<summary><mark style="color:blue;">Expand to view the fields included in the exported file, whether in CSV or JSON format</mark></summary>

* Incident ID
* Title
* Description
* Status
* Service
* Alert Source
* Assignee
* Created At
* Acknowledged At
* Resolved At
* Tags
* Event Count
* TTA (Time to Acknowledge)
* TTR (Time to Resolve)
* Activity Logs

</details>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Incident Priorities

Add priority to incidents for classification thus promoting efficient and effective triage.

Incident priority allows you to classify incidents based on a level of prioritization. Establishing incident classification levels and response plans based on priorities and thus, sharing this information throughout the entire organization is ideal. It's important to remember that resolution plans aren’t exclusively for technical responders and support staff; other departments within an organization may also need to be informed about incidents, understand their assessed impact, and occasionally take part in incident response as needed.

If your organization lacks an established incident classification scheme based on priorities, it is crucial and hence, beneficial to define a limited number of classification levels for efficient triage and major incident response processes. Conversely, if you currently utilize more than five classification levels, carefully assess the practical benefits for your organization. A higher number of levels can only lead to increased complexity and time consumption during the triage process. You will need to ensure that incoming incidents are associated with the 5 allowed, pre-defined priority levels in Squadcast.

Incidents can be classified into 5 different priority levels, the allowed values being `P1`, `P2`, `P3`, `P4`, and `P5` with `P1` being the highest priority. If no priority is set for an incident, then it will be `Unset` by default.

<figure><img src="/files/mLQPkf4Y69sold1WdAl1" alt=""><figcaption><p>Incident Priorities on the Incident List Page</p></figcaption></figure>

***

## Prioritize Incidents

Priority of an incident can be set or edited at any point in its lifecycle (across all states - Triggered, Acknowledged, Resolved, Suppressed).

### While Creating a New Incident

Anywhere in the system when you are creating a new incident, you can set a priority level for it by choosing one of the options in the drop-down. However, if the priority cannot be determined yet and is going to be set at a later point in time, you can simply select `Unset` and proceed with incident creation.

<div data-full-width="false"><figure><img src="https://lh7-us.googleusercontent.com/lYWrQFuZvGusKYVaXyOucxxkRTxhpJcwOiHojoe6YdXcydHPeP__FuKFqfifQ_WkEFupZMxnVLUQZ-deptYmYoYqhgJTDdHJuF8ZTYjcXsk5nIlj15n4m-eZTXbSdkFttcE4dxKkTu7FROC0tX_Woxk" alt="" width="375"><figcaption><p>Setting Priority While Creating a Manual Incident</p></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> By default, the priority level for every incident is `Unset`.
{% endhint %}

### For Existing Incidents

Priority levels can be set or edited for incidents either in the Incident List or in the Details page of incidents.

### From the Incident List page

If you are looking to set or edit the priority for a single incident, you can simply hover over the incident and select Update Priority. From the drop-down, you can choose one of the options and that will be updated.

<figure><img src="https://lh7-us.googleusercontent.com/9Q7ErvCoQVRQfYcPYgPwbQeLuBhM13TThxkheY2V9A0FSnnecn1P9-47M1HNsDjUyC-o-wWWj8AqazcbksvFDM0e9FkJ-KYH2hYrKji55mqkBM5nAiISLvoNqNvpVSKZwl1zgbXooLkJ_58jzBTQGoU" alt=""><figcaption><p>Updating Priority for an Incident on the Incident List Page</p></figcaption></figure>

If you are looking to set or edit the priority for multiple incidents in one go, start by selecting multiple incidents and selecting Update Priority bulk action on the top. From the drop-down, you can choose one of the options and the selected priority level will be set for all the selected incidents.

<figure><img src="https://lh7-us.googleusercontent.com/aNkTL3fH4sbQQdz8y6aOXSBFWUCCh8pWLyYhCfdcyVTOWh0jZpZ_2BP9bI8F201IL-Hsx3kUpRdOcFSgWKAdb5JuFbKNNnEmAzZeGigEOfVJIEzY1x5g8VWzO8t3MqxWVrAAH8eRFmi1RxS93FTffnY" alt=""><figcaption><p>Updating Priority for Multiple Incidents on the Incident List Page</p></figcaption></figure>

### From the Details page

In the Details page of an incident, you can click on the Priority drop-down to set or edit the priority level.

<figure><img src="https://lh7-us.googleusercontent.com/O9NYwohW3u5TG5EbjEi2IjM89jmGJG1Hh_Gjxv9nuI3JawueFtE3-IaeRn_WQfJaGRa4D8F83RXw8aA1HTDRfAKUPoz4Ujk5VhpEbA3nFofxWAPq3iY467m5BKR9DI7bcqiUUNT1nOIyTsjh28qp_Gc" alt=""><figcaption><p>Updating Priority on the Incident Details Page</p></figcaption></figure>

Whenever a priority level is set or edited, a log for it is present in the Activity Timeline of the incident.

<figure><img src="https://lh7-us.googleusercontent.com/wS5XAJiHp2DNo47aQ-Pw8FE0pEFpLUEo8ppdDVpyyiW7CVmZMCfNzdzvEe4Y6LdZdh5Xa1u0aWpke4yxMUMAeDxPqKcDr0bCUi4wkXJJVOye3Mb40H5UXgVh74Q8sFm76xgko2srLqFoKGnMzuzbZ6s" alt="" width="375"><figcaption><p>Activity Timeline Update for Updating the Priority</p></figcaption></figure>

***

## Filtering and Sorting

Incidents can be filtered based on priority levels on the Incident List page.

An important outcome of classifying incidents based on priority levels is to be able to view all the high-priority incidents at the top, grouped together so that responders and other members in your organization are informed of the ongoing critical issues. This is possible in the Incident List page by sorting on the **Priority** column.

<figure><img src="https://lh7-us.googleusercontent.com/gaZkjKuw4CiLIlbI7R2QEXS5rukUwWdHl7Cq7LO5TI_dSAHAKwwf7Gcdh2QNfWdum67OyCJoWXr_EM4ZFcCOjzxYvauexC_hzwSqfffEMaXYKGmlbrk-RbUgtCkdRfxYzd_EA-K_al6u_yiioaxypb8" alt=""><figcaption><p>Sorting the Priority Column on the Incident List Page</p></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> This is a one-way sort. When a user clicks the sort icon in the Priority column, all the `P1`s are bubbled on the top, followed by `P2`s, and so on until `P5`. All the `Unset` priority incidents would be grouped below `P5`. If you wish to sort incidents based on the time of creation, you can click the sort icon next to **Created At** and that will reset the sorting based on time.
{% endhint %}

### Filtering on Priorities for Analytics

[Analytics for your Team or Organization](https://support.squadcast.com/analytics/analytics) can be viewed by setting filters, one of the filters now being priorities. Just like with the other filters for Analytics, you can select Add Filters > Priority > Select a level and view results.

<figure><img src="https://lh7-us.googleusercontent.com/1uy5nWeOH-C-cQsXz9sjvVnO-UVJas9Ziq9vfEmGdUyOhswGeJ_cf8sEUmCrFrr37jTB4hZeMiqMPIkz7KGeF9HEgBEAEr4kIPS09aWbrxMeVmuSCggPM_591Z69R1LUQTqr6v2vCrRwgEvJxHh423w" alt=""><figcaption><p>Analytics based on Priority</p></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> Priority levels can be set, edited, viewed, and filtered in the mobile app as well.
{% endhint %}

1. While creating an incident

   <figure><img src="https://lh7-us.googleusercontent.com/wTAoDbiogtGsMne_ffpUZooQB3Nas9XK3ns9SsvxBhFDTsKCbqovegcsESvtS_5tTId7pcuoi7wKRDXqvZNuz-lzmndCL_ow5KADTndI8zNxRTJXSi2yzMrbTb3uo9HqpzXne39x5KujeH9LB6Kl9sw" alt="" width="188"><figcaption></figcaption></figure>
2. From the Details page of an incident

   <figure><img src="https://lh7-us.googleusercontent.com/Eu8DHanllzoiDBp7TmzCgvz49vLAHjuwL9LQwj3WMVKWga1kJ5fL-DKA2XgojPOFBeZb2QVVux_-bFKfp17422gUU-LGKyiCXcTY2EwubG-wzDwDpIXmrpijuzAPURzlUM84MYcuTkVoNq4fOsK8dGE" alt="" width="188"><figcaption></figcaption></figure>
3. Adding Priority as a Filter in the List page

   <figure><img src="https://lh7-us.googleusercontent.com/Unr9hLtmig1bX4wcD_H0PoMS8JKiRNMCXOtNrCAgK5vuFKCIMcQMwJgKzgCAGZyP1_OKtwWhS5O_7RQGfgOCS3ebJL8xDJxqrQYegI42rYAjdkOlrXRfyokeOrisawsjK_Y8idLw1LlPJeks9jK3MO4" alt="" width="188"><figcaption></figcaption></figure>
4. Viewing logs in the Activity Timeline of an Incident

   <figure><img src="https://lh7-us.googleusercontent.com/N_FLGGsrdQB9j_8WcpmhuP-3Ppe-moE28lIVqSftORLwYhtVDZ_HJrHq5XjlSMu7o0w8pvYOJTQmxfg-vB8dzMHShJsGwaLDqfW8sanOYFHchSIjzGgEtHZkGx0uI_jmKti0-XrG2pvAtFudXG1EB70" alt="" width="188"><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Filter Incidents

Enhance your Incident Management with a variety of filters available on the Incident Page. Discover the filters you can apply and streamline your incident handling process efficiently.

## Filters Incidents

To filter incidents,

1. Go to the **Incident List page** -> Choose the desired team from the available options.
2. Locate and click on the **Filter icon** -> Apply the desired combination of filters by selecting options such as **Created at**, **Responders**, **Tags**, etc.
3. Once you have set your filters, click on the **Apply** button.

<figure><img src="/files/ryFNAK68bNIVX9hmwJKi" alt="Filter Incidents in Squadcast for Incident Management" width="563"><figcaption><p>Image. Filter Incidents</p></figcaption></figure>

## Filters

Below is a comprehensive list of filters accessible on the Incident Page:

<table><thead><tr><th width="272">Filter Name</th><th>Description</th></tr></thead><tbody><tr><td><strong>Assignee</strong></td><td>Allows you to filter Incidents based on Responders. They can be Users, Squads, or Escalation Policies.<br><br><mark style="color:blue;"><strong>Note</strong></mark>: The Responder filter's scope encompasses all current and previous responders.</td></tr><tr><td><strong>Created</strong></td><td><p>Allows you to filter Incidents based on their Created Date.<br><br><mark style="color:blue;"><strong>Note</strong></mark>: By default, the Incident Page shows Incidents created in the last <strong>7 days</strong>.<br><br><mark style="color:blue;"><strong>Note</strong></mark>: You will be limited to choosing the custom time range here based on the <a href="https://squadcast.com/pricing"><mark style="color:blue;">plan</mark></a> that you are currently on (data retention by the plan).<br><br>Here are the options for this filter:</p><p><br>1. <strong>Last 24 Hours</strong> - shows incidents for the last 24 hours.<br>2. <strong>This Week</strong> - shows incidents from the beginning of the week (Sunday) to now.<br>3. <strong>This Month</strong> - shows incidents from the beginning of the month to now.<br>4. <strong>Last 7 Days</strong> - shows incidents from exactly the last 7 days. For instance, if a user queries this filter at 17:30 p.m. on 10/10/2023, it will show incidents from 17:30 p.m. on 3/10/2023 to 17:30 p.m. on 10/10/2023.<br>5. <strong>Last 14 Days</strong> - similar logic to the "Last 7 Days" filter.<br>6. <strong>Last 30 Days</strong> - similar logic to the "Last 7 Days" filter.</p></td></tr><tr><td><strong>Service Owner</strong></td><td>Allows you to filter incidents that affect services owned by specific squads or users<br><br>Eg: You can use this filter to find incidents that affect services owned by your squads</td></tr><tr><td><strong>Services</strong></td><td>Allows you to filter Incidents based on their respective Services.</td></tr><tr><td><strong>Tags</strong></td><td><p>Allows you to filter Incidents based on Tags.<br><br><mark style="color:blue;"><strong>Note</strong></mark><strong>:</strong> Without any Service filter, all Tags across Services are displayed. To narrow down Tags by Service, apply the Service filter first.<br><br><mark style="color:blue;"><strong>Note</strong></mark>: <mark style="color:blue;"><strong>Multiple Tag Filters</strong></mark></p><p>Selecting multiple Tag values functions as a logical <mark style="color:orange;"><code>AND</code></mark> operation. To view the list of Incidents for each Tag, perform the selection in multiple steps.</p></td></tr><tr><td><strong>Alert Sources</strong></td><td>Allows you to filter Incidents based on Alert Sources.<br><br><mark style="color:blue;"><strong>Note</strong></mark>: The drop-down shows the valid Alert Sources for the selected date range.</td></tr><tr><td><strong>SLO Affecting</strong></td><td>Allows you to filter Incidents based on the SLOs affected by them.</td></tr><tr><td><strong>Show Incidents with Postmortem</strong></td><td>Allows you to filter Incidents based on whether they contain a Postmortem or not.<br><br><mark style="color:blue;"><strong>Note:</strong></mark> For incidents with a Postmortem, you can further filter the list by their statuses, namely: In Progress, Under Review, and Published.</td></tr><tr><td><strong>Show Incidents with Notes</strong></td><td>Allows you to filter Incidents based on whether they contain a Note or not.</td></tr><tr><td><strong>Show Starred Incidents</strong></td><td>Allows you to filter important Incidents that have been starred.</td></tr></tbody></table>

{% hint style="info" %} <mark style="color:blue;">Note:</mark>

* You can select multiple options per filters, and type in, to search and refine your choices.
* We use "AND" for combining filters and "OR" for each filter condition.
  {% endhint %}

## Find incidents relevant to your squads

### Incidents assigned to you or your squads:

* Your squads are shown at the top of the Assignee dropdown
* You can click on 'select all' to view incidents assigned to you or your squads

<figure><img src="/files/eL7dFD2KzjPWd9t8eLPZ" alt=""><figcaption></figcaption></figure>

### Incidents that affect services owned by you or your squads:

* Your squads are shown at the top of the Service Owner dropdown
* You can click on 'select all' to view incidents that affect services owned by your or your squads

<figure><img src="/files/ZQ7teGTCuQdugxnKPtIg" alt=""><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Save Filter View

Build your filters and save them as views for your Team for quick access

With Squadcast, you have the convenience of saving your applied filters as a quick view option, that can be accessed by you and your entire Team.

## Saving Filter

To save filters,

1. Go to the **Incident List page** -> Choose the desired team from the available options.
2. Locate and click on the **Filter icon** -> Apply the desired combination of filters by selecting options such as **Created at**, **Responders**, **Tags**, etc.
3. Once you have set your filters, click on the **Save Filter** button.
4. Next, enter **Filter Nam**e, and **Scope** (Team or yourself) -> Click **Save**, or **Save and Apply**, to instantly access the Saved Filter view.

<div><figure><img src="/files/0BU6ymL1pYKpKHkjsdwQ" alt="Add Filters in Squadcast for Incident Management" width="563"><figcaption><p>Image. Add Filters</p></figcaption></figure> <figure><img src="/files/1LiNVkB0gMTZ4fnWKDkc" alt="Save Filter view in Squadcast for Incident Management" width="563"><figcaption><p>Image. Save Filters</p></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: Please note the scope of the Saved Filters cannot be altered at a later point. However, you can create a new Saved Filter view if you wish to change the scope
{% endhint %}

## Rename Saved Filter

To rename a Saved Filter,

1. Go to the **Incident List page** -> Choose the desired team from the available options.
2. Locate and click on the **Filter icon** -> **Saved Filter**
3. Locate the Filter view you wish to rename -> Then hover over it, and click **Rename Filter**
4. Provide the new name for the filter as per your requirement -> **Save.**

<div><figure><img src="/files/uZqU1XAC2oahsCSVUHEx" alt="Rename Saved Filter name in Squadcast for Incident Management" width="563"><figcaption><p>Image. Rename Saved Filter</p></figcaption></figure> <figure><img src="/files/nKP6wdnDwJnmIoQBnTlk" alt="Rename Saved Filter name in Squadcast for Incident Management" width="563"><figcaption><p>Image. Save Rename Changes</p></figcaption></figure></div>

## Edit Saved Filter

To edit a Saved Filter,

1. Go to the **Incident List page** -> Choose the desired team from the available options.
2. Locate and click on the **Filter icon** -> **Saved Filter**
3. Locate the Filter view you wish to edit -> Then hover over it, and click **View**
4. Click the **Edit View** icon **->** Make the required adjustments **-> Save Changes.**

## **Delete Saved Filter**

To delete a Saved Filter,

1. Go to the **Incident List page** -> Choose the desired team from the available options.
2. Locate and click on the **Filter icon** -> **Saved Filter**
3. Locate the Filter view you wish to delete -> Then hover over it, and click **View**
4. Click the **Delete** icon **->** A confirmation modal will appear, to confirm, click **Delete**.

## Share Saved Filter View

You can directly share the link to the view of any Saved Filter with the rest of your team. To do this,

1. Go to the **Incident List page** -> Choose the desired team from the available options.
2. Locate and click on the **Filter icon** -> **Saved Filter**
3. Locate the Filter view you wish to share -> Then hover over it, and click **View**
4. Click the **Copy URL** icon

This URL will get copied to the clipboard.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Merge Incidents

Seamlessly merge related incidents created for the same issue for streamlined notifications and resolutions.

When a major incident occurs, there are usually multiple incidents created for the same issue. All these incidents created for a single issue can be associated and linked together under one main Incident.

Merging more than one incident into a single incident streamlines the notification and resolution process. Merging incidents also allows you to consolidate information into a single incident, helping responders identify an issue’s root cause and impact.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: This feature will be available for accounts in the [<mark style="color:blue;">Pro, Premium, and Enterprise plans</mark>](https://squadcast.com/pricing).
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: A merged incident would be represented using the symbol shown below.

<img src="/files/5EH6mM0RkCFmYpVdwqC3" alt="Merge Incident in Squadcast for Incident Management" data-size="line">
{% endhint %}

## On the Incident List

On the **Incident List** page, you can merge two or more open (triggered or acknowledged) incidents (children) with one representative (parent) incident.

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>:

1. Incidents across different services can be merged.
2. Two parent incidents cannot be merged together.
3. All the selected incidents merged into a parent incident will be marked as suppressed.
4. Merging incidents will mark SLO-affected child incidents as false positives.
5. Once the parent incident is resolved, child incidents cannot be unmerged from it.
6. Only incidents in Triggered and Acknowledged states can be merged. Resolved and Suppressed incidents cannot be merged.
   {% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>:

The child incidents that have been suppressed will now live under the parent incident that represents them, and hence will not be shown on the Suppressed tab of the Incident List.
{% endhint %}

To merge incidents on the Incident List:

1. Navigate to the **Incidents List** page -> Select **two or more triggered or acknowledged incidents** from the Incident List.
2. Click **Merge Incidents** -> In the side panel, select a **parent incident**. You can select between the existing incidents or create a new incident.
3. Next, click **Merge Incidents**, and you're done.

The Incident List will then show only a single incident.

<div><figure><img src="/files/XAXEZ3D2xEYQlHRsZaU6" alt="Merge Incidents in Squadcast for Incident Management" width="563"><figcaption><p>Image. Merge Incidents</p></figcaption></figure> <figure><img src="/files/93oDJTyYDZNuGLX6bCa3" alt="Select or Create a parent Incident in Squadcast for Incident Management" width="563"><figcaption><p>Image. Select or Create a parent Incident</p></figcaption></figure> <figure><img src="/files/3TH8Q7GWW8viK0xIsUpm" alt="Merged Incident in Incident List in Squadcast for Incident Management" width="563"><figcaption><p>Image. Merged Incident in Incident List</p></figcaption></figure></div>

## Review Child Incidents

To review the child incidents,

1. Navigate to the **Incidents List** page -> Click on the **parent incident.**
2. In the **Incident Details** page, navigate to the **Child Incidents section**.
3. You can review the Incident Message, Service, Alert Source, and Created At date for the child incidents.
4. You can unmerge any incidents from here.

<div><figure><img src="/files/yWhlENWeNEYY5TAS4iWU" alt="Review Merge Incidents in Squadcast for Incident Management"><figcaption><p>Image. Review Merged Incidents</p></figcaption></figure> <figure><img src="/files/zfPm030XeNacoGLiB4oH" alt="Child Incidents section in Incident Details in Squadcast for Incident Management"><figcaption><p>Image. Child Incidents section in Incident Details</p></figcaption></figure></div>

## Unmerge from Parent Incident

To unmerge incidents from the parent incident,

1. Navigate to the **Incidents List** page -> Click on the **parent incident.**
2. In the **Incident Details** page, navigate to the **Child Incidents section**.
3. On hover, click **Unmerge** -> **Unmerging will re-trigger this incident and it will be assigned to the last assignee, by default.** You can choose to **send a notification to this assignee** by enabling the checkbox. If you wish to assign the incident to yourself, you can do so by enabling the checkbox.\
   \
   **However, if the last assignee for that incident has been deleted, you will have to compulsorily assign the incident to yourself** in order to unmerge.
4. Click **Unmerge.**

<div><figure><img src="/files/JuMKm2impE0lK50ytu9D" alt="Unmerge incidents in Squadcast for Incident Management"><figcaption><p>Image. Unmerge incidents</p></figcaption></figure> <figure><img src="/files/fkEkOaRh2boUTHSwQc5j" alt="Assign unmerged incident in Squadcast for Incident Management"><figcaption><p>Image. Assign Unmerged Incidents</p></figcaption></figure></div>

## Unmerge from Child Incident

Furthermore, you have the option to unmerge a child incident by accessing its Incident Details.

1. Navigate to the **Child Incidents** section -> Select the specific incident you want to work with.
2. Access the detailed view of the chosen child incident -> Click **Unmerge**.
3. **Unmerging will re-trigger this incident and it will be assigned to the last assignee, by default**. You can choose to **send a notification to this assignee** by enabling the checkbox. If you wish to assign the incident to yourself, you can do so by enabling the checkbox.\
   \
   **However, if the last assignee for that incident has been deleted, you will have to compulsorily assign the incident to yourself** in order to unmerge.
4. Click **Unmerge.**

<div><figure><img src="/files/JuMKm2impE0lK50ytu9D" alt="Unmerge incidents in Squadcast for Incident Management" width="563"><figcaption><p>Image. Unmerge incidents</p></figcaption></figure> <figure><img src="/files/EMbPjjcizaAk6QpJ2oGr" alt="Unmerge Incidents from Child Incident Details page in Squadcast for Incident Management" width="563"><figcaption><p>Image. Child's Incident Detail</p></figcaption></figure> <figure><img src="/files/QYQgTjllu9131HHNSMF7" alt="Assign unmerged incident in Squadcast for Incident Management" width="563"><figcaption><p>Image. Assign Unmerged Incidents</p></figcaption></figure></div>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Snooze Incidents

Snooze incident notifications for a certain period and get notifications for the snoozed incidents later.

You can choose to snooze incident notifications for incidents with lower priority and a flexible timeline. By snoozing the incident, all scheduled notifications for that specific incident will be halted and canceled. Users will not receive any notifications during the snooze period.

<figure><img src="/files/rzi2yWibBmtqn0bgc7Nm" alt="" width="563"><figcaption><p>Image. Snooze Incidents</p></figcaption></figure>

## Points to Note <a href="#points-to-note" id="points-to-note"></a>

* The Incident can be snoozed for a maximum of 24 hours.
* When the snooze timer ends, the incident will be assigned to the user who snoozed the incident.
* Incidents can be snoozed multiple times but users cannot snooze an incident when the snooze timer is running.
* Users can unsnooze the incident anytime and the incident can be reassigned to
  * A user who snoozed the incident
  * A user who is currently performing the unsnoozing action
  * Different User/Squad/Escalation Policy

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> Incidents will be unsnoozed automatically when the incident states are changed/when the incident is reassigned.
{% endhint %}

## Snooze an Incident <a href="#snoozing-an-incident" id="snoozing-an-incident"></a>

### From the Incident List Page <a href="#from-the-incident-list-page" id="from-the-incident-list-page"></a>

To snooze an incident from the incident list page,

1. Navigate to the **Incident List page** -> Hover over the incident you wish to snooze.
2. Select **Snooze** -> From the dropdown you can choose one of the options and the incident will be snoozed for the selected hour(s).

<figure><img src="/files/kXTzCzz3jjjMK3cTRCzh" alt="" width="563"><figcaption><p>Image. Snooze incident from the incident list page</p></figcaption></figure>

### From the Incident Details Page <a href="#from-the-incident-details-page" id="from-the-incident-details-page"></a>

To snooze the incident from the incident details page,

1. Navigate to the **Incident Details page** -> Click on **Snooze**.
2. Select the Snooze duration from the dropdown. That’s it Incident will be snoozed for the selected hour(s).

<figure><img src="/files/RgpqdJ6LIorfSh1HDtU8" alt="" width="563"><figcaption><p>Image. Snooze incidents from the incident details page</p></figcaption></figure>

## Unsnooze an Incident <a href="#unsnoozing-an-incident" id="unsnoozing-an-incident"></a>

### From the Incident List Page <a href="#from-the-incident-list-page.1" id="from-the-incident-list-page.1"></a>

To unsnooze a snoozed incident,

1. Hover over the snoozed incident -> Select **Unsnooze.**
2. Select one of the options shown on the side panel and click **Unsnooze and Reassign.**

<div><figure><img src="/files/RycOmg0nvno0Zhh0o3DZ" alt="" width="563"><figcaption><p>Image. Unsooze an incident</p></figcaption></figure> <figure><img src="/files/WNMQRRveCCKpyxDjvU51" alt="" width="563"><figcaption><p>Image. Reassign the incident</p></figcaption></figure></div>

### From the Incident Details Page <a href="#from-the-incident-details-page.1" id="from-the-incident-details-page.1"></a>

To unsnooze an incident from the incident details page,

1. Navigate to the incident details page -> Click on **Unsnooze.**
2. Select one of the options shown on the side panel and click **Unsnooze and Reassign.**

<div><figure><img src="/files/ZuiX90aoT0YqbXb9bb5f" alt="" width="563"><figcaption><p>Image. Unsnooze an incident</p></figcaption></figure> <figure><img src="/files/JepQy39IDdwHa9QHsjBw" alt="" width="563"><figcaption><p>Image. Reassign the incident</p></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: Please note that the actions related to unresolved incidents will not be executed for incidents that have been snoozed.
{% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Incidents Details

Get more details of an incident

{% embed url="<https://www.youtube.com/watch?v=QdL2Jcn_c3w>" %}

An incident represents an issue that needs to be addressed and resolved. Incidents trigger on services, and a service’s escalation policy prompts notifications to go out to on-call responders to remediate the issue.

### Incident Statuses <a href="#statuses-of-an-incident" id="statuses-of-an-incident"></a>

<figure><img src="/files/UIkkKoBrYbLj1gTUcu5a" alt="Incident Statuses in Squadcast"><figcaption></figcaption></figure>

### Incident Details Page

To view the Incident Details Page, select the **Team** from the team picker on the top -> Navigate to the **Dashboard** or the **Incidents** page from the sidebar and open incidents.

<figure><img src="/files/ZksuFq7IGKh97VUIR8nG" alt="Navigate to Incident Details Page in Squadcast"><figcaption></figcaption></figure>

Click on any Incident from the Incident List to view the Incident Details page.

<figure><img src="/files/MgbKsz3Y1brnGL9oJh4L" alt="Incident Details Page in Squadcast"><figcaption></figcaption></figure>

The Incident Details page has many components:

| Component              | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Incident ID            | <p>A unique ID for the incident</p><p><img src="/files/AdwqjxLAZWnnOa9fFhrX" alt="Incident ID in Squadcast"></p><p><strong>Note</strong>: To copy this Incident URL to the clipboard, use the <strong>Copy</strong> button on the right</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Incident Message       | The displayed title of the incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Incident Watchers      | Incident Watchers can choose to receive notifications for all the updates of an Incident. This allows any user/stakeholder to act as an observer of the incident. You can customize your subscription to the incident by choosing between the watch options. Know more about Incident Watchers [<mark style="color:blue;">here</mark>](/incidents-page/incident-watchers).                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Incident Tags          | <p>Tags are key-value pairs, added to an incident.</p><p>They allow you to quickly see relevant information, such as severity or environment, for a particular incident rather than needing to review all of the related alerts</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Incident Description   | Incident Description i.e. the alert information along with images and links sent by the Alert Source                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Notes                  | Incident Notes enable you to add important notes for you and your team that can help mitigate an incident faster                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Runbooks               | <p><a href="/pages/a2el7FzBmziidHUp3Z26">Runbooks</a> are a “how-to” guide for completing a commonly repeated task or procedure while working on a critical incident.</p><p><strong>Note</strong>: Simple Runbooks will be available for accounts in the <a href="https://www.squadcast.com/pricing">Pro and Enterprise plans</a>.</p><p>To attach and reference runbooks to your incident, click on the <strong>Attach Runbooks</strong> button -> Check the runbook you wish to attach -> Click <strong>Add Runbook</strong><img src="/files/LMvrgnhMa5kMTzXPudiN" alt="Runbooks in Squadcast"></p>                                                                                                                                                                                                                                             |
| Tasks                  | <p><a href="/pages/a2el7FzBmziidHUp3Z26#incident-tasks">Tasks</a> are instructions or to-dos for other team members or even follow-up tasks for an incident.</p><p><strong>Note</strong>: Tasks will be available for accounts in the <a href="https://www.squadcast.com/pricing">Pro and Enterprise plans</a>.</p><p>To add your tasks, click on the <strong>Add Task</strong> button -> Add your Task -> Click on <strong>Add Task</strong> again, to save</p><p><img src="/files/yz5GRG3ZbiFUOCqtl2oi" alt="Tasks in Squadcast"></p><p>Once added, you can Edit/Update and Delete the Task.</p>                                                                                                                                                                                                                                                |
| Acknowledge            | To mark an incident as Acknowledged                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Reassign               | To reassign an Incident to another User, Squad or an Escalation Policy                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Resolve                | If Resolution Reason is marked mandatory for an organisation, incident cannot be resolved without providing a reason. Otherwise, user can simply go ahead and mark incident as resolved.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Actions                | Actions are used to create JIRA tickets or take actions via [Circle CI](/integrations/extensions/circleci)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Incident Details       | <p><strong>Incident Details displays</strong>:</p><p>1. When the incident was <strong>created</strong> in Squadcast<br>2. <strong>Alert Source</strong> via which the incident was created<br>3. <strong>Affected Service</strong> for which the incident was created<br>4. <strong>Elapsed time</strong> since the incident got created in Squadcast</p><p>Note: Hover over the <strong>created field</strong> to view the exact Date and Time of the creation of the incident.<img src="/files/BqhUwLInPiTz2Th29Pml" alt="Incident Details View in Squadcast"></p>                                                                                                                                                                                                                                                                              |
| Responsiveness         | <p>Responsiveness displays:<br>1. <strong>Created</strong> - Time elapsed since the creation of the incident<br>2. <strong>Latest Ack</strong> - Time elapsed since the latest Acknowledgement of the incident. Will change every time the incident is reassigned<br>3. <strong>First Ack</strong> - Time elapsed since the first Acknowledgement of the incident<br>4. <strong>Resolution Time</strong> - Time elapsed from creation to the resolution of the incident<img src="/files/tP7TLD5ydXfQJjpnH9v2" alt="Responsiveness View in Incident Details Page"></p>                                                                                                                                                                                                                                                                             |
| Communication Channels | <p>Communication Channels help you add video calls, chatops and external links to an incident. Additionally, you can create a dedicated Slack Channel for an incident using the Communications Card.<br></p><p><img src="/files/eg2ePDZrXMP5Kvrc3XC9" alt="Add communication channels for Incident Management in Squadcast"></p><p>To add a Communication Channel, Click on <strong>+Add Link</strong> -> Select the type of channel you want to add -> Add the link and Text to Display for your Communication Channel -> Click on <strong>Save</strong></p><p>Once added, you can <strong>Edit/Update</strong> the Communication Channel.<br><img src="/files/0qAMW0GS25IAyInhEoO4" alt="Save communication channels in Squadcast"></p><p>Any activity in the Communications Card, gets reflected on the Activity Timeline of the incident.</p> |
| Responders             | Responders will display the list of all Users, Squads or Escalation Policies that were involved during the lifecycle of the incident. Select **Notification Logs** to open up logs of all the notifications generated for the incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Activity Timeline      | <p>Activity Timeline will indicate the list of all activities performed on this incident in reverse chronological order</p><p><strong>Note</strong>: Activity Timeline will show incident reassignment, mentioning both the assigned and assignee.</p><p><strong>Note</strong>: Downloading Activity Timeline will be available for accounts in the <a href="https://www.squadcast.com/pricing">Pro and Enterprise plans</a>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                 |
| SLO Details            | <p>You can select the affected SLO for an incident. It will give you details on the affected SLO, SLIs and the Error Budget.</p><p>Additionally, you can mark the <strong>Incident</strong> as <strong>False Positive</strong> from here as well.<br><img src="/files/ja8zrqH4e88O2VqyQtoc" alt=""></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Update Status Page     | Update Status Page is used to update your Status Page for this incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Create Postmortem      | Create Postmortem will let you start/update the Postmortem for the incident![](/files/1xxWBgY3am6yBb9g1jSx)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Deduped Events         | <p>If the incident has deduplicated events, they will be listed under <strong>Deduped events</strong>.</p><p>By clicking on <strong>Deduped events</strong>, you will be able to see the following:</p><p>1. Number of deduplicated events<br>2. Event Timestamp<br>3. Message and Payload of the event</p><p><img src="/files/jbkSQc4THLiDmcj5EYyY" alt="View Deduped Events in Squadcast"></p><p>Clicking on any of the deduplicated events will display all the information that is sent for that alert from the monitoring tool, including the <strong>Deduplication Reason</strong> (which Deduplication Rule got executed).<img src="/files/McrPKXr4DczuNxQFNsqT" alt="View Deduped Incidents for Incident Management"></p>                                                                                                                 |
| View Payload           | <p>To view your latest incoming payload.</p><p><br></p><p><strong>Note:</strong> The search option under payload is not a free search, we have to search by JSON format, for example, type in payload.annotations to get annotations.</p><p><br>We also have an option for click-to search, wherein you can click on the keys in the payload to get their required values.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |

### Understanding Resolution Reason

This feature will be available for organisations in the Premium and Enterprise pricing plan.

Enabling Resolution Reason requirement for incident resolution in an organisation would be the first step before users can start adding reasons before resolving incidents on a mandatory basis.

Navigate to Settings > Feature Settings > Enable / Disable Resolution Reason

* Enabling Resolution Reason would make it **mandatory** in order to resolve an incident
* Disabling Resolution Reason would make it **optional** in order to resolve an incident

<figure><img src="/files/9usslBqHdErVz9BidhhK" alt=""><figcaption><p>Enabling and disabling Resolution Reason</p></figcaption></figure>

Entering reason for resolution while resolving an incident would essentially be a modal like below.

<figure><img src="/files/eLQ1n4ep5zRnI8qnoS4y" alt=""><figcaption><p>Resolution Reason modal</p></figcaption></figure>

Once resolution reason is added for an incident, it appears in two places.

1. In the Notes section, as a pinned Note

<figure><img src="/files/mZ8dusB0yEE69VouzO9U" alt=""><figcaption></figcaption></figure>

2. In the Activity Timeline along with the resolution log

<figure><img src="/files/7r1VqypJ5iEekDqnDANf" alt=""><figcaption></figcaption></figure>

For auto-resolved incidents, the resolution reason would automatically get added as:

> Incident marked as Automatically Resolved by \<alert source name>.

### Incident Details Field Limitations <a href="#incident-details-field-limitations" id="incident-details-field-limitations"></a>

There are certain character limitations for the Incident Message and Incident Description fields. The same is indicated below.

| Incident Field       | Character Limit |
| -------------------- | --------------- |
| Incident Message     | 250             |
| Incident Description | 15000           |

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Incident Activity Timeline

View the Activity Timelines of an Incident

You can access the **Incident Activity Timeline** for a particular incident on the **Incidents** page in the web app and the timeline will be displayed on the right-hand side of the **Incident Details** page.

<figure><img src="/files/dJP6BZz8p9jBWzyfTYQm" alt="Incident Activity Timeline in Squadcast"><figcaption></figcaption></figure>

The Incident Timeline will display the timeline of the incident in reverse chronological order for the following details:

**(a)** when the incident was first **triggered** and **acknowledged**

**(b)** who **acknowledged** it

**(c)** who **reassigned** it and who it is **reassigned** to

**(d)** who **resolved** it and when

**(e)** what message was posted on the **status page**

**(f)** by whom and when the **postmortem** was created

**(g)** what **action** was taken

**(h)** starred comments from the **notes**

**(i)** if the incident is suppressed due to a **scheduled maintenance**

<figure><img src="/files/t5BUCTeLXWJDttJu9BSu" alt="Incident Suppression update in Incident Activity Timeline"><figcaption></figcaption></figure>

**(j)** if the incident is routed due to a **routing rule**

<figure><img src="/files/wz47j9PrjogvF3EjKTJw" alt="Routing Rules in Incident Activity Timeline"><figcaption></figcaption></figure>

**(k)** if the incident is suppressed due to a **suppression rule**

**(l)** when a **postmortem status** is updated

<figure><img src="/files/QwbutsbtxdspLsKeGpuG" alt="Auto Suppression update in Incident Activity Timeline"><figcaption></figcaption></figure>

As and when we add new features that affect an incident into the platform, related logs will get added to the incident's activity timeline

#### Exporting Incident Activity Timeline <a href="#exporting-incident-activity-timeline" id="exporting-incident-activity-timeline"></a>

The automated **Incident Activity Timeline** serves as a real-time chain of incident resolution activity. You can download this and use it for **Incident Reviews** or create **Postmortems**. **Incident Activity Timeline** can be exported by clicking on the **Download** icon at the top right corner of the **Activity Timeline**. You can download this in PDF or CSV formats.

![Download Incident Activity Timeline](/files/XZf2MfuFz0hFj1L7q54Q)

## Manually Edit the Activity Timeline

If you are on our higher plans - either Premium or Enterprise, you will have the ability to manually add, edit and delete manual log entries into the activity timeline.

To add manual logs into the activity timeline, select **+** as highlighted below.

<figure><img src="/files/YiC36H7ZBTIEXEn3rusd" alt=""><figcaption></figcaption></figure>

**Note:** Enter the contents of the log entry that needs to be added.

**Timestamp:** Select the timestamp that needs to be associated with the log entry. Based on the timestamp selected, this log will get placed accordingly either on top, at the end or in between other logs that are already present (chronological order). Timestamp selection cannot be at a date and time that is prior to the incident being triggered.

**Show in Postmortem:** Typically, when referenced, the activity timeline of the incident shows up in the the postmortem for the incident. Users can now decide if they want the manually added log entries also to show up in the postmortem or not, along with the default system log entries present in the activity timeline.

Once you click **Save**, this log will get added to the activity timeline.

<figure><img src="/files/JoCDYoA8vKflDb2zTDMG" alt=""><figcaption></figcaption></figure>

Once the manual log gets added to the activity timeline, it will be indicated by a different symbol for visual differentiation between a manually added log versus system logs.

Hovering over the manually added log gives you an option to either edit it or delete it as well.

<figure><img src="/files/OHKMmLHNOliLNGFOU36X" alt=""><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Communication Channels

Enhance incident management communication - Add video calls, chatops, and external links to incidents. Create dedicated Slack Channels for seamless collaboration.

{% embed url="<https://www.youtube.com/watch?feature=youtu.be&v=k_WQhWJvnCQ>" %}

To add a Communication Channel,

**(1)** Click on **+ icon** or **+Add Link** button

<figure><img src="/files/H1PWewpOybeRj45uXKDP" alt="Add Communication Channels in Squadcast"><figcaption></figcaption></figure>

**(2)** Select the type of channel you want to add

![Add Communication Channel](/files/u9vrCsHTpNPJXiq5wCgP)

**(3)** Add the link and Text to Display for your Communication Channel -> Click on **Save**

![Add Communcation Channel link and Label](/files/GssUXKK9nwpn8Dx9sJ0v)

Once added, you can **Edit/Update** the Communication Channel.

{% hint style="info" %}
**Note:**

Any activity in the Communications Card gets reflected on the **Incident Activity Timeline**.
{% endhint %}

### Creating Slack Channel for Incidents <a href="#creating-slack-channel-for-incidents" id="creating-slack-channel-for-incidents"></a>

To create a Slack Channel for an Incident,

**(1)** Navigate to the Incident Details page, and click on the **+ icon** or **+ Add Link** button

<figure><img src="/files/Fu4GYPPVGXuR566QynYt" alt="Create Slack Channels for Incidents"><figcaption></figcaption></figure>

**(2)** Click on the **Create Slack Channel** option from the menu

![Create Slack Channel for an incident in Squadcast](/files/LFXY07HFG0L3wytXUmYp)

**(3)** Type in the **Channel Name** for your Incident and click **Save**

![Save the Slack Channel to an incident](/files/pntojx9JTil1wTRfG9Yr)

This will generate a dedicated Slack Channel for your Incident.

{% hint style="info" %}
**Note**\
All notifications of this specific incident like Acknowledged, Re-assigned, **and** Resolved will be sent to this channel in addition to the regular channel (if configured).
{% endhint %}

{% hint style="info" %}
**Note**\
Once the Incident is resolved, you can archive the Slack Channel using the **Archive** button on the right.

<img src="/files/HedqwlGKho388Z3l8bFy" alt="Archive a Slack Channel" data-size="original">
{% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Create Incident Manually

Tigger incidents manually

Incidents can be triggered manually either from the **Incident Dashboard** or the **Incident** page.

First, select the **Team** from the team picker on the top.

<figure><img src="/files/ghRuZWZbec61g0IAY5cD" alt="All incident page Squadcast"><figcaption></figcaption></figure>

### Triggering Incidents in the **Incident Dashboard** <a href="#triggering-incidents-in-the-incident-dashboard" id="triggering-incidents-in-the-incident-dashboard"></a>

Click on **+** right next to the **Actions** dropdown tab

<figure><img src="/files/NfObM75yNcl1Qlbj3AjD" alt="Triggering Incidents in the Incident Dashboard"><figcaption></figcaption></figure>

### Triggering Incidents on the **Incidents** page <a href="#triggering-incidents-in-the-incidents-page" id="triggering-incidents-in-the-incidents-page"></a>

**(1)** Click on **Create an Incident**

<figure><img src="/files/DLzHlJbzCXIiQEK4Fqgj" alt="Triggering Incidents on the Incidents page"><figcaption></figcaption></figure>

**(2)** Add details in the relevant fields:

<figure><img src="/files/0Flo9VBvWRLbTcdofMjT" alt="Create an Incident"><figcaption></figcaption></figure>

* **Incident Title** - This would be the title/message of the incident being created
* **Incident Description** - This would be the description of the Incident being created. This is an optional field.
* **Service** - Select the relevant **Service** to which this incident would be mapped
* **Assigned To** - Upon choosing the **Service**, the default **Escalation Policy** associated with the **Service** would be auto-filled. You can choose to manually update the **Assigned To** field to a different **Escalation Policy** or a specific **User** or **Squad** in your Team
* **Tags**

<figure><img src="/files/n79LRWllNbDBi95mrko6" alt="set tags for incidents"><figcaption></figcaption></figure>

* By default, you will have the option to add **Tags** to an incident (either while creating the incident or after the incident is created)
* You can do so by assigning the <mark style="color:red;">`tag name (key)`</mark> and <mark style="color:red;">`tag value`</mark> in the text fields provided and you can also change the tag colour by clicking on the colour of your choice
* You can also add multiple tags by clicking on the **+** option
* Adding a **Tag** is optional

**(3)** Click on **Create new incident** to trigger the incident

### Adding Attachments to Incident Description <a href="#adding-attachments-to-incident-description" id="adding-attachments-to-incident-description"></a>

You can add a variety of file types as an attachment to your incident’s description.

To attach a file, drag and drop the file to the markdown editor. You can also copy-paste the file directly into the markdown editor.

The maximum size for a single file is 10 MB (for upload). You can upload a maximum of 5 files at a time.

The storage limit for an organization depends on the plan:

* For Free plan - the limit is 50 MB
* For Pro and Enterprise plans - the limit is unlimited

File uploads won’t work if the plan limit has been reached. The file once uploaded cannot be deleted.

The supported file types are:

* Images (.png, .jpg, .jpeg)
* Word Processors (.doc, .docx, .odt, pages)
* Spreadsheets (.xls, .xlsx, numbers)
* PDFs (.pdf)
* Presentations (.ppt, .pptx. .odp)
* Miscellaneous (.log, .txt, .eml, .msg, .csv, .key, .json)

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Incident Notes

Share notes and collaborate with your team during incident resolution

**Incident Notes** enable you to add important notes for you and your team that can help mitigate an incident faster.

You can use this to:

* Collaborate with your team and resolve the incident
* Use it to store important pointers that will help with the mitigation
* Use it to store Notes that can be populated in the Postmortem report
* Share Team-wide information like resolution reasons, follow-up tasks, etc.

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* Only verified users would be receiving any kind of notifications from Squadcast
* For receiving Push notifications, users should have the latest version of the [<mark style="color:blue;">Squadcast mobile app</mark>](/mobile-app/using-the-mobile-app) installed

### To get started <a href="#to-get-started" id="to-get-started"></a>

First, select the **Team** from the team picker on the top.

**(1)** Click on either **Dashboard** or **Incidents** from the sidebar

<figure><img src="/files/ghRuZWZbec61g0IAY5cD" alt="All incident page Squadcast"><figcaption></figcaption></figure>

**(2)** Open an incident to view the **Incident Details**

<figure><img src="/files/WFUSEd0SIC0Qa5ZhvP8W" alt="Squadcast - Incident details page"><figcaption></figcaption></figure>

#### Mentioning Users, Squads and Teams in Notes. <a href="#mentioning-users-squads-and-teams-in-notes" id="mentioning-users-squads-and-teams-in-notes"></a>

* Users can call out other users using the “@” symbol for important notes. This action will notify them of the mention via Push and Email. This will also add them as Incident Watchers for that incident. Such users, by default, will start receiving updates on state changes on an incident and comments in notes, via Email.
* Users can also notify all the members of a particular squad or a team by “@” mentioning the squad or the team name.

![Mentioning Users, Squads and Teams in Notes.](/files/PDsphnwjJdnRvTWkCgdV)

* Users who are currently on-call are indicated with a green dot against their name. In the above screenshot, you can see that **Diane Nyugen** is currently on-call
* The mentioned Users, Squad or Team members will get notified instantly via **Email** and **Push** notification on the Squadcast mobile app. However, the author of the note will not get notified even when they are self-mentioned or belong to a mentioned Squad or Team

![Incident note mention notifications](/files/UILTwbpXBcGFwN3beD3A)

![Incident note mention notifications](/files/lss6zQLf02fBaZyhYgwX)

#### Adding Images <a href="#adding-images" id="adding-images"></a>

* Incident Notes support Markdown text format. Hence, images can be added as URLs or links

<figure><img src="/files/4QpnvRZ6P8Ja4TJSUb4K" alt="Incident Notes support Markdown text format"><figcaption></figcaption></figure>

**Adding Images to a Note**

You can use the below syntax to add an image:

```
![image_name](image_url)
```

![Adding Images to a Squadcast Note](/files/oDAHhQKpKlNrKLONOHk8)

#### Editing or Deleting a Note <a href="#editing-or-deleting-a-note" id="editing-or-deleting-a-note"></a>

* One can **Edit** or **Delete** existing notes as well by clicking on the **More** icon corresponding to a particular note which would appear on hovering over the note

![Editing or Deleting a Note](/files/FvqFDH1dFSnIMsBJBGcj)

#### Starring and Un-starring Notes <a href="#starring-and-un-starring-notes" id="starring-and-un-starring-notes"></a>

* Star important notes by clicking on the **Star** icon as shown in the screenshot above beside the **More** option

![Starring and Un-starring Notes](/files/nLikIACKgkWfIlBCwbUb)

* When you have a bulk of Notes and want to simply take a look at all the important, Starred Notes, you can do so by clicking on **View Starred Notes**

![View Starred Notes](/files/Qgs5MsBHu55Mmlq7QoyH)

* To un-star, click on the **Star** icon for that note

![To un-star Starred Notes](/files/ybXlis2F09wdSfB6jClC)

* Starred notes would be captured in the **Incident Activity Timeline**. Clicking on the starred note activity in the **Incident Activity Timeline** will take you to that specific note in the Incident Notes section

![Starred notes in Incident Activity Timeline](/files/p2It3QG3cJ7rccbrTwsP)

### Adding Attachments <a href="#adding-attachments" id="adding-attachments"></a>

You can add a variety of file types as an attachment in the Notes section for an incident.

To attach a file, drag and drop the file to the markdown editor. You can also copy-paste the file directly into the markdown editor.

The maximum size for a single file is 10 MB (for upload). You can upload a maximum of 5 files at a time.

The storage limit for an organization depends on the plan:

* For Free plan - the limit is 50 MB
* For Pro and Enterprise plans - the limit is unlimited

File uploads won’t work if the plan limit has been reached. The file once uploaded cannot be deleted.

The supported file types are:

* Images (.png, .jpg, .jpeg)
* Word Processors (.doc, .docx, .odt, pages)
* Spreadsheets (.xls, .xlsx, numbers)
* PDFs (.pdf)
* Presentations (.ppt, .pptx. .odp)
* Miscellaneous (.log, .txt, .eml, .msg, .csv, .key, .json)

### Jira Notes Sync

Sync your Jira notes seamlessly with your Squadcast account. This bidirectional sync ensures that any comment added to a Jira ticket will automatically appear in the Incident Notes section in Squadcast, and vice versa.

<div><figure><img src="/files/lF2fGeI3e5UwllH7ua7U" alt=""><figcaption><p>Jira Notes in the Incident Details Page</p></figcaption></figure> <figure><img src="/files/pd5qCtBAI0sENEQFxMxS" alt=""><figcaption><p>Squadcast Notes in Jira</p></figcaption></figure></div>

In Squadcast:

* You can star a Jira note to mark it as important.

In Jira:

* You can edit or delete Squadcast incident notes directly from Jira.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

For all new users, this feature will be available upon configuring the extension. Existing users will need to update the Squadcast bot in Jira by following these steps:

1. In Jira Cloud, navigate to the **Apps** dropdown present in the top navigation bar.
2. Click on the **Manage Apps** button.
3. Search and click on the **Squadcast bot** from the Manage Apps page.
4. Then select the **Update** option to update the bot.

<img src="/files/oHNNQUsXGFb2JyUNDriF" alt="" data-size="original"><img src="/files/lIJDRyQw2ahiI9oOnkjR" alt="" data-size="original"><img src="/files/6C5ZyOPqVubyviX6RLXq" alt="" data-size="original">
{% endhint %}

### FAQs <a href="#faqs" id="faqs"></a>

**(1)** What actions can be taken by the different User Types?

* **Note Creation**: Any user can add a note
* **Note Updation**: Only the author of the note can update it
* **Note Deletion**: Only the author of the note can delete it
* **Note Starring and Un-starring**: Any user can star/un-star any note

**(2)** Can I add and star notes from the Squadcast mobile app?

Yes, users can add, edit, delete, star and unstar notes for an incident from the Squadcast mobile app.

To do so:

* Login to your Organization on the Squadcast mobile app, choose your Team and open an incident

![Open incident in mobile app](/files/kRdqVto61QUXAgBleyZC)

* “@” mention a user and/or add notes

![@ mention a user/squad in a note](/files/8Rcp5rcQTAs6FvyJxi6C)

* **A long press on a note authored by you will give you an option to \_star, un-star, edit and delete** *it. A long press on a note authored by others will give you an option to only* **star, un-star**\_ it

![A long press on a note option](/files/jVeE52B6VddGpsmejBL3)

* View only starred notes by switching to **Starred Notes** tab

![View Starred Notes](/files/8gl59d3SMzziEEKKzBLF)

**(3)** Can I notify stakeholders in the notes section?

Yes, you can “@” mention stakeholders to add them as [<mark style="color:blue;">Incident Watchers</mark>](/incidents-page/incident-watchers). So, they would be notified of the note via email and push and start receiving notifications about the ongoing incident via email.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Incident Watchers

Add watchers to your incident, allowing them to be notified about all the updates to that incident.

In Squadcast, any user/stakeholder can subscribe to an Incident and act as a Watcher for an incident.

Incident Watchers can choose to receive notifications for all the updates of an incident. This allows any user/stakeholder to act as an observer of the incident, even if they are not active responders. You can customize your watch options for the incident and receive notifications only for those updates.

{% hint style="info" %}
This feature is available as part of the Product Trial and [<mark style="color:blue;">Pro, Premium, and Enterprise Plan.</mark>](https://www.squadcast.com/pricing)
{% endhint %}

### **Add Incident Watchers**

You can add users/squads/team as Incident Watchers by @mentioning them in an incident note. Once done, they will start receiving notifications on all the updates. All the notifications will be sent out via email and push.

You can view the list of Incident Watchers for an incident by clicking on the eye-icon on the top, in the incident details page, under the Incident Watchers tab.

<figure><img src="/files/PUgI1XsjaKLeE0VSAed1" alt="Add Incident Watchers"><figcaption></figcaption></figure>

{% hint style="info" %}
**Note:**

A user can add themselves as Incident Watcher by @mentioning themselves in the incident notes, in addition to using the watch toggle method.

<img src="/files/NV6H4kcSbLUWu7LrqS8f" alt="Add Incident Watchers" data-size="original">
{% endhint %}

### **Observe an Incident (Become an Incident Watcher)**

To start observing an incident, follow one of the two ways:

#### A. **Use the Watch toggle**

1. Navigate to the incident details page.
2. Click on the **eye-icon** on the top left of the incident details page.
3. Switch the **Watch toggle**, and expand the accordion to select between the watch options.
4. You can select between the following watch options:
   1. **Incident Lifecycle + Notes**: To receive notifications on all states of an incident + every comment added in the note section.
   2. **Incident Lifecycle:** To receive notifications on all states of an incident i.e, when an incident is acknowledged, resolved, reassigned.
   3. **All activity**: To receive notifications on all states of an incident, comments added in notes section, actions on incidents - like adding tasks, attaching runbooks, adding communication channels, updating status page, starting postmortems, adding tags, adding affected SLOs.

<figure><img src="/files/c2zY3gjV9V3O5Bv4C0BS" alt="Observe an Incident"><figcaption></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>**:**

By default, your watch preference would be Incident Lifecycle + Notes.
{% endhint %}

#### B. **@mention yourself in the incident notes**

You can start observing an incident by @mentioning yourself in the incident notes. Once you do, you will start receiving notifications on all the updates.

<figure><img src="/files/NV6H4kcSbLUWu7LrqS8f" alt="mention yourself in the incident notes"><figcaption></figcaption></figure>

### **Remove Incident Watchers**

Users can remove themselves by switching the Watch toggle under the eye-icon. You will be removed from the Incident Watchers list and stop receiving the notifications for the incident.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Past Incidents

View similar incidents from the past to gain insights and shorten incident resolution time.

The Past Incidents feature helps incident responders by showing similar past incidents on the same service. It uses data science techniques to match and display a historical list of similar incidents from the same service you are currently investigating.

This helps them resolve issues faster by providing historical context, previous incident activity and involvement, timing patterns, and past solutions.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: This feature will be available for accounts in the [<mark style="color:blue;">Enterprise plan</mark>](https://www.squadcast.com/pricing).
{% endhint %}

## View Past Incidents

To view the Past Incidents for a parent incident,

1. Navigate to the **Incidents List** page -> Click on an **incident** from the Incident List.
2. In the **Incident Details** page, under the **Details** section -> **Past Incidents**.
3. By default, you can review the top 5 relevant incidents that have been resolved in the past.

To view Past Incidents from a specific date, click on the relevant date square from the heat-map.

<div><figure><img src="/files/nG1dgshEExNWUYmeRHmi" alt="Past Incidents on the Incident Details page in Squadcast for Incident Management"><figcaption><p>Image. Past Incidents on the Incident Details page</p></figcaption></figure> <figure><img src="/files/fxRaiy50ZnFG3X6fptR0" alt="View Past Incidents in Squadcast for Incident Management"><figcaption><p>Image. View Past Incidents</p></figcaption></figure></div>

## Past Incident Details

Here are the details shown for the relevant incidents

<figure><img src="/files/WIVt2TXuPPiTYosvloA1" alt="Past Incidents in Squadcast for Incident Management" width="563"><figcaption><p>Image. Top 5 Relevant Incidents</p></figcaption></figure>

<table><thead><tr><th width="201">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Incident Message</strong></td><td>Shows the incident title of the past incident.</td></tr><tr><td><strong>Alert Source</strong></td><td>Shows the alert source from where the incident came in.</td></tr><tr><td><strong>Assignee</strong></td><td>Shows the latest responder of the past incident.</td></tr><tr><td><strong>Created At</strong></td><td>Displays the date and time of the incident creation.</td></tr><tr><td><strong>Resolution</strong></td><td>Coveys the resolution type for the past incident: Automatic or Manual.</td></tr><tr><td><strong>TTR</strong></td><td>Shows the time taken to resolve the past incident.</td></tr><tr><td><strong>Incident Activity</strong></td><td><p>Present the past incidents in descending order of activity. This is a system generated measure based on the response and resolution activities taken during this incident.</p><p><br><span data-gb-custom-inline data-tag="emoji" data-code="1f4a1">💡</span> <strong>Incident activity</strong> is determined by the incident activity score, which takes into account actions taken on the incident, such as attaching a Runbook, adding a Task, and other relevant activities.<br><br><strong>Here is the exact list of activities that we measure:</strong> Incident Reassign, Tags Manually Added, Incident Actions Taken, Marked as SLO Affecting, Communication Link Added, Notes Added, Noted Starred, Postmortem Created/Edited, Runbook Attached, Tasks Added.</p></td></tr></tbody></table>

Additonally, it also displays the following incident stats:

<figure><img src="/files/imOAW5OGtW3T2ryDXaqr" alt="Past Incidents Stats in Squadcast for Incident Management" width="563"><figcaption><p>Image. Past Incidents Stats</p></figcaption></figure>

<table><thead><tr><th width="205">Component</th><th>Description</th></tr></thead><tbody><tr><td><strong># of occurrences in the last 6 months</strong></td><td>Shows the frequency of occurrence of similar incidents over the last 6 months. It also displays the median TTR of all these past incidents in this period.</td></tr><tr><td><strong># of occurrences in the last 3 months</strong></td><td>Shows the frequency of occurrence of similar incidents over the last 3 months. It also displays the median TTR of all these past incidents in this period.</td></tr><tr><td><strong># of occurrences in the last week</strong></td><td>Shows the frequency of occurrence of similar incidents over the last 7 days. It also displays the median TTR of all these past incidents in this period.</td></tr><tr><td><strong>Heatmap</strong></td><td>The Past Incidents heatmap provides a six-month overview of comparable incidents related to the service you're currently assessing.<br><br>In this visualization, the intensity of the square's color reflects the frequency of incidents on each respective day. Darker squares correspond to days with a higher incident count, while lighter ones indicate fewer occurrences.<br><br><mark style="color:blue;"><strong>Note:</strong></mark> <mark style="color:blue;">For a more detailed examination of a specific day, simply hover your cursor over a square to reveal the number of incidents from that particular date. If you click on a square, all the past incidents from that day will be displayed in the Past Incidents list below. To gain further context, you can easily access these incidents by clicking on their linked titles.</mark></td></tr></tbody></table>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Additional Responders

Add more responders to ongoing incidents to receive additional assistance

With Additional Responders, you can add extra help beyond the original responders of the incident. So you easily add and notify users/squads as extra hands on deck and help with a coordinated response. Plus, users can now view who's involved in each incident, apart from the owners of the incident.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> This feature is available as part of the Product Trial,[ Premium, and Enterprise Plan.](https://www.squadcast.com/pricing)
{% endhint %}

### Add Additional Responders to an Incident

You can request individual users/squads as responders, with a limit of 100 unique users/squads **per addition**. And these requested users/squads receive a notification via email and push.

To add responders to an incident,

1. Navigate to the **Incidents Details** page of the specific incident -> Click on the **Add Responders** button.
2. Search and select from multiple users/squads in the list. You can choose up to 100 entities to bulk add in one operation.
3. Once selected, click **Confirm**.

You have now added more assistance to the incident, and these people will be notified of the same.

<div><figure><img src="/files/40aJyUXOAxxj07ktKP5J" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="/files/9XcEEwYpwFcgskrXGIXH" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="/files/K5HMfbJVqTmmevXmiyBv" alt="" width="563"><figcaption></figcaption></figure></div>

### Remove Additional Responders

To remove Additional Responders from an incident,

1. Navigate to the **Incidents Details** page of the specific incident -> In the Responders section, you'll see a **remove responder icon** next to each Additional Responder when you hover over it.
2. Click on the remove icon, then confirm the deletion.

<div><figure><img src="/files/9od61dihthmnd5JnOHFT" alt="" width="563"><figcaption></figcaption></figure> <figure><img src="/files/WAtoD7w8EfetNhuf8tBL" alt="" width="563"><figcaption></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> Please note that removal can only be done individually and is not available as a bulk action.
{% endhint %}

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark> If a user is removed from the team or downgraded to a stakeholder role, they will be removed from the responder list.
{% endhint %}

### Resend Notification

If users/squads miss responding to an incident, you can resend notifications (push and email) by using the "Resend Notification" button located next to each Additional Responder when hovering over it.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: You can view further details in the notification logs of the incident.
{% endhint %}


# Incident Summaries

Catch up with ongoing incidents by viewing AI generated summaries

Are you looking at an incident midway and wondering what has happened so far? You can view AI generated summaries for incidents during any point of the incident lifecycle and quickly catch up with the timeline and progress that has been made, team members involved in triaging, resolution steps determined, meeting links to join war room discussions, and much more.

This feature is currently a beta offering. Feel free to share your feedback with us and we will be happy to engage and discuss the same. You can also optionally either upvote or downvote on the summaries generated for incidents and let us know via the prompt shown as to why you did not like the summary generated, in case of a downvote.

{% hint style="info" %}
**Note**

Feature will be available for accounts in the[ Enterprise plan](https://www.squadcast.com/pricing)
{% endhint %}

## Generating Incident Summaries

* Navigate to the details page of the incident you are interested in

<figure><img src="/files/nSLId6l6ZRlwxDo2VpET" alt=""><figcaption></figcaption></figure>

* Select **Generate Summary**

<figure><img src="/files/aPDPyT6S5QV02ek633zZ" alt=""><figcaption></figcaption></figure>

* View the generated summary for the incident and optionally provide feedback

<figure><img src="/files/wk3VTdOxMmGL4cpmsKkP" alt=""><figcaption></figcaption></figure>

## Understanding Incident Summaries

Each generated summary for an incident will have the following structure:

1. **Timestamp** of the time when the summary was generated
2. **Status** of the incident - Triggered, Acknowledged or Resolved
3. **Impacted Service(s)** - List of the impacted Service and it’s affected dependent Services
4. **Incident Owner** - We assign the impacted Service owner as the owner of the incident by default
5. **Participants** - List of responders for the incident
6. **Timeline** - AI summarised life cycle progress and updates of the incident so far
7. **Resolution** - AI summarised resolution reason and next steps determined (available only for incidents in the Resolved state)
8. Ability to provide **feedback** for the generated summary

{% hint style="info" %}
You can simply click the copy icon to copy the incident summary in Markdown and use the same anywhere required.
{% endhint %}

<figure><img src="/files/qaXEp7YmYwaDVx0yGUYG" alt=""><figcaption></figcaption></figure>

## Other Information

1. Incident summary can be generated for incidents in Triggered, Acknowledged and Resolved states
2. To keep information up to date with the progress of an incident, every time you want to view the summary for an incident, you can simply generate it using the steps above
3. Both user types - Users and Stakeholders can generate and view incident summaries given they are already added to the relevant Teams

\
\&#xNAN;*Have any questions?*[ *Ask the community*](https://community.squadcast.com/view/home)*.*


# Incident Suggestions

### Suggested Runbooks <a href="#incident-tasks" id="incident-tasks"></a>

You can request runbook suggestions based on similar past incidents. We score runbooks based on their similarity to the current incident and how recent they are, then suggest the most relevant ones for attachment.

{% hint style="info" %}
Note:

Runbook suggestions are available on the Enterprise plan.
{% endhint %}

To get a runbook suggestion:

1. Head over to the Runbooks tab in the Incident page and click on Add Runbook

<figure><img src="/files/y7NzRtUDycT1BCIIrc4l" alt=""><figcaption></figcaption></figure>

2. Click on Suggest Runbook

<figure><img src="/files/dyBJbGskxFkJnj948AgU" alt=""><figcaption></figcaption></figure>

3. You'll get a list of upto 3 suggested runbooks. You can expand each suggestion to view more details
   1. If no relevant runbooks are found, no suggestions will be made.

<figure><img src="/files/TIaH6BzficcHvSWKU7Ck" alt=""><figcaption></figcaption></figure>

3. Choose the runbook(s) you want to attach and click on Attach. The runbook(s) will be attached to the incident

### Suggested Responders

Suggested responders are highlighted and shown at the top of the responders list based on their relevance to the incident. This helps users quickly find the most suitable responders to involve.

<figure><img src="/files/SYPpj4cJpHs8nZ6nyN49" alt=""><figcaption></figcaption></figure>


# Runbooks

Create, attach, reference and mark progress for incident resolution using Runbooks

{% embed url="<https://www.youtube.com/watch?feature=youtu.be&v=b0SA-6Cl530>" %}

### Understanding Runbooks <a href="#understanding-runbooks" id="understanding-runbooks"></a>

A Runbook is a compilation of routine procedures and operations that are documented for reference while working on a critical incident. Sometimes, it can also be referred to as a Playbook.

Typically, organizations store their incident checklists in various places such as Google Docs, Notion, Confluence etc., and sometimes even stored in a physical notebook. Valuable time is lost in searching for these different checklists and following up on the list items while working on critical incidents.

In order to avoid delays, scrambling between multiple tools and tabs to find the right checklist, Squadcast brings to you Runbooks. This feature will help you access the relevant Runbook, associate it with incidents and assign tasks to relevant users.

Simple Runbooks are a checklist of tasks that need to be performed manually for an incident. These could either be procedures that need to be performed during the occurrence of a Sev1 incident, or technical/functional instructions to debug and fix a certain issue, along with the code that needs to be manually executed.

One can easily create Runbooks and use it as a reference once it is attached to an incident. Additionally, one can mark the progress against each step in the Runbook.

{% hint style="info" %}
**Note:**

Simple Runbooks will be available for accounts in the [<mark style="color:blue;">Premium and Enterprise plans</mark>](https://squadcast.com/pricing).
{% endhint %}

### Creating Runbooks <a href="#creating-runbooks" id="creating-runbooks"></a>

#### RBAC Prerequisites <a href="#rbac-prerequisites" id="rbac-prerequisites"></a>

Runbooks are a Team-level entity and in order to create a Runbook, the user role should have the following Team-level Role permissions:

* <mark style="color:red;">`create`</mark> permission to create Runbooks
* <mark style="color:red;">`read`</mark> permission for viewing Runbooks
* <mark style="color:red;">`update`</mark> permission for editing Runbooks
* <mark style="color:red;">`delete`</mark> permission for deleting Runbooks

![Permissions for Runbooks](/files/eOw8RDCxGLVSvrCVUtMT)

**(1)** To create a Runbook, the user needs to click on the **Runbook** menu on the left navigation bar and click on the **Create Runbook** button

<figure><img src="/files/HojLGQp8BPEJqMoFFFFl" alt="Squadcast dashboard - Create Runbook"><figcaption></figcaption></figure>

**(2)** In the **Create Runbook** page:

* Enter a **Name** for the Runbook.
* Start adding steps for the Runbook by clicking on the **+ Add Step** button.

You can add as many steps as you like. Every step supports <mark style="color:red;">`Markdown`</mark>, hence you can use Markdown formatting features like Code Blocks, Bold, Italic, Ordered & Unordered List, Images & Links. You can manually upload images and attachments as well.

<figure><img src="/files/ZpUWb66ZuNsllyVJKa5I" alt="Create Runbook in steps"><figcaption></figcaption></figure>

Although you can add all the series of actions within a single step, we recommend you add each action as a separate step. It would be helpful to mark the progress of each step by checking it done.

<figure><img src="/files/lVuLIDNNM8HCgz4lsbvW" alt="Add steps in the Rubooks"><figcaption></figcaption></figure>

You can switch between the <mark style="color:red;">`Edit`</mark> mode & <mark style="color:red;">`View`</mark> mode (Preview) by using the Visual/Markdown option. You can also drag & drop each step to rearrange their order.

After adding all the details, click on the **Save** button and the Runbook is created.

<figure><img src="/files/XoAwrKEDcu5YytxPc3Zl" alt="Save created Runbook"><figcaption></figcaption></figure>

Once created, you can view, edit or delete an existing Runbook.

{% hint style="info" %}
**Note:**

The Runbooks created here to act as a template and any update to the Runbook will only get applied to subsequent incidents and not to any previously attached incidents.
{% endhint %}

### Attaching Runbooks to Incidents <a href="#attaching-runbooks-to-incidents" id="attaching-runbooks-to-incidents"></a>

**(1)** Open an incident and click on the **Runbooks & Tasks** tab and then click on the **Attach Runbook** option

<figure><img src="/files/gs84U5HP8X0Sm3vTkthl" alt="Attaching Runbooks to Incidents"><figcaption></figcaption></figure>

**(2)** Select the Runbook(s) that you want to be attached to the incident and click on the final **Attach Runbooks** button

<figure><img src="/files/yqUGzJuheVKlJf8Mowsj" alt="Select attached Runbook"><figcaption></figcaption></figure>

You have the option to attach more than one Runbook to an incident.

![Attach more than one Runbook to an Incident](/files/5KrOzexC0fauEoYkPUuc)

**(3)** The Runbook will be attached and listed. One can then follow the Runbook and perform the steps. They can also mark the completion of each step by checking the checkbox for each step

<figure><img src="/files/JxVGbydQiAIXE8sBq7vZ" alt="Mark completion of steps in a Runbook"><figcaption></figcaption></figure>

{% hint style="info" %}
**Note:**

Every action on a Runbook, such as adding a Runbook, or completing a step - of it gets recorded in the Incident Timeline automatically.
{% endhint %}

### Incident Tasks <a href="#incident-tasks" id="incident-tasks"></a>

Tasks are instructions or to-dos for other team members or even follow-up tasks for an incident. The ability to have tasks associated with an incident comes in handy for critical incidents where most often than not, there would be a list of tasks that need to be completed even post-incident closure, to ensure final fixes are in place.

### Creating Tasks <a href="#creating-tasks" id="creating-tasks"></a>

**(1)** To create a task, click on the **Add Task** option under the **Runbooks & Tasks** tab

<figure><img src="/files/DerwTP2i8Dh47BTMyKk0" alt="Create Tasks"><figcaption></figcaption></figure>

**(2)** Here, enter the details of the task. You can use <mark style="color:red;">`Markdown`</mark> formatting for it. Then, click on the final **Add Task** button to generate your task list

<figure><img src="/files/vaIZk5nG9EpqQE4RTme2" alt="Add Tasks - supports markdown"><figcaption></figcaption></figure>

**(3)** Similar to Runbook actions, the completion of the task can also be marked using the checkbox

<figure><img src="/files/NNwHhjzZogk5xyaa7J6U" alt="Mark completion of Tasks"><figcaption></figcaption></figure>

For any queries on Runbooks and Tasks, reach out to our Support Team and they will be happy to assist you.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Postmortem Templates

Postmortem Templates for the Postmortems that you conduct for incidents

{% embed url="<https://www.youtube.com/watch?v=Y-vY2iCoyTU>" %}

### Postmortem Templates <a href="#postmortem-templates" id="postmortem-templates"></a>

Each Organization has a few predefined **Postmortem Templates** available from **Squadcast** by default. You can choose to create new templates or modify the existing ones, based on how you do postmortems within your Organization.

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* Only the **Account Owner** or **Users** with the **Manage Postmortem Templates** permission will have the access to modify Postmortem Templates and/or create new Postmortem Templates for the Organization

<figure><img src="/files/CECqxMLOsXmo1cfkxdKr" alt="Permissions to Manage Postmortem Templates"><figcaption></figcaption></figure>

### Managing Postmortem Templates <a href="#managing-postmortem-templates" id="managing-postmortem-templates"></a>

1\. Click on **Settings** in the primary navigation and then select **Postmortem** from the secondary navigation

<figure><img src="/files/sP1Eh1seszIAWu6DKsl5" alt="Manage Postmortem Templates"><figcaption></figcaption></figure>

Here you’ll find the list of pre-defined templates.

You can either make use of the existing templates or add new templates for the rest of your Organization to use.

![Adding new Postmortem Template](/files/s7q5RQ9BZadfnesMdXYx)

2\. There is a set of <mark style="color:red;">`incident variables`</mark>, which can be used while creating **Postmortem Templates**. These <mark style="color:red;">`incident variables`</mark> will dynamically get populated with the incident’s data for which the Postmortem is being created. You can see all the available <mark style="color:red;">`incident variables`</mark> on the right half while creating templates. The variables need to be specified using [<mark style="color:blue;">MustacheJS syntax</mark>](https://github.com/janl/mustache.js/)

Refer to any of the pre-defined templates for the templating syntax.

![pre-defined postmortem templates](/files/Gy40Sokz2MsmQOlTb5d3)

3\. A template can be marked **Default**. While filling a Postmortem report for an incident, the default template would pop up automatically when a user starts a Postmortem for it

![Select postmortem as default](/files/bvzgH5Rrc0Vj1JU11T06)

Click on **Add** to save the new template or **Update** to save the changes in an existing template

### Adding Attachments <a href="#adding-attachments" id="adding-attachments"></a>

You can add a variety of file types as an attachment in the Postmortem Template.

To attach a file, drag and drop the file to the markdown editor. You can also copy-paste the file directly into the markdown editor.

The maximum size for a single file is 10 MB (for upload). You can upload a maximum of 5 files at a time.

{% hint style="info" %}
The storage limit for an organization depends on the plan:\
\
**Free Plan** - 50 MB\
**Pro, Premium, and Enterprise** - Unlimited
{% endhint %}

File uploads won’t work if the plan limit has been reached. The file once uploaded cannot be deleted.

The supported file types are:

* Images (.png, .jpg, .jpeg)
* Word Processors (.doc, .docx, .odt, pages)
* Spreadsheets (.xls, .xlsx, numbers)
* PDFs (.pdf)
* Presentations (.ppt, .pptx. .odp)
* Miscellaneous (.log, .txt, .eml, .msg, .csv, .key, .json)

### FAQs <a href="#faqs" id="faqs"></a>

1\. Can Stakeholders create Postmortem Templates?

No, **Stakeholders** cannot create Postmortem Templates.

2\. Are Postmortem Templates limited to a particular Team?

No, Postmortem Templates are an Organization-wide entity. Any Team in the Organization can make use of the Postmortem Templates added.

3\. I am in a Team and the Team has all the necessary Roles (Create, Read, Update, Delete) for Postmortems, yet I am unable to add a Postmortem Template that my Team could use. What am I missing?

The Roles associated with a Team for Postmortems are different from the Permission required to create a Postmortem Template. The Permission required to create/modify a Postmortem Template is an Organization-level Permission. Head over to Settings -> Postmortem -> and ensure that you have been given the same (the checkbox must be enabled for **Manage Postmortem Templates** Permission).

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Create Postmortems

Postmortems are a way to summarize the resolution for an incident once it is resolved

{% embed url="<https://www.youtube.com/watch?v=Y-vY2iCoyTU>" %}

Postmortems are a way to summarize the resolution for an incident once it is resolved. It is also a way for you to create a knowledge-base of failures and fixes that can be shared across your team to help build a culture of shared learning and learning from failures.

In this documentation, we’ll be going through how to create Postmortems.

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* Ensure that the users of the Team have the right Roles (with the right permissions associated with the Postmortem entity) to be able to create and manage Postmortems
* The Postmortem feature is enabled for an incident only after it has been **resolved**. Hence, an incident first needs to be **resolved.**

![right permissions to manage postmortem](/files/KW1El20r2iYzIDYsYjoa)

### Creating a Postmortem <a href="#creating-a-postmortem" id="creating-a-postmortem"></a>

To create a Postmortem for a resolved incident:

1. Navigate to the **Incident Details** page for the incident and click on **Start Postmortem.**
2. You can select one of the **Postmortem Templates** from the drop-down.
3. The **Postmortem Title** is auto-populated with your Incident Name as default. You can edit it, and start documenting the Postmortem.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> The <mark style="color:red;">`incident variables`</mark> will auto-populate as per the data available for that particular incident. The remaining details need to be manually filled in by the user by editing the Postmortem.
{% endhint %}

4. You can select the **Postmortem Status** from the drop-down. The status indicates where in our process the postmortem currently is. The available statuses include:
   1. **In Progress** - Indicates that the postmortem is currently a work in progress.
   2. **Under Review** - Indicates that the postmortem is currently under review.
   3. **Published** - Indicates that the postmortem has been reviewed and is published. This is the final stage.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> You can export postmortem reports at any stage, and this status field will not be reflected in the exported file.
{% endhint %}

5. Apart from the Markdown body in a Postmortem, you can also create a **checklist of follow-ups** that can be used to keep track of further actions that need to be done for that incident.
6. Click on **Create** to save the Postmortem

Once a Postmortem is created, any member of the Team with the right permissions can view and manage the Postmortem

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> Once the Postmortem is created (and updated), it can be downloaded offline in either <mark style="color:red;">`Markdown (MD)`</mark> or <mark style="color:red;">`PDF`</mark> format.
{% endhint %}

### Adding Attachments <a href="#adding-attachments" id="adding-attachments"></a>

You can add a variety of file types as an attachment in the Postmortem of an incident.

To attach a file, drag and drop the file to the markdown editor. You can also copy-paste the file directly into the markdown editor.

The maximum size for a single file is 10 MB (for upload). You can upload a maximum of 5 files at a time.

{% hint style="info" %}
The storage limit for an organization depends on the plan:\
\
**Free Plan** - 50 MB\
**Pro, Premium, and Enterprise** - Unlimited
{% endhint %}

File uploads won’t work if the plan limit has been reached. File once uploaded cannot be deleted.

The supported file types are:

* Images (.png, .jpg, .jpeg)
* Word Processors (.doc, .docx, .odt, pages)
* Spreadsheets (.xls, .xlsx, numbers)
* PDFs (.pdf)
* Presentations (.ppt, .pptx. .odp)
* Miscellaneous (.log, .txt, .eml, .msg, .csv, .key, .json)

### Updating a Postmortem <a href="#updating-a-postmortem" id="updating-a-postmortem"></a>

We understand that conducting Postmortems and documenting them is an iterative process in some cases. In Squadcast, once a Postmortem is created, users with the right permissions can update the Postmortems as well.

There are 2 ways to do this:

1. For an incident, head over to its **Incident Details** page and click on **Update Postmortem**. Switch to the **Edit** mode. Then, make the necessary modifications and click on **Update**

<figure><img src="/files/b5UzGP0mVbHK3nCrfmP9" alt="Update Postmortem"><figcaption></figcaption></figure>

2. Head over to **Postmortems** from the navigation on the left, and scroll to the applicable Postmortem in the list. Click on the **Edit** icon, make the necessary changes and click on **Update.**

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Accessing Postmortem

Discover Postmortems that exist for incidents in your Team

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* Ensure that the users of the Team have the right Roles (with the right permissions associated with the Postmortem entity) to be able to create and manage Postmortems
* Be sure to choose the Team from the team picker on the top to view/manage Postmortems created within that particular Team

### Accessing Postmortems <a href="#accessing-postmortems" id="accessing-postmortems"></a>

We understand that the cycle of conducting Postmortems does not stop at just that. Once Postmortems are created and are being maintained for multiple incidents in your Team, having the ability to discover and access them easily would be equally important.

You can follow the steps below to access Postmortems:

1\. Click on **Postmortems** in the primary navigation

2\. Here, you will be able to see the list of all Postmortems that exist for the Team chosen

* You can use the **+Add Filter** tab to add filters based on **Alert Sources, Services, and Status**. It will filter the Postmortem list according to the chosen Alert Source, Service, or Postmortem Status.

<figure><img src="/files/xPtaofmJAmYXw4gOOh9O" alt=""><figcaption></figcaption></figure>

* You can choose the time filter to view all Postmortems in the selected time period. By default, all the Postmortems within the **last 3 months** are displayed.

<figure><img src="/files/A2Phoi8KTammB0k7NdUi" alt="Postmortem in selected time period"><figcaption></figcaption></figure>

* As we know, each of the listed Postmortem is associated with an incident. The <mark style="color:red;">`Incident ID`</mark> of the associated incident is listed above the Postmortem. Clicking on the <mark style="color:red;">`Incident ID`</mark> will navigate you to the **Incident Details** page of that incident.
* The **date of creation** of the Postmortem is mentioned alongside the <mark style="color:red;">`Incident ID`</mark>.

![Incident associated with the Postmortem](/files/cHNzwdNZlH4nltFfPYRT)

* The search bar on the top right can be used to search for particular Postmortems. You can search by any word that is contained within the Postmortem

![Search for particular Postmortem](/files/Nyc595jrdCpxDK9rkMnr)

3\. To update/edit a Postmortem, click on the **Edit** icon, make the necessary changes and click on **Update.**

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Status Page

Enhance customer communication and visibility with Status Pages - your go-to platform for sharing crucial outage and maintenance updates.

A Status Page provides visibility into the current health of your system. It’s a single page where anyone can view the latest status messages for ongoing or past incidents.

Incidents happen. What matters the most is how you handle them. Status pages help you turn every outage into an opportunity to build trust in your service.

Your users can subscribe to status page updates via email or webhooks when you have an incident, and you can customize your URLs to embed your system status directly into other interfaces. Hence, ensuring your customers are consistently in the know.

<figure><img src="/files/MfhfDjvJp5vriwiUYSte" alt="Status Page created in Squadcast"><figcaption><p>Image. Status Page</p></figcaption></figure>

## Benefits of having a status page

A status page is of great help before and during downtime. Being transparent about how your team has handled incidents in the past is a great way to build trust.

When your service is up, they help you showcase historical reliability. During downtime, they help your team communicate status updates with all stakeholders.

Status pages enable your team to

<details>

<summary><mark style="color:blue;"><strong>Showcase your reliability</strong></mark></summary>

Help your users see how reliable and performant your services are. This builds trust and sets the right expectations on what your SLAs are.

</details>

<details>

<summary><mark style="color:blue;"><strong>Reduce support tickets</strong></mark></summary>

Be transparent about past and ongoing outages. Your customers can answer their questions without going through support first.

</details>

<details>

<summary><mark style="color:blue;"><strong>Build and scale your incident communication process</strong></mark></summary>

Your team doesn’t have to use different platforms to communicate incidents.

</details>

## Prerequisites

* To effectively create and manage Status Pages, the user assigned to the Team must possess the appropriate permissions corresponding to their User Role.

## Helpful Terms

1. <mark style="color:blue;">**Public page**</mark>. This page is accessible to anyone who has the URL. It can be viewed by anyone, and individuals have the option to subscribe to receive updates from this page.
2. <mark style="color:blue;">**Private page**</mark>. This page is restricted to authenticated users of Squadcast. Only users who have been added to Squadcast with the necessary permissions can view and subscribe to this page.

## Create a Status Page

To create a Status Page,

Navigate to **Status Page** -> **Add Status Page**. On the next screen, you will be guided through four creation steps. Navigate between these steps by clicking on any of the steps on the top bar.

### 1. Add Status Page Details

1. Enter the **Name**, **Timezone**, **Owner**, and an *optional* **Description** for the Status Page.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: The status page and messages will be displayed at this timezone.
{% endhint %}

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 For optimal consistency, we recommend selecting UTC as the standard practice or choosing a timezone that aligns with the majority of your users.

🔹 **Best Practice Tip** 🔹 We recommend utilizing the description field to inform your users about the best way to reach out to you in case of any issues. You can include links to your support email, website, or provide a brief guide on the preferred method of communication.
{% endhint %}

<figure><img src="/files/FiLMSR3yNFoolNR5da92" alt="Add Status Page Details" width="563"><figcaption><p>Image. Add Status Page Details</p></figcaption></figure>

2. **Send Only Email**. This is the email address from which notification emails will be sent to subscribers of the status page.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: Email notifications for Status Page updates will be sent exclusively from <updates@status.squadcast.com>.\
\
Kindly note that the Send Only Email is non-editable.
{% endhint %}

3. **Fallback Support Email**. This email will appear in the notification updates, enabling end users to easily reach out to you for assistance whenever needed.
4. **Domain Settings**. Please enter a domain name to utilize Squadcast's public URL feature. The public URL will be hosted by Squadcast under the specified domain.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: After creating a page, you have the option to configure a custom domain within the **Page Configuration** settings. This allows you to map your own domain to the page you have created.

For detailed instructions on how to accomplish this, please refer to the following steps given [<mark style="color:blue;">here</mark>](#edit-page-configuration-or-configure-custom-domain).
{% endhint %}

5. **Choose the visibility of your status page**. You have the option to leave it unchecked, which would keep it publicly accessible. Alternatively, you can check the box to make it private, restricting access to only Squadcast users on the platform.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: Kindly note that once this setting is configured, it cannot be changed in the future. It's important to keep in mind that ***only Squadcast authenticated*** users have access to view private pages.
{% endhint %}

<figure><img src="/files/FDuduyhqS24YzNAVLgux" alt="Configure Status Page" width="563"><figcaption><p>Image. Configure Status Page</p></figcaption></figure>

6. Click **Next: Add Component**, and navigate to the next step.

### 2. Add Component

Components serve as fundamental elements that represent specific functional parts of your service. They are essentially the building blocks that make up your overall service structure. These can include your website, mobile app, API, and other vital elements of your service.

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 It is recommended to create a separate component for each functional or architectural division within your infrastructure. Components are typically used to represent resources or services that are utilized by your customers.
{% endhint %}

Create and group various aspects of your systems into components.

To create a component,

1. Enter the **Component Name** and *an optional* **Descriptio**n. You can choose to add a Component to a Group as well.

<figure><img src="/files/v2vMHwChNu3NKp8bIGd6" alt="Add Components to Status Page" width="563"><figcaption><p>Image. Add Components</p></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**What is a Group?**</mark>

Grouping similar functional services or resources can form a component group. Creating a component group can help declutter the status page to give it a more organized and comprehensible look.

Component status is organized based on severity, following this hierarchy:

* <mark style="color:green;">**Operational**</mark>. This status indicates that the component is functioning as expected and in a timely manner. It is the default state.
* <mark style="color:red;">**Degraded**</mark>. When a component's performance is impacted in a minor way, such as being slower than usual due to high traffic, it is considered as degraded. In this case, all or most components may be affected, leading to a severe impact on the overall experience.
* <mark style="color:orange;">**Major Outage**</mark>. A component is marked as a major outage when it becomes completely unavailable. If many components are down, it can significantly impact the overall experience.
* <mark style="color:yellow;">**Partial Outage**</mark>. If only some components are down, resulting in an impact on a subset of customers, it is considered a minor or partial outage. For example, if a specific data center is down and only affects a subset of customers, while the rest are unaffected, it would be categorized as a partial outage.
* <mark style="color:blue;">**Under Maintenance**</mark>. This status indicates that the component is currently undergoing maintenance or work.\
  \
  By using these statuses, the status page provides valuable information about the operational state of different components, helping users understand the overall health of the service.
  {% endhint %}

2. Click **Next: Customize your page**, and navigate to the next step.

### 3. Customize Your Page

Add your company logo and choose a color theme for your status page. You can customize your status pages to suit your convenience.

<div><figure><img src="/files/RbI4K9sSmOkkbeqefuFd" alt="Customize your Status Page Theme" width="563"><figcaption><p>Image. Customize Page Theme</p></figcaption></figure> <figure><img src="/files/QEMNidK2ILkWf1Wa5nFC" alt="Status Page Theme" width="563"><figcaption><p>Image. Status Page Theme</p></figcaption></figure></div>

This creates your Status Page! Now, if you want, you can add your first Issue here.\
\
To do that, click **Next: Add Your First Issue** and navigate to the next step.

### 4. Add Your First Issue

{% hint style="info" %} <mark style="color:blue;">**What is an Issue?**</mark>

An Issue is created to communicate a change in functionality or availability of your services. An Issue has the following fields: \\

1. Affected Component
2. Affected Component Impact
3. Status Message
4. Issue Message(s)
   {% endhint %}

Enter the **Issue Title** and select the **Component** that this issue is impacting along with the **status of that component**.

However, it is also possible to skip this step for now and create it at a later time if needed. The choice is yours.

<div><figure><img src="/files/grc4MSKgjZVYkuhS60am" alt="Add Issue in Status Page"><figcaption><p>Image. Add First Issue</p></figcaption></figure> <figure><img src="/files/fjh2CYNt22HqPYvPKFyy" alt="Add Status Message"><figcaption><p>Image. Add Status Update</p></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**What is an Issue Status?**</mark>

Issue Status refers to the current stage of resolution for an issue. It is accompanied by an Update, which provides a concise description of the issue, including the cause and, if known, the planned resolution.

Each Update is associated with one of the following four Issue States:

1. **Investigating.** This status is assigned when efforts are underway to determine the root cause of the incident. It signifies active investigation to identify the reasons behind the issue.
2. **Identified.** The cause of the issue has been successfully determined and recognized. This status indicates that the underlying reason behind the problem has been identified.
3. **Monitoring.** After identifying the cause and implementing a resolution, the issue is in the monitoring phase. During this stage, the service is being observed to ensure it returns to its normal functioning and operates smoothly.
4. **Resolved.** This status is assigned when the incident has been fully resolved, and the service is once again available for use.\
   \
   By tracking the Issue Status and corresponding Updates, you can effectively monitor and communicate the progress of issue resolution.
   {% endhint %}

{% hint style="info" %} <mark style="color:blue;">**What is a Status Update?**</mark>\
\
A Status Update allows you to provide additional information regarding the current status of an incident. This field enables you to communicate specific details about the stage of your investigation or outline your planned actions when the incident status is set as "Acknowledged." It serves as a means to share relevant updates and progress related to the incident.
{% endhint %}

Click **Save** to complete creating the Status Page.

That completes it! You have finally created your Status Page.

## Edit Page Configuration or Configure Custom Domain

Now that you have created a status page, you can map a custom domain in the page configuration settings.

To edit page configurations,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. Click on the status page to navigate to the **Status Page Details page**.
3. In the top right, click **More** -> **Page Configuration**.
4. You can modify the **Name**, **Timezone**, **Owner**, **Description**, **Domain,** and **Search Engine Settings**.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> Please note that the created status page is set to be accessible to search engines for crawling and indexing by default. However, you have the option to conceal the status page from search engines by selecting the provided checkmark.
{% endhint %}

{% hint style="warning" %} <mark style="color:orange;">**How to map your custom domain?**</mark>\\

1. Navigate to **Domain Settings** -> check **Map a custom domain name**.
2. Enter the **Hostname**. To verify ownership of the domain, complete the DNS settings on your service provider's end using the provided information.
3. Create a new **A record** and **TXT Record** in your DNS, as instructed, to activate the custom URL and verify ownership of the domain.\\

By following these steps, you will be able to successfully map your custom domain in Squadcast.
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>:\
If you have already verified your CNAME mapping, your status page will continue to function normally without any changes. Your existing CNAME setup will remain intact and won't require any modifications.

However, we strongly encourage you to complete the verification process by adding and verifying the A and TXT Records to ensure a comprehensive verification.
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Why did we add an A and TXT Record verification layer?**</mark>

* We have implemented this additional level to enhance the security of your Status.
* By utilizing A and TXT records, we can validate the ownership of the domain. If your domain is a subdomain, the record can be placed either on the subdomain itself or the apex domain. Both will undergo verification to confirm domain ownership.
* This addition was crucial to prevent the inappropriate use or abuse of valid domains, as we have a system in place to ensure uniqueness of the status page URLs.
* We kindly request your cooperation in completing the status page verification process.

\ <mark style="color:blue;">**Note**</mark>: Please complete this step for all the Status Page(s) in your account within 30 days of receiving this email.

Rest assured, your subscribers will continue receiving notifications without any interruptions for these 30 days.
{% endhint %}

{% hint style="warning" %} <mark style="color:orange;">**What happens if I don't complete the verification within the 30-day timeframe?**</mark>

Please note that if you fail to complete the two-step verification within the 30-day period, your Status Page(s) will become inactive and inaccessible to your customers. However, your data will remain secure and unaffected. Once the verification process is completed, all services will return to normal.
{% endhint %}

5. Click **Save.**

## Edit Page Theme

You can modify the logo and the color theme of the status page post-creation of your status page.

To edit the page theme,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. Click on the status page to navigate to the **Status Page Details** **page**.
3. In the top right, click **More** -> **Edit Page Theme**.
4. Once you have edited your preferred page themes, click **Save**.

## Create Default Message Update Templates

You can modify the issue states along with the message templates used for them.

To edit message templates,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. Click on the status page to navigate to the **Status Page Details page**.
3. In the top right, click **More** -> **Message Template**.
4. Once you have edited your preferred templates, click **Save**.

<div><figure><img src="/files/VkOkU5SgM7AWjcQQVp5r" alt="Edit Status Message Template" width="563"><figcaption><p>Image. Edit Message Template</p></figcaption></figure> <figure><img src="/files/MfhfDjvJp5vriwiUYSte" alt="Status Message as shown in Status Page" width="563"><figcaption><p>Image. Status Message as shown in Status Page</p></figcaption></figure></div>

## Edit Status Messages

You can modify the status messages.

To edit status messages,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. Click on the status page to navigate to the **Status Page Details page**.
3. In the top right, click **More** -> **Status Message**.
4. Once you have edited your preferred messages, click **Save**.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: Kindly note that the following messages will appear in both the status page header and the components section.
{% endhint %}

## Guide to setup DMARC for status pages

Customers can set the following <mark style="color:orange;">`spf`</mark> records on their status page subdomain so that we can send the emails from your domain without any issues:

\# for EU customers

<mark style="color:orange;">`v=spf1 include:incidents.eu.squadcast.com ~all`</mark>

\# for US customers

<mark style="color:orange;">`v=spf1 include:incidents.squadcast.com ~all`</mark>

For example:

If you are a customer who signed up in our US Data center with a Statuspage subdomain, let's say <mark style="color:orange;">`status.example.com`</mark>, you should set up a <mark style="color:orange;">`TXT`</mark> record in your DNS provider for the <mark style="color:orange;">`status.example.com`</mark> subdomain with value <mark style="color:orange;">`v=spf1 include:incidents.squadcast.com ~all`</mark> as shown below.

<figure><img src="https://lh4.googleusercontent.com/nquoRkmAkKZj2JB7hO_TSC_1xjWwMpGJXqmRm-vh4JVA1WtNdvGzLpvLSkWwl6wqf1NUd97zfmZzVlFaYpoCr-CR3bfKPyIHpbreHdFHdoIlAE3TY1IMkY-KXOFMTXQ5sHC5iMdAcUnT1wwnEnCx6UQ" alt="Setting up a TXT record in your DNS provider" width="563"><figcaption><p>Image. Setting up a TXT record in your DNS provider</p></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Status Page Overview

Enhance your status page experience with our comprehensive Status Page Overview. Gain valuable insights, take necessary actions, and access relevant information seamlessly.

Status Page Overview provides a high-level aggregate view of all status pages set up by your team. Users can filter all status pages by their status and types (public or private), dive into each individual status page to learn more about it, make changes to the settings, and take further action.

## Search

To search for a specific status page, enter its **name** or any other *related keywords* in the Search field and hit enter.

## Filters

### Status

To filter by status, click on the **Filter icon** in the Status Page’s Listings page -> **Status Page Status** -> choose the status you want to use to filter from the dropdown list -> click **Apply**, and you’re done.

You can choose from the following statuses of a Status Page:

1. [<mark style="color:blue;">**Operational**</mark>](https://support.incidents.cloud.solarwinds.com/status-page/pages/nxvHY77dRUmjsjsRX5m9#2.-add-component)
2. [<mark style="color:blue;">**Degraded**</mark>](https://support.incidents.cloud.solarwinds.com/status-page/pages/nxvHY77dRUmjsjsRX5m9#2.-add-component)
3. [<mark style="color:blue;">**Major Outage**</mark>](https://support.incidents.cloud.solarwinds.com/status-page/pages/nxvHY77dRUmjsjsRX5m9#2.-add-component)
4. [<mark style="color:blue;">**Partial Outage**</mark>](https://support.incidents.cloud.solarwinds.com/status-page/pages/nxvHY77dRUmjsjsRX5m9#2.-add-component)
5. [<mark style="color:blue;">**Under Maintenance**</mark>](https://support.incidents.cloud.solarwinds.com/status-page/pages/nxvHY77dRUmjsjsRX5m9#2.-add-component)

### Type

To filter by type, click on the **Filter icon** in the Status Page’s Listings page -> Show -> checkmark either of the types (public or private) -> click **Apply**, and you’re done.

## Update Status Manually

To update the Status of the page manually,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. On hovering over the status page, click **Update Status Manually.**
3. A side panel opens up, you can update the Status of the page.
4. Click **Update** to save.

## View Maintenance

To view maintenance from the overview page,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. On hovering over the status page, click **View Maintenance.**
3. You are navigated to the **Maintenance section** in the **Status Page Details page**.
4. You can view, add and perform actions on any scheduled maintenance from here.

## View Issue

To view issues from the overview page,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. On hovering over the status page, click **View Issue.**
3. You are navigated to the **Issues section** in the **Status Page Details page**.
4. You can view, add and perform actions on any of the issues from here.

## Delete Status Page

To delete a status page,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. Click on the more options against the status page you want to delete.
3. Click **Delete**, and a confirmation modal will appear.
4. Click **Delete** again to confirm.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Components and Groups

Understand Components and Groups, their distinctions, and leverage their capabilities. Discover actionable insights and take control with ease.

Components are the functional units of your service or IT infrastructure. For instance, your websites, API endpoints, databases, and mobile applications, are all components.

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 We recommend creating a component for every functional or architectural division of your infrastructure. Resources or services used by the end user can be helpful additions.
{% endhint %}

Some more examples of components include:

* Authentication and Authorization Services
* Messaging Services
* Payment Gateway
* Cloud Services
* Knowledge Base/ Support Portal
* External Dependencies/ Third-party Services

<figure><img src="/files/EV1nm2bpGsnfbrIxiwHu" alt=""><figcaption></figcaption></figure>

### What components should you add?

The answer is almost always, "It depends". However, a helpful guideline is to include a component for each significant functional or architectural division within your service.

### Status of a Component

To convey the current state of each component, they are assigned one of the five following statuses:

<table><thead><tr><th width="231">Status</th><th>Description</th></tr></thead><tbody><tr><td><mark style="color:green;"><strong>Operational</strong></mark></td><td>This status indicates that the component is functioning as expected and in a timely manner. It is also the default state.</td></tr><tr><td><mark style="color:blue;"><strong>Under Maintenance</strong></mark></td><td>This status indicates that the component is currently undergoing maintenance work.</td></tr><tr><td><mark style="color:red;"><strong>Degraded</strong></mark></td><td>When a component's performance is impacted in a minor way, such as being slower than usual due to high traffic, it is considered degraded.<br><br>In this case, all or most components may be affected, leading to a severe impact on the overall experience.</td></tr><tr><td><mark style="color:yellow;"><strong>Partial Outage</strong></mark></td><td>If only some components are down, resulting in an impact on a subset of customers, it is considered a minor or partial outage.<br><br>For example, if a specific data center is down and only affects a subset of customers, while the rest are unaffected, it would be categorized as a partial outage.</td></tr><tr><td><mark style="color:orange;"><strong>Major Outage</strong></mark></td><td>A component is marked as a major outage when it becomes completely unavailable.<br><br>If many components are down, it can significantly impact the overall experience.</td></tr></tbody></table>

### Components & Component Groups

If a Component is a single resource necessary to your operations, Component Groups are related resources grouped together to make it easy for visitors to inspect.

By grouping similar functional services or resources, you can establish a component group, which contributes to a more organized and comprehensible appearance of the status page.

### Edit Components and Component Groups

To edit components and groups,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. Click on the status page to navigate to the **Status Page Details page**.
3. In the top right, click **More** -> **Page Components**.
4. Click **Add Components**, to add individual components.
   1. Enter the **Component name**
   2. Check to **Allow users to subscribe to the component**
   3. Enter *an optional* **Description**
   4. You can add this component to a group by clicking **Add Component to a Group** -> select the component group.
5. Click **Add Component Group**, to add a component group.
   1. Enter the **Component Group name**
   2. Click Save
6. Once you have entered your preferred components and groups, click **Save**.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: Please note that you have the flexibility to reorder the list of Components and Component Groups by simply dragging and rearranging them.
{% endhint %}

### Delete Component and Component Group

To delete a component,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. Click on the status page to navigate to the **Status Page Details page**.
3. In the top right, click **More** -> **Page Components**.
4. On hovering over any component group, click **Delete Group**
5. A confirmation modal will open, click **Delete**
6. You have to reassign the components of this group before deleting the component group and selecting the component group to assign the components.
7. Click **Reassign and Delete**.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: Kindly note that it is advisable to reassign the components before deleting them.
{% endhint %}

### Edit Component Uptime

To make retroactive edits to a component's uptime graph,

1. Go to **Page Components.**

<figure><img src="/files/MNxFVugPMcmKC1RPTWDV" alt="" width="563"><figcaption></figcaption></figure>

2. Click on **Edit** for the component whose timeline you want to edit

<figure><img src="/files/uFAfPwLy1gRX3Nnavb6H" alt="" width="563"><figcaption></figcaption></figure>

3. **Hover** over the uptime graph and click on **Edit** for a specific date.

<figure><img src="/files/lcxx4W6WtMpIw9ubDpet" alt="" width="563"><figcaption></figcaption></figure>

4. Modify the hours and minutes of Degraded, Partial Outage, and Major Outage.
5. Click on **Save**. Your changes will be reflected immediately on your status page

<figure><img src="/files/k0kYGXbb6hk536VdO6JD" alt="" width="547"><figcaption></figcaption></figure>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Issues

Learn how effectively manage issues to communicate changes in functionality or service availability through your Status Page.

## What is an Issue?

An Issue is created to communicate a change in functionality or availability of your services. An Issue has the following fields:

1. Affected Component
2. Affected Component Impact
3. Status Message
4. Issue Message(s)

<figure><img src="/files/oPYJmq8Nnc0hfHUg5vpN" alt=""><figcaption></figcaption></figure>

### Add Issue

To add an issue,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. Click on the status page to navigate to the **Status Page Details page**.
3. In the Issue section, click **Add Issue**.
4. Enter the **Issue Title**, this would be the Status Message conveying the issue and impact.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: We only support editing the Issue Title for historical issues.
{% endhint %}

1. Select the overall **Page Status**.
2. Next, select the **Component Group** and the **Impact**.
3. Add the **Issue State** and its messaging.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: You can manually select the Date & Time of the Message Update.
{% endhint %}

1. Once you have added all your preferred settings, click **Save**.

<div><figure><img src="/files/4oCWA9IO9HvZZkaUSwYH" alt="Add an Issue in Status Page" width="563"><figcaption><p>Image. Add Issue</p></figcaption></figure> <figure><img src="/files/9vQ1LLkKAqV4ud0aBa5i" alt="Add an Issue State &#x26; Messaging in Status Page" width="563"><figcaption><p>Image. Add Issue State &#x26; Messaging</p></figcaption></figure></div>

### Update Issue States & Messages

Once your issue is created, you can add update the Issue States & Messages, to do so:

1. Hover over the Issue from the Issue List -> **Update State & Messages**
2. You can edit an existing message or add another update.
3. Moreover, you can change the State by clicking on them.

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>: Before you change the Issue State to Resolved, we recommend you change the Page and Component Status from non-operational.\
\
Resolving it would mean you are closing this issue and you will no longer be able to add new updates to this issue.
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: After the resolution of the issue, the only available option for the Page and Component Status is to set it as "Operational."
{% endhint %}

<div><figure><img src="/files/zJzcinXaAQ241mrAD5mD" alt=""><figcaption><p>Image. Update Issue States</p></figcaption></figure> <figure><img src="/files/dBYUwPkzHuQh1Fyjp7Mr" alt=""><figcaption><p>Image. Update Issue Message</p></figcaption></figure></div>

### Delete an Issue

To delete an Issue from the Status Page,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. Click on the status page to navigate to the **Status Page Details page**.
3. In the Issue section, against the Issue you wish to delete, click **More options**.
4. Click **Delete**, and a confirmation model will appear.
5. Click **Delete** again, to confirm.

{% hint style="warning" %}
**Important**: This action would remove the Issue from the recorded Issue History.
{% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Subscribers

Learn how to effectively manage subscribers of your Status Pages to ensure they receive timely updates.

Subscribed customers and stakeholders will receive notifications regarding issues and upcoming maintenance on this status page. These updates can be delivered through emails or webhooks, depending on their preferred method of receiving notifications.

Your users can choose to subscribe to the entire status page, specific components, or timely maintenance activities.

<figure><img src="/files/EjSUs89YDMlvvhF2gW61" alt="Subscribe to Status Page for timely updates" width="563"><figcaption><p>Image. Subscribe to Status Page</p></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: Kindly note that an email subscription is automatically enabled by default.
{% endhint %}

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 To ensure that updates are effectively sent to subscribers of your Status Page, we highly recommend completing the domain verification process.\
\
🔹 **Best Practice Tip** 🔹 We recommend verifying if you have enabled your subscription settings according to your preferences. You have the option to set up a subscription for the entire page or choose specific components and maintenance updates to receive notifications for.
{% endhint %}

## Subscriber Limit

There is a subscriber limit based on the pricing plans available:

| Pricing Plan   | Limit                 |
| -------------- | --------------------- |
| **Premium**    | 5000 per Status Page  |
| **Enterprise** | 10000 per Status Page |

## Subscriber Status

Email subscriptions can exist in two distinct states:

* **Verified**
* **Not Verified**

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: You can find this status in the Subscriber List within the Subscriber section of each Status Page.
{% endhint %}

## Subscriber Settings

To edit subscriber settings,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. Click on the status page to navigate to the **Status Page Details page**.
3. In the top right, click **More** -> **Subscriber Settings.**
4. To enable subscriptions via email, check to **Allow users to subscribe via Email**
5. Similarly, to enable subscribers via Webhooks, check to **Allow users to subscribe via Webhook**.
6. You can also specify the subscription options available to users:
   * **Entire Status Page**
   * **Individual Components**
   * **Maintenance Updates**
7. Once you have added your preferred settings, click **Save**.

<div><figure><img src="/files/jjKb480CnLIp0zUmPiCJ" alt="Navigate to Subscriber Settings" width="563"><figcaption><p>Image. Navigate to Subscriber Settings</p></figcaption></figure> <figure><img src="/files/szfTPYAO8W6iIgzsBMBf" alt="Customize your Subscriber Settings" width="563"><figcaption><p>Image. Customize your Subscriber Settings</p></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**Component Subscriptions**</mark>

Component Subscriptions ensure that your subscribers receive updates exclusively on the topics that truly matter to them.\
\
Subscribers can pick and choose components they wish to receive notifications about and opting out of notifications for others.
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Webhook Subscriptions**</mark>

Subscriber users will receive a webhook notification when you create an incident, update an incident, resolve an incident or change a component status.\
\
All we need is their Webhook Endpoint URL and email address. <mark style="color:blue;">**Note**</mark>: We'll send them an email if the endpoint fails.
{% endhint %}

The subscribe option is now available on your public Status Page, allowing your end users to subscribe and receive incident update notifications directly from the Status Page.

## Export Subscribers

To export subscribers,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. Click on the status page to navigate to the **Status Page Details page**.
3. In the **Subscribers Section**, click **Export**.
4. On clicking export, a CSV file will be sent to your email.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Maintenance

Efficiently schedule maintenance windows and notify subscribers of planned downtime events. Keep users informed and minimize disruptions.

Scheduling maintenance is a way to let your page viewers know ahead of time when you will be unavailable due to maintenance. Scheduling maintenance will add the information to your status page and also send a notification to those who have opted-in to receive notifications.

## Add Schedule Maintenance

To schedule maintenance,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. Click on the status page to navigate to the **Status Page Details page**.
3. In the **Maintenance Section**, click **Add Schedule Maintenance**.
4. Enter the **Maintenance Name**.
5. Select a **Start Date**, **Duration**, and **End Date** and **Time**.
6. Select one or a component from the drop-down. You can add multiple components to a status page maintenance together.
7. Enter a **note** to provide further details on the maintenance.
8. Click **Save**.

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>:

It's important to note that the **Maintenance Title** is an internal field visible exclusively in the admin dashboard. It serves as a reference for internal users to understand the purpose behind scheduling a specific maintenance event.\
\
While the **Maintenance Note** is an external field that will be displayed in a specific format on the page. It is used to inform subscribers about the reason behind scheduling maintenance.
{% endhint %}

## Edit Schedule Maintenance

To edit scheduled maintenance,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. Click on the status page to navigate to the **Status Page Details page**.
3. In the **Maintenance Section**, hover over any of the scheduled maintenance and click **Edit**.
4. Once you have edited your preferred changes, click **Save**.

## Delete Schedule Maintenance

To delete scheduled maintenance,

1. Navigate to **Status Page** -> select or search for your desired status page.
2. Click on the status page to navigate to the **Status Page Details page**.
3. In the **Maintenance Section**, hover over any of the scheduled maintenance and click **Delete**.
4. A confirmation modal will open, choose between deleting this event or all following events too.
5. Click **Delete**.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# SLO Basics

Elevate service delivery using Service Level Objectives (SLOs). Define and enforce performance agreements for enhanced customer satisfaction and efficient service management.

{% embed url="<https://www.youtube.com/watch?v=pZe6fTA2HHo>" %}

In recent years, organizations have increasingly adopted Service Level Objectives, or SLOs, as a fundamental part of their Site Reliability Engineering (SRE) practice. Best practices around SLOs have been pioneered by Google—the [<mark style="color:blue;">Google SRE book</mark>](https://sre.google/sre-book/service-level-objectives/) provides a great introduction to this concept.

In essence, SLOs are rooted in the idea that service reliability and user happiness go hand in hand. Setting concrete and measurable reliability targets helps organizations strike the right balance between product development and operational work, which ultimately results in a positive end-user experience.

### What is a Service Level Objective? <a href="#what-is-a-service-level-objective" id="what-is-a-service-level-objective"></a>

{% hint style="info" %}
A **Service Level Objective (SLO)** is a reliability target, measured by a Service Level Indicator (SLI) and sometimes serves as a safeguard for a Service Level Agreement (SLA). SLOs represent customer happiness and guide the development team’s velocity
{% endhint %}

SLOs quantify customers’ expectations for reliability and start conversations between product and engineering on reliability goals and action plans when the goal is at risk. An example SLO for service is 95% availability in a rolling 28-day window.

You might feel tempted to set the objective at 100%, but that’s too good to be true. Change brings instability, which will inevitably lead to failure. Not only is 100% reliability an impossible target, but it would also mean that you can’t make any changes to the service in production. So expecting perfect reliability is the same as choosing to stop any new features from reaching customers and choosing to stop competing in the market.

**The rule of thumb for setting an SLO is to find the point where the customer is happy with the service’s reliability.**

### Who does your SLO matter to? <a href="#who-does-your-slo-matter-to" id="who-does-your-slo-matter-to"></a>

In order to get the main stakeholders across your organization to adopt SLOs, you will need them to agree on reliability targets that are realistically achievable, given the priorities of the business and the projects they wish to work on. We will take a closer look at what end-users, developers, and operations engineers care about—and how we should factor in their goals and priorities when setting SLOs.

#### End Users <a href="#end-users" id="end-users"></a>

No matter what product, end users have expectations for the quality of service they receive. While you could use support tickets or incident pages to gauge how unhappy your customers are, you shouldn’t solely rely on them for making product decisions as they do not comprehensively capture your end-user experience.

SLOs help you figure out the right balance between product innovation (which will help you provide greater value to your end users, but runs the risk of breaking things) and reliability (which will keep those users happy). Your error budgets dictate the amount of unreliability that can be afforded for development work before your end users are likely to experience a degradation in quality of service.

#### Developers and Operations Engineers <a href="#developers-and-operations-engineers" id="developers-and-operations-engineers"></a>

Traditionally, the split between developers and operations engineers stems from their opposing goals and responsibilities: developers aim to add more features to their services, while operations engineers are responsible for maintaining the stability of those services.

With SLOs—and their accompanying error budgets—in place, teams are able to objectively decide which projects or initiatives to prioritize. As long as there is an error budget remaining, developers can ship new features to improve the overall quality of the product, while operations engineers can focus more heavily on long-term reliability projects. But when the error budget begins running low, developers will need to slow down or freeze feature work—and work closely with the operations team to restabilize the system before any SLAs or SLOs are violated.

In short, error budgets act as a quantifiable method for aligning the work and goals of developers and operations engineers.

Before we go any further, let’s walk through some of the fundamental concepts and definitions we use within the product.

### Key Terminology <a href="#key-terminology" id="key-terminology"></a>

* **SLA or Service Level Agreement** is an explicit or implicit agreement between a client and service provider stipulating the client’s reliability expectations and the service provider’s consequences for not meeting them.
* **SLO or Service Level Objective** is an agreement within an SLA about a specific metric over a certain period of time. It is expressed as a percentage or ratio over some time, for example, “99.95% availability over 24 hours”.
* **SLI or Service Level Indicator** measures compliance with an SLO (Service Level Objective). So, for example, if an SLA specifies that your system will be available 99.95% of the time, your SLO is likely 99.95% uptime and your SLI is the actual measurement of your uptime. Maybe it’s 99.90%, or maybe it’s 99.99%.
* **Error Budget** is the maximum acceptable downtime without breaching the SLO. For example, if your Service Level Agreement (SLA) specifies an uptime of 99.99% (in a year) before the business has to compensate clients for the outage, that means your error budget (or the time for which your system can go down without any consequences) is 52 mins 35 secs in a year.
* **Burn Rate** tells you how fast you are consuming the allocated error budget.

SLOs can be defined over various time intervals, you can either use a *Rolling Time Window* or a *Fixed Duration Window*.

* **Fixed Duration**, when selected as the **Period Type**, user can specify the Period Length, which can be a day, a week or a month. Periods are non-overlapping and fixed to the calendar start and end dates. Compliance is calculated at the end of the time period. An example of where the Calendar period makes sense is when the company wants to calculate SLO compliance one quarter at a time.
* **Rolling Period**, when selected as the **Period Type**, user can specify the number of days for the Period Length, like, 30 days. They don’t have fixed start and end dates. With a rolling time period, you get the last 30 day measure of compliance, each day, rather than one per month. However, services can hover between compliance and non-compliance as the SLO status changes daily.
* **False Positives** are those incidents that were marked initially as affecting an SLO (and hence be considered for error budget calculations) but after further analysis, they were deemed not to be SLO affecting.

### Getting from SLIs to SLOs <a href="#getting-from-slis-to-slos" id="getting-from-slis-to-slos"></a>

Now that we’ve defined some key concepts related to SLOs, it’s time to begin thinking about how to graft them. Developing a good understanding of how your users experience your product—and which user journeys are most critical—is the first and most important step in creating useful SLOs.

Here are a few questions you should consider:

1. How are your users interacting with your application?
2. What is their journey through the application?
3. Which parts of your infrastructure do these journeys interact with?
4. What are they expecting from your systems and what are they hoping to accomplish?

You would need to figure out how your customers interact with the product—and what path they take from when they first enter the site until they exit.

Critical user journeys are directly related to user experience, and therefore, would be important to set SLOs on.

Once you’ve gone through this exercise, you can then move on to selecting metrics—or SLIs—to quantify the level of service you are providing in these critical user journeys.

### Picking good SLIs <a href="#picking-good-slis" id="picking-good-slis"></a>

As your infrastructure grows in complexity, it becomes more cumbersome to set external SLOs. We recommend organizing your system components into a few main categories and specifying SLIs within each of these categories.

As you start selecting SLIs, a short but important saying to keep in mind is: “All SLIs are metrics, but not all metrics make good SLIs.” This means that while you might be tracking hundreds or even thousands of metrics, you should focus on the indicators that matter most: the ones that best capture your users’ experience.

You can use the table below—which comes from [<mark style="color:blue;">Google’s SRE book</mark>](https://sre.google/workbook/implementing-slos/#slis-for-different-types-of-services)—as a reference.

![](/files/z8wfwA2lzWmEWAouCne3)

Once you have identified good SLIs, you’ll need to measure them with data from your monitoring system. Again, we recommend pulling data from the components that are in closest proximity to the user.

### Finally turning SLIs into SLOs <a href="#finally-turning-slis-into-slos" id="finally-turning-slis-into-slos"></a>

Finally, you will need to set a target value—or range of values—for an SLI to transform it into an SLO. You should state what your best- and worst-case standard would be—and over what period of time this condition should remain valid. For example, an SLO tracking request latency might be “The latency of 99 percent of requests to the authentication service will be less than 250 ms over a 30-day period.”

As you start to create SLOs, you should keep the following points in mind.

#### Be realistic <a href="#be-realistic" id="be-realistic"></a>

And as a general rule of thumb, you should keep your SLOs slightly stricter than what you detail in your SLAs. It’s always better to err on the side of caution to ensure you are meeting your SLAs rather than consistently under-delivering.

#### Experiment away <a href="#experiment-away" id="experiment-away"></a>

There is no hard-and-fast rule for perfecting SLOs. Each organization’s SLOs will differ depending on the nature of the product, the priorities of the teams that manage them, and the expectations of the end-users. Remember that you can always continue to refine your targets until you find the most optimal values.

#### Don’t overcomplicate it <a href="#dont-overcomplicate-it" id="dont-overcomplicate-it"></a>

Last but not least, resist the temptation to set too many SLOs or to overcomplicate your SLI aggregations when defining your SLO targets.

In general, you should restrict your SLOs and SLIs to only ones that are absolutely critical to your end-user experience. This helps cut through the noise so you can focus on what’s truly important.

### How to Define the SLO of a Service? <a href="#how-to-define-slo-of-a-service" id="how-to-define-slo-of-a-service"></a>

We will discuss the step-by-step approach to defining service level objectives. There are no hard and fast rules concerning the order of the steps. Some companies start by defining user journeys and formulating the SLO accordingly, whereas others start with metrics and hypothesize user journeys later to improve and refine an existing SLO.

1. Define user journey with the product team
2. Identify the key services that are on the user journey and select the best SLI type
3. Define SLI
4. Define SLO
5. Create an error budget policy
6. Monitor and report on the SLO
7. Periodically re-evaluate the SLO and make changes as needed

### How often will my SLOs change? <a href="#how-often-will-my-slos-change" id="how-often-will-my-slos-change"></a>

If this is your first time implementing SLOs, know that they are meant to be evolutionary.

The first step is agreeing on the need for an SLO and just getting started. You don’t have to focus on getting it right the first time. It’s natural to change your SLIs and SLOs as you start measuring them and start understanding the reliability of your services better.

The Google SRE book has a fantastic [<mark style="color:blue;">read</mark>](https://sre.google/workbook/implementing-slos/#continuous-improvement-of-slo-targets) that can help you understand how to continuously improve your SLO targets.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Configure and Monitor your SLOs

With Squadcast, you can define and monitor Service Level Objects for your services.

{% hint style="info" %}
**Note:**

This feature is available as part of the Product Trial and [<mark style="color:blue;">Premium and Enterprise</mark> Plan](https://www.squadcast.com/pricing).
{% endhint %}

{% hint style="info" %}
Before configuring your SLOs, we recommend you read our [<mark style="color:blue;">SLO Basics documentation</mark>](https://support.squadcast.com/docs/slo-basics)<mark style="color:blue;">.</mark>
{% endhint %}

Before you begin to define your SLO, you should have an expectation of what percent of your SLI (availability, latency, etc.) is needed to pass the SLO. For example, you may want your service to be available 99.99% of the time to pass the SLO. In this case, 99.99% is the *Target SLO* and “availability” is your *SLI*.

## Creating New SLO <a href="#creating-new-slo" id="creating-new-slo"></a>

Navigate to **SLO** from the left sidebar. To create a new SLO, click on **+Create New SLO** button on the top right.

### Define SLO <a href="#define-slo" id="define-slo"></a>

You begin by defining your SLO.

<figure><img src="/files/VGsx4XbOPPF2bqvZlaa1" alt="Creating new SLO - Define SLO"><figcaption></figcaption></figure>

1. Enter the SLO Name of your choice (this needs to be unique across SLOs)
2. Enter the SLO Description detailing out specifics of the SLO
3. Enter Tags (key-value pairs) specifying information such as the Owner, Environment and Type of SLO

You can additionally add your own tags by clicking the **+Add Tag** button.

\
Once done, click on **Next** to Configure SLO.

### Configure SLO <a href="#configure-slo" id="configure-slo"></a>

1. Under the **Services Associated with this SLO** tab, you can select multiple Services to link it to the SLO. Only incidents from these linked Services can then be mapped to the SLO
2. Enter the **SLIs that affect the SLO**. There could be one or more SLIs - like availability, response time, etc - that map to this SLO
3. Enter the percentage or ratio under **Target SLO in %**. This sets the target percentage to define compliance
4. **Error Budget** is auto-calculated based on the values entered for target SLO and duration. It is calculated in minutes and cannot be edited
5. Enter the **Duration** for this SLO, by choosing between **Rolling Period** or **Fixed Duration** (Calendar Duration)

* Under **Rolling**, you can select the period in days. This option is used when you want the SLO calculated continuously for a defined number of days (for example, continuously over a 7-day period). This can be a maximum of 90 days.
* Under **Fixed Duration**, you can select the start and end dates from the drop-down. This option is used when the SLO has to be calculated over a fixed duration - for example, over one quarter at a time. The fixed duration can be a maximum of one year.\
  Once done, click on **Next** to configure Error Budget Policy.

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark> When an SLO reaches the end of its configured time duration, it transitions into an inactive state. Once inactive, the SLO becomes uneditable, signaling that it has fulfilled its purpose and achieved the intended goal for which it was established.
{% endhint %}

### Error Budget Policy <a href="#error-budget-policy" id="error-budget-policy"></a>

<figure><img src="/files/nqgOR0AdRE6IAQgOivNw" alt="Error Budget Policy Configuration"><figcaption></figcaption></figure>

The **Error Budget Policy** defines the conditions based on which to notify one or more Users or Squads or when incidents have to be created when a condition is breached.

Choose the conditions you want to be alerted for, out of the following options:

* Alert when there is a breach of allocated **Error Budget**
* Alert when there is an **Unhealthy Burn Rate**. An unhealthy burn rate is determined when the error budget is burning faster than what’s expected. For example, for an SLO of 99.99% over the course of a year, the error budget works out to be about 52 mins 35 seconds - or approximately about 4 mins 30 sec per month. If the error budget is being burnt faster than than, then its considered unhealthy
* Alert when the number of **False Positives** exceeds the set limit
* Alert when the **Error Budget** decreases below the set limit

Choose the mode of delivery of the alerts

* **Email** Alerts, wherein an email notification is sent to the Users or Squads you specify
* **Incident** Alerts, wherein an alert is created for the specified Service

\
Once done, click on **Create**, and your SLO is created!

## Monitor Your SLOs

Once created, you can access all your SLOs for the current Team from the SLO dashboard.

<figure><img src="/files/PP2w98LfxIT2zwhfz7ls" alt="SLO dashboard"><figcaption></figcaption></figure>

The SLO list view shows information for each SLO, including:

| Field              | Description                                                                       |
| ------------------ | --------------------------------------------------------------------------------- |
| Target SLO (%)     | Shows the percentage or ratio to target, which is the target value for compliance |
| Current SLO (%)    | Shows the current historical compliance with the SLO                              |
| SLO Health         | Indicates the health of the SLO, either as Healthy or Needs Attention             |
| Service            | Shows the services related to the SLO                                             |
| Status             | Indicates whether the SLO is Active or Inactive                                   |
| Incidents Reported | Indicates the # of incidents reported **+** the false positives for this SLO      |
| Time Window        | Indicates the type of time window you have configured, either Rolling or Fixed    |
| Duration (Days)    | Indicates the duration (in days) for which the slo is configured                  |
| Updated On         | Indicates the latest date of update                                               |
| Tags               | Indicates the tags associated with the SLO                                        |

## SLO Detail Page <a href="#slo-detail-page" id="slo-detail-page"></a>

To view the details of a particular SLO, select the SLO from the SLO list in the SLO dashboard.

<figure><img src="/files/22GCmNlqIocaoCVUICnO" alt="SLO Detail Page - Squadcast"><figcaption></figcaption></figure>

The SLO details view shows information for each SLO, including:

<table><thead><tr><th width="344">Field</th><th>Description</th></tr></thead><tbody><tr><td>Target SLO (%)</td><td>Indicates the percentage value set to target performance compliance.</td></tr><tr><td>Total Error Budget (mins)</td><td>Indicates the entire time period for which a system can fail without violating the SLO.</td></tr><tr><td>Time Window</td><td>Indicates the extent of time for which the SLO has been set. It can be on a rolling (or continuous) basis or on a fixed basis (eg, once a quarter).</td></tr><tr><td>Duration</td><td>Indicates the duration (in days) for which the SLO is configured.</td></tr></tbody></table>

*The fields hereon are time-range sensitive.*

| Field                         | Description                                                                                                                                                                                                                                                                                                                                                                                                           |
| ----------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Current SLO (%)               | Indicates the current historical compliance with the SLO in the specified time range.                                                                                                                                                                                                                                                                                                                                 |
| Error Budget Consumed         | Indicates the Error Budget consumed in the specified time range.                                                                                                                                                                                                                                                                                                                                                      |
| MTTA (mins)                   | Indicates the mean time taken to acknowledge the SLO-violating incidents, for the specified time range.                                                                                                                                                                                                                                                                                                               |
| MTTR (mins)                   | Indicates the mean time taken to resolve the SLO-violating incidents, for the specified time range.                                                                                                                                                                                                                                                                                                                   |
| Error Budget Consumed by SLIs | <p>Indicates the consumption of error budget across different SLIs, including the number of incidents affecting each of the SLIs.<br></p><p>Expand the accordion to view a further breakdown of the error budget consumed by each SLI, and a list of services associated with the SLO.<br><img src="/files/YH9R4ex27bj07y9xCcGr" alt="Error Budget consumed by SLIs &#x26; list of services associated with SLO"></p> |

## Marking an Incident as False Positive <a href="#marking-an-incident-as-false-positive" id="marking-an-incident-as-false-positive"></a>

This is useful if an incident was previously marked as one that affects an SLO and has been subsequently determined that it does not. This acts like an “undo” button.

Through the SLO Details page, checkmark the incident(s) -> Click on Mark as **False Positive** button

<figure><img src="/files/8ukTTOdBr16UhLtQ8ooX" alt="False positive in SLO monitoring"><figcaption></figcaption></figure>

{% hint style="info" %}
**Note:**

If you marked an incident as False Positive by mistake, you can undo this. Navigate to **False Positives** tab on SLO Details Page -> Check the **incident** -> Click on **SLO Affected**

<img src="/files/jDkBXQ73cFEIUZweIdAQ" alt="Check SLO Affected on False Positives tab on SLO Details Page" data-size="original">
{% endhint %}

## Deleting an SLO <a href="#deleting-an-slo" id="deleting-an-slo"></a>

To delete an SLO, click on the icon on the right of the SLO from the SLO list, and click on the **Delete** icon, as shown in the image below.

<figure><img src="/files/zMfOq6jBIc5aNGXLuMzs" alt="Illustration of deleting an SLO"><figcaption></figcaption></figure>

## FAQs <a href="#faqs" id="faqs"></a>

Please refer to the Frequently Asked Questions below that might help you fix any issues/answer your queries.

#### 1. Can I delete services associated with an SLO? <a href="#id-1-can-i-delete-services-associated-with-an-slo" id="id-1-can-i-delete-services-associated-with-an-slo"></a>

Yes, you can delete a service associated with an SLO, the SLO and its Incidents will still be intact.

#### 2. How is the Error Budget calculated? <a href="#id-2-how-is-the-error-budget-calculated" id="id-2-how-is-the-error-budget-calculated"></a>

An error budget is 1 minus the SLO of the service. A 99.9% SLO service has a 0.1% error budget. If our service receives 1,000,000 requests in four weeks, a 99.9% availability SLO gives us a budget of 1,000 errors over that period.

#### 3. How is the Burn Rate calculated? <a href="#id-3-how-is-the-burn-rate-calculated" id="id-3-how-is-the-burn-rate-calculated"></a>

* First, we calculate the error budget allocated for a day. (for eg: if slo is 99.99% for a year, you get a 55.5min/365 error budget for a day)
* Then, we fetch the total error budget spent till today’s date
* Subsequently, we see how many days its been since the slo started and later check if the user has consumed more error budget than they were supposed to, to calculate the burn rate

#### 4. What determines a Healthy or Unhealthy SLO? <a href="#id-4-what-determines-a-healthy-or-unhealthy-slo" id="id-4-what-determines-a-healthy-or-unhealthy-slo"></a>

Healthy or unhealthy is based on how rapidly the error budget is getting depleted. Slo burn rate indicates how fast your error budget is getting consumed relative to your SLO’s target length.

For example, if have a 99.9% target for a month, then you will get 43.12 min of downtime, Which means you can burn 1.43 Min(43.12/30) of error budget every day. If you burn a total of 30 min of error budget within the first 10 days of your SLO duration then it will turn to *Needs Attention* (unhealthy).

So the SLO is Healthy today because it’s consumed less error budget than allocated for the days it's been since the SLO started.

#### 5. Can I automatically associate incidents with an SLO? <a href="#id-5-can-i-automatically-associate-incidents-with-an-slo" id="id-5-can-i-automatically-associate-incidents-with-an-slo"></a>

We’re working on something that can help you do this in the near future.

#### **6. Are there any rate limits for SLOs?**

There exists a rate limit on the number of SLO promotions that can take place (manually or via Workflows). Not more than 50 incidents per hour can be promoted to SLO violations in a Team.

#### 7. How many incidents are considered for error budget calculation when they are overlapping in a given time window?

The current incident and 49 preceding incidents (a total of 50 incidents) are considered for calculating the error budget consumed in case there is an overlapping observed by the system (i.e., calculate the cumulative error budget consumed for multiple "open" SLO-violating incidents).

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Webforms

Webforms can help stakeholders & the customers of an organization easily report issues

{% embed url="<https://www.youtube.com/watch?v=y-hNub20UnE>" %}
Webforms | Creating alerts from outside Squadcast ecosystem
{% endembed %}

Squadcast allows organizations to expand their customer support by hosting public Webforms, so their customers can quickly create an alert from outside the Squadcast ecosystem. Not only this, but internal stakeholders can also leverage Webforms for easy alert creation.

Webforms also support custom CNAMES so you can host them on your own domain, say <mark style="color:blue;"><https://support.example.com></mark>.

Check out our blog post [<mark style="color:blue;">here</mark>](https://www.squadcast.com/blog/introducing-webforms-live-call-routing-incident-management-process) for more information!

{% hint style="info" %}
Webforms will be available in the [<mark style="color:blue;">Premium and Enterprise plans only</mark>](https://www.squadcast.com/pricing).
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>: We utilise a reCaptcha integration for Webforms, adding an extra layer of security against bot-based spamming. This is supported for both the types of Webforms.
{% endhint %}

## **Configure a Webform**

To configure a webform:

1. Navigate to **Webforms** -> **Create Webform**
2. Setting up a Webform consists of 4 steps:

#### Step 1: Form Configuration

1. Give the Webform a Name

<figure><img src="/files/xXLvzanmKyjkmfEJ5V3k" alt="Configure Webforms in Squadcast" width="563"><figcaption></figcaption></figure>

2\. By default, every Webform has a public URL (Squadcast hosted). However, you can also set up custom CNAMES so you can host them on your own domain

<figure><img src="/files/BNXsBuAkKtSTfv1erMmb" alt="Set up custom domain for Webforms" width="563"><figcaption></figcaption></figure>

3\. Associate tag key-value pairs with your Webforms

<figure><img src="/files/GQ6NGooIW9h3tHLWttzp" alt="Create tags for Webforms"><figcaption></figcaption></figure>

#### Step 2: Define Owner & Services

1. Choose the owner of the Webform. The owner can be a user, or a squad in which the Webform is being set up.
2. Select the services that would be displayed on the Webform. For the selected services, aliases can be defined. This is especially important since your services in Squadcast might have names that are internal/technical for your customers/stakeholders

<figure><img src="/files/lfmWVfEqbdAYsraI7cjf" alt="Define Owner and Services for Webforms" width="563"><figcaption></figcaption></figure>

#### **Step 3: Input Configuration**

1. Here is where you can define the input fields reporters can associate with the alerts they create. Specify the Input fields that the reporter will see on the Webform and can select one of the options against the label.
2. Give each input field type a label and options. This helps the reporter to understand which label would be most relevant to them while creating the alert. These labels will be reflected as tags for the created alert.

<figure><img src="/files/OiMsAQT8JbwnEtYAE0iW" alt="Configure Input Fields in the Webform" width="563"><figcaption></figcaption></figure>

#### Step 4: Customise your Webform by providing Additional Details

1. Fill in the Form Header, Title, and Description fields to customize and give more context to your users
2. Upload a logo (of size not larger than 70 kB)
3. The Footer Text and Link fields can be used to route your users to your website, a mail link, or even a Status Page if you use one!
4. If you want your reporter to receive email updates for the issue reported, you can choose the option(s) - send an email on the issue “trigger”, send an email on the issue “acknowledged by internal team”, send an email on the issue “resolution”

<figure><img src="/files/aOOOsNVAqOaCwVPDJuw6" alt="Customize the Webform in Squadcast" width="563"><figcaption></figcaption></figure>

With this, your Webform configuration is complete! Depending on the mode of setup for hosting your Webform, your Webform will now be publicly accessible.

![Sample Webform created using Squadcast](/files/XFI6CDHv8eq0T1GuZTXn)

Issues reported here will create incidents in Squadcast for the selected Service. The severity selected here gets added as a tag to the incident. The creation of the incident will, in turn, will trigger the Escalation Policies accordingly.

There are 2 ways in which the right responders are notified of Webform incidents:

1. If there are Routing Rules defined for severities of the services listed in the Webform, the tag would then trigger the configured Routing Rules. Based on the Routing Rules defined, the right user, squad, or escalation will be notified for the incident.
2. If there are no Routing Rules defined for severities of the services listed in the Webform, then the default escalation policy of the service for which the incident has been triggered will be executed.

{% hint style="info" %}
**Things to Understand**

1\. Every user in the team needs to have the right set of permissions (configured from the Settings page) to CRUD Webforms

2\. The listing page for Webforms contains the following information:

a) The name of the Webform

b) Quick link to the Webform

c) Form Owner

d) Quick link to view incidents (Tip: Once you land on the Incident List page, apply the filter Alert Source > Webform)

e) Services associated with the Webform

f) MTTR of the incidents associated with each of the Webforms; this metric helps teams understand how quickly customer/stakeholder-reported issues are being resolved

3\. Once a Webform is deleted, it appears as grayed out on the listing page of Webforms
{% endhint %}

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Global Event Rulesets

Streamline routing alerts across services and take action based on predefined global event rulesets

Global Event Rulesets let you create rulesets for alert routing, eliminating the need for individual alert source webhooks setup for each Service. This centralized routing simplifies configuration management, saving time and enhancing efficiency, particularly for users dealing with numerous micro-services.

The scope for a ruleset is a Team, and the execution updates for Global Event Rulesets are recorded in the Incident Activity Timeline.

<figure><img src="https://lh4.googleusercontent.com/3bxYItAhXlUDJPjDM0IqpFYRHTjQTrlnzyVQp8K3yLJyR5JPsaQGc2dfhGuYncAvojqRbnh2BUn0p2A0xRCOezEMItC_3NfT0njZo0koVOPpJOd1xu3D1BJ535YK_DgivkW8O8MExWzjRaaG2s7-9Z4" alt="Global Event Rulesets flow in Squadcast for Incident Management" width="563"><figcaption><p>Image. Global Event Rulesets</p></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> This feature will be available for accounts in the [<mark style="color:blue;">Enterprise plan</mark>](https://www.squadcast.com/pricing).
{% endhint %}

## Prerequisite

* To effectively create and manage Global Event Rulesets, the user assigned to the Team must possess the appropriate permissions corresponding to their User Role.

## Add Ruleset

To add new rulesets,

1. Navigate to **Global Event Rulesets** -> **Add New Ruleset**
2. Next, add the **Ruleset Name**, *optional* **Description**, and select the **Ruleset Owner**.
3. Click **Save**, and you're done.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

1. You can create and manage up to 30 rulesets for each Team.
2. A Ruleset Owner is a user or a Squad that someone can reach out to, for anything pertaining to that ruleset. There are no permissions associated with the ownership here.
   {% endhint %}

<div><figure><img src="/files/tqf9pg4E2wFIWraBC5ia" alt="Add Ruleset in Squadcast for Incident Management"><figcaption><p>Image. Add Ruleset</p></figcaption></figure> <figure><img src="/files/fMkFBBmM4f4cQHXvNsBQ" alt="Details for added Ruleset in Squadcast for Incident Management"><figcaption><p>Image. Details for added Ruleset</p></figcaption></figure></div>

This creates a new ruleset, and the next step is to add alert sources and start creating rules for your ruleset. If you would like to create multiple such rulesets, each with individual endpoints, repeat the above steps as needed.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> You can edit or delete a ruleset from its detail page.

Please note, that deleting a ruleset will remove all the mapped alert sources and their rules.
{% endhint %}

## Add Alert Sources

To add alert sources to a ruleset,

1. Navigate to **Global Event Rulesets** -> select the relevant ruleset from the list.
2. Click **Add Alert Source** -> In the side panel, search and select the alert source you wish to create a rule for -> Click **Add**.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

1. You can only add one alert source at a time.
2. Deleting an added alert source from the ruleset will result in all its rules getting deleted.
   {% endhint %}

<div><figure><img src="/files/lJouzfTbTnXCrcVG6pf6" alt="Add Alert Source in GER in Squadcast for Incident Management"><figcaption><p>Image. Add Alert Source</p></figcaption></figure> <figure><img src="/files/rPSkoqBRCIK96r4QrmHW" alt="Added Alert Source in GER in Squadcast for Incident Management"><figcaption><p>Image. Added Alert Sources</p></figcaption></figure></div>

## Add Rules

Event rules allow you to set actions that should be taken on events that meet your designated rule criteria. In the current version, the only action that the system takes is routing of incoming alerts.

To add rules for an alert source,

1. Navigate to **Global Event Rulesets** -> select the relevant ruleset from the list.
2. For your added alert source, click **Add Rule.**
3. In the side panel, provide a **Rule Description** and create the **Rule Expression**, referring to the payload data available on the right.
4. Lastly, designate the Service for routing when the rule expression is met -> Click **Save**.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> You can create and manage up to 1000 rules for each alert source.
{% endhint %}

<div><figure><img src="/files/yHYQVTvkJy2pYZbvKzNd" alt="Add Rules for an Alert Source in Squadcast for Incident Management"><figcaption><p>Image. Add Rules for an Alert Source</p></figcaption></figure> <figure><img src="/files/juT6pNAVJ3P7btNJ7tGN" alt="View and arrange priority of added Rule in Squadcast for Incident Management"><figcaption><p>Image. View and arrange the priority of added Rule</p></figcaption></figure></div>

To manage the order of rule execution, simply use the arrows to rearrange the priority of these rules.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

1. The payload you see on the right may be a sample payload provided by Squadcast for the selected alert source, if you have not set up alert source webhooks and started receiving alerts yet. If the webhooks have been set up and you are receiving alerts, then you will see the payload of the latest alert for that alert source.
2. Also note that, if alert sources support multiple types of payloads for different events, please ensure you refer to the documentation of your alert source for the different payload structures.
3. You will see only the Services for the selected Team.
   {% endhint %}

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>: If you intend to delete a Service in Squadcast that is associated with a Global Event Ruleset, please ensure that you delete the rule first. Otherwise, you will receive a warning message similar to the one described below.

<img src="/files/i2oFQQVSoZ7i2x0ahwFr" alt="" data-size="original">
{% endhint %}

### Example

**Alert Source: Admin Labs**

```
{
    "webhookId": "5e3378c2-275d-11e8-89db",
    "monitorId": "1afb2342-2754-11e8-89db",
    "monitorName": "Example",
    "monitorAddress": "http://example.adminlabs.com/example.html",
    "stateChange": "down",
    "outageId": "4fd5c5df-275d-11e8",
    "outageStartedAt": "2018-03-14 08:57:09",
    "outageEndedAt": null,
    "maintenanceId": null
  }
```

**Example Rule Expression:**

```
payload.stateChange="down"
```

## Catch All Rule

Any alerts that are sent through event rules but do not match any are routed to the Service configured in the Catch All Rule. If the Catch All Rule is empty, the outlier alert is simply dropped from the system. Configuring this helps in making sure no alerts are missed, that is, every incoming alert ends up reaching a Service.

{% hint style="success" %}
🔹 **Best Practice Tip** 🔹 This is not mandatory, but we highly recommend having this configured.
{% endhint %}

To add a catch-all rule,

1. Navigate to **Global Event Rulesets** -> Select the relevant ruleset from the list.
2. For your added alert source, click **Add Catch All Rule** -> Select a **Service**.
3. Click **Save**.

<div><figure><img src="/files/KWuSwetdeS9P2h7detU0" alt="Add Catch All Rule for an Alert Source in Squadcast for Incident Management"><figcaption><p>Image. Add Catch All Rule for an Alert Source</p></figcaption></figure> <figure><img src="/files/KsB9buZMInCJMiygFW2o" alt="View Added Catch All Rule in Squadcast for Incident Management"><figcaption><p>Image. View Added Catch All Rule</p></figcaption></figure></div>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Workflows

Configure a predefined set of actions to automate responses to incidents.

A Workflow represents a predefined series of actions initiated by specific conditions. These Workflows are instrumental in automating responses to various incidents. For example, you can establish a Workflow for addressing P1/P2 incidents and another for managing security incidents.

{% @storylane/embed subdomain="app" url="<https://app.storylane.io/share/fjsma7cptada>" linkValue="fjsma7cptada" %}

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> This feature will be available in the [<mark style="color:blue;">Premium and Enterprise plans only</mark>](https://www.squadcast.com/pricing).
{% endhint %}

## Workflow Components

A Workflow comprises two fundamental components: Triggers and Actions. By tailoring these triggers and actions to your specific requirements, you can tailor a Workflow to suit your unique use case.

### Triggers

Triggers are events that dictate when actions should be executed. You can add multiple trigger conditions within each Workflow.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> In the case of multiple trigger conditions, all the conditions should be met in order to execute the actions.
{% endhint %}

**Here is a list of supported triggers:**

* When an Incident is Triggered
* When Incident is Acknowledged
* When Incident is Reassigned
* When the Incident is Resolved
* When Incident Tags are updated
* When Incident Priority is updated
* When Incident Note is added

### **Trigger Properties/Filters**

For each of the triggers, here are the available filters and their conditions:

* **Service** - is/is-not/contains/does not contain
* **Alert Source** - is/is-not/contains/does not contain
* **Tags** - is/is-not
* **Priority** - is/is-not

To emphasize once more, it's essential for all conditions to be satisfied for the actions to be executed.

### Actions

Each Workflow includes a predefined sequence of actions that determine the progression of the Workflow. These actions may involve tasks such as attaching Runbook(s) or marking an incident as SLO-affecting.

**Here is a list of the supported Squadcast actions:**

* [<mark style="color:blue;">**Attach Runbook(s)**</mark>](/workflows/actions#attach-runbook-s)
* [<mark style="color:blue;">**Add Communication Channel**</mark>](/workflows/actions#add-communication-channel)
* [<mark style="color:blue;">**Add Incident Note**</mark>](/workflows/actions#add-incident-note)
* [<mark style="color:blue;">**Mark Incident as SLO affecting**</mark>](/workflows/actions#mark-incident-as-slo-affecting)
* [<mark style="color:blue;">**Make an HTTP call**</mark>](/workflows/actions#make-an-http-call)
* [<mark style="color:blue;">**Send an Email**</mark>](/workflows/actions#send-an-email)
* [<mark style="color:blue;">**Trigger Manual Webhook**</mark>](/workflows/actions#trigger-manual-webhook)
* [<mark style="color:blue;">**Update Priority**</mark>](/workflows/actions#update-priority)
* <mark style="color:blue;">**Add**</mark>[ <mark style="color:blue;">**Status Page**</mark>](/workflows/actions#add-status-page-issue) <mark style="color:blue;">**Issue**</mark>

**Here is a list of the supported Slack actions:**

* [<mark style="color:blue;">**Create Incident-Specific Slack Channel**</mark>](/workflows/actions#create-incident-specific-slack-channel)
* [<mark style="color:blue;">**Archive Incident-Specific Slack Channel**</mark>](/workflows/actions#archive-incident-specific-slack-channel)
* [<mark style="color:blue;">**Send a Message to a Specific Slack Channel**</mark>](/workflows/actions#send-a-message-to-a-specific-slack-channel)
* [<mark style="color:blue;">**Send a Direct Message to a Slack User**</mark>](/workflows/actions#send-a-direct-message-to-a-slack-user)

**Here is a list of the supported Jira actions:**

* [<mark style="color:blue;">**Create a Jira Ticket**</mark>](/workflows/actions#create-a-jira-ticket)

**Here is a list of the supported MS Teams actions:**

* [<mark style="color:blue;">**Send a message to a Microsoft Teams Channel**</mark>](/workflows/actions#send-a-message-to-a-microsoft-teams-channel)

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark> When selecting the "Mark Incident as SLO Affecting" action, please ensure that you choose an active SLO that is associated with the same service as your incident.
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

* Each action will be executed serially, and all actions executed by a Workflow will be recorded in the Incident timeline.
* A Workflow will continue to run irrespective of the success/failure of a specific action.
  {% endhint %}

## Prerequisite

* To effectively create and manage Workflows, the user assigned to the Team must possess the appropriate permissions corresponding to their User Role.

## Add Workflows

To create a new workflow using the web app,

1. Navigate to the **Workflows page** -> **Create Workflow.**
2. Enter the **Title**, *optional* **Description**, **Workflow Owner**, and **Tags**.

<div><figure><img src="/files/SXyILXeo22SFaFxf4DtT" alt=""><figcaption><p>Image. Create Workflow</p></figcaption></figure> <figure><img src="/files/lpVWwW9IymOz6g9CzGg9" alt=""><figcaption><p>Image. Add Details on Title, Description, Owner, and Tags</p></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**How to Pick an Owner?**</mark>

A Workflow Owner is the designated contact for clarifications, adjustments, or removal of a Workflow. By default, the Team is assigned as the owner, but you can modify it using the drop-down menu.\
\ <mark style="color:blue;">**How to use Tags?**</mark>

Choose tags to organize, classify, and add context to your Workflows. For instance, adding tags like Environment, Cluster/Team name, and Priority can help structure and add more context to your Workflows.
{% endhint %}

3. Next, select the **Trigger** and its **filters**:

   1. You can select between the following triggers:
      1. **When incident is Triggered**
      2. **When incident is Acknowledged**
      3. **When incident is Reassigned**
      4. **When incident is Resolved**
      5. When Incident Tags are updated
      6. When Incident Priority is updated
      7. When Incident Note is added
   2. For each of the trigger events, here are the available **filters** and their **conditions**:
      1. **Service** - is/is-not/contains/does not contain
      2. **Alert Source** - is/is-not/contains/does not contain
      3. **Tags** - is/is-not
      4. **Priority** - is/is-not

   You can add a group of Triggers which all must hold true to set off the actions. Additionally, you can add a collection of filters using OR/AND conditions to consolidate their effects.

<figure><img src="/files/RsQOjS6Tp6nV8IcQcmNX" alt="" width="563"><figcaption><p>Image. Define Tigger and its Filters</p></figcaption></figure>

4. Next, select the **Actions** you want the Workflow to execute. These actions will execute one after the other.
   1. You can select between the following Squadcast actions:
      1. [<mark style="color:blue;">**Attach Runbook(s)**</mark>](/workflows/actions#attach-runbook-s)
      2. [<mark style="color:blue;">**Add Communication Channel**</mark>](/workflows/actions#add-communication-channel)
      3. [<mark style="color:blue;">**Add Incident Note**</mark>](/workflows/actions#add-incident-note)
      4. [<mark style="color:blue;">**Mark Incident as SLO affecting**</mark>](/workflows/actions#mark-incident-as-slo-affecting)
      5. [<mark style="color:blue;">**Make an HTTP call**</mark>](/workflows/actions#make-an-http-call)
      6. [<mark style="color:blue;">**Send an Email**</mark>](/workflows/actions#send-an-email)
      7. [<mark style="color:blue;">**Trigger Manual Webhook**</mark>](/workflows/actions#trigger-manual-webhook)
      8. [<mark style="color:blue;">**Update Priority**</mark>](/workflows/actions#update-priority)
      9. <mark style="color:blue;">**Add**</mark>[ <mark style="color:blue;">**Status Page**</mark>](/workflows/actions#add-status-page-issue) <mark style="color:blue;">**Issue**</mark>
   2. Or, you can select between the following Slack actions:
      1. [<mark style="color:blue;">**Create Incident-Specific Slack Channel**</mark>](/workflows/actions#create-incident-specific-slack-channel)
      2. [<mark style="color:blue;">**Archive Incident-Specific Slack Channel**</mark>](/workflows/actions#archive-incident-specific-slack-channel)
      3. [<mark style="color:blue;">**Send a Message to a Specific Slack Channel**</mark>](/workflows/actions#send-a-message-to-a-specific-slack-channel)
      4. [<mark style="color:blue;">**Send a Direct Message to a Slack User**</mark>](/workflows/actions#send-a-direct-message-to-a-slack-user)
   3. Or, you can select between the following Jira actions:
      * [<mark style="color:blue;">**Create a Jira Ticket**</mark>](/workflows/actions#create-a-jira-ticket)
   4. Or, you can select between the following MS Teams actions:
      * [<mark style="color:blue;">**Send a message to a Microsoft Teams Channel**</mark>](/workflows/actions#send-a-message-to-a-microsoft-teams-channel)

<div><figure><img src="/files/PLJoibfk24XMzB0NSySa" alt=""><figcaption><p>Image. Define Actions</p></figcaption></figure> <figure><img src="/files/P31P4XBqPja7LcQMXSLM" alt=""><figcaption><p>Image. Add Details for Sequence of Actions</p></figcaption></figure></div>

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark> When selecting the "Mark Incident as SLO Affecting" action, please ensure that you choose an active SLO that is associated with the same service as your incident.
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

* Each action will be executed serially, and all actions executed by workflows will be recorded in the Incident timeline.
* The workflow will continue to run irrespective of the success/failure of a specific action.
  {% endhint %}

5\. Once all details have been added, click **Done**.

After creating the Workflow, you will be automatically directed to the details page of the newly created Workflow. Here, you can access more information and logs related to this Workflow.

Additionally, you have the option to edit, update, or delete the Workflow directly from this details page.

<figure><img src="/files/M39qEeudNmRF9AEikpGO" alt="" width="563"><figcaption><p>Image. Workflow Details Page</p></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> Please note that you have access to the execution logs (audit logs) for the Workflow from the last 30 days.
{% endhint %}

## Edit Workflows

To edit a workflow,

1. Navigate to the **Workflows** page -> Click on the Workflow you want to edit, and you'll be directed to its details page.
2. From the three-dot menu, select **Edit**. -> The Workflows form, containing all the entered details, will appear. Once you've made the necessary updates, click **Close**.

<div><figure><img src="/files/kZXEyBnCQDB1Sg2Vs5rK" alt=""><figcaption><p>Image. Select Workflow</p></figcaption></figure> <figure><img src="/files/R6s0MylhPJqSR6iCiY1B" alt=""><figcaption><p>Image. Edit Workflow</p></figcaption></figure> <figure><img src="/files/H9RTO0JtWiDi0TceNXST" alt=""><figcaption><p>Image. Update Workflow Details</p></figcaption></figure></div>

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> The changes you make to the Workflow will be auto-saved.
{% endhint %}

## Delete Workflows

To delete a workflow,

1. Navigate to the **Workflows** page -> Click on the Workflow you want to remove, and you'll be directed to its details page.
2. From the three-dot menu, select **Delete** -> A confirmation modal will appear, click on **Delete** again to confirm.

Alternatively, you have the option to delete the Workflow directly from the listing page.

<div><figure><img src="/files/cXm8LzLhxQPDqWsIeTzJ" alt=""><figcaption><p>Image. Select Workflow</p></figcaption></figure> <figure><img src="/files/2WeiUpczidZcCPQMd8qO" alt=""><figcaption><p>Image. Delete Workflow</p></figcaption></figure> <figure><img src="/files/bvZK60oPPDj1yCdRy8wF" alt=""><figcaption><p>Image. Confirm Deletion</p></figcaption></figure></div>

## Logs

Show the logs of the workflows that have been executed and all of their corresponding details.

<table><thead><tr><th width="192">Field</th><th>Description</th></tr></thead><tbody><tr><td><strong>Execution Date &#x26; Time</strong></td><td>Displays the date and time when the workflow was executed.</td></tr><tr><td><strong>Log ID</strong></td><td>Displays the log id of the executed workflow.</td></tr><tr><td><strong>Status</strong></td><td>Displays where it was executed successfully or not.</td></tr><tr><td><strong>Incident</strong></td><td>Displays the incident that triggered the workflow.</td></tr><tr><td><strong>Actions Executed</strong></td><td>Displays the no. of actions executed under it.</td></tr></tbody></table>

To view further details about the executed actions,

1. Within the **Workflows** details page, navigate to the **Logs** section.
2. On hover, click on **View Log Detail** -> Here you can find the list of actions executed as part of the Workflow along with their individual timestamp.

<div><figure><img src="/files/Q39df7xge3mAXlACPZgY" alt=""><figcaption><p>Image. View Logs</p></figcaption></figure> <figure><img src="/files/m7HWQsjGoPPoWoxP5Mde" alt=""><figcaption><p>Image. View Log Details</p></figcaption></figure></div>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Workflows Overview

Use Workflows Overview to view relevant information and perform actions on workflows.

The Workflows Overview provides a quick, searchable snapshot of all your team's Workflows. Dive into each one to learn, make changes, and take action.

<figure><img src="/files/eBb1xmfHkUzEjAhaJRzb" alt="" width="563"><figcaption><p>Image. Workflows Overview</p></figcaption></figure>

## Workflows Overview

The Workflow Overview provides the following details:

<table><thead><tr><th width="229">Field</th><th>Desciption</th></tr></thead><tbody><tr><td><strong>Title</strong></td><td>Displays the title of the workflow.</td></tr><tr><td><strong>Enable</strong></td><td>Option to enable/disable a workflow.</td></tr><tr><td><strong>Trigger</strong></td><td>Shows the conditions set to trigger the workflow.</td></tr><tr><td><strong>Actions</strong></td><td>Shows the sequence of actions executed when the workflow is triggered.</td></tr><tr><td><strong>Owner</strong></td><td>Indicates the user or squad that owns the workflow.</td></tr><tr><td><strong>Created</strong></td><td>Shows user information and the creation timestamp of the workflow.</td></tr><tr><td><strong>Updated</strong></td><td>Shows user information and the most recent update timestamp of the workflow.</td></tr><tr><td><strong># of Execution</strong></td><td>Displays the number of times the workflow has been executed.</td></tr></tbody></table>

### Search

To search for a specific workflow, enter its name or any other related keywords in the Search field and hit enter.

### Filters

To filter workflows,

1. Navigate to the **Workflows page** -> On the top-right, locate and click on the **Filter** icon.
2. Apply the desired combination of filters by selecting options such as **Event**, **Action**, **Owners**, etc. -> Once you have set your filters, click on the **Apply** button.

<div><figure><img src="/files/NHMfy68jzFdxr41MeTY6" alt=""><figcaption><p>Image. Filter Workflow List</p></figcaption></figure> <figure><img src="/files/XO5DDjyPUfr0vHkvtYww" alt=""><figcaption><p>Image. Add Filter Selections</p></figcaption></figure></div>

Below is a comprehensive list of filters accessible on the Workflows Page:

<table><thead><tr><th width="227">Filter Name</th><th>Description</th></tr></thead><tbody><tr><td><strong>Event</strong></td><td>Allows you to filter Workflows based on Events. They can be Incident Triggered, Incident Acknowledged, Incident Reassigned, and Incident Resolved.</td></tr><tr><td><strong>Actions</strong></td><td>Allows you to filter Workflows based on Actions set up. For instance, Add a Communication Card, and Attach Runbook(s).</td></tr><tr><td><strong>Tags</strong></td><td>Allows you to filter Workflows based on Tags.</td></tr><tr><td><strong>Owner</strong></td><td>Allows you to filter Workflow based on its Owner.</td></tr><tr><td><strong>Created By</strong></td><td>Allows you to filter Workflows based on the user it was created by.</td></tr><tr><td><strong>Updated By</strong></td><td>Allows you to filter Workflows based on the user who updated it.</td></tr><tr><td><strong>Show Enabled</strong></td><td>Allows you to filter Workflows to show only the enabled or disabled ones.</td></tr></tbody></table>

## Clone Workflow

If you need to quickly establish a Workflow that closely resembles an existing one, but with minor modifications, you can expedite the process by cloning it. This allows you to make the necessary adjustments and bring the updated Workflow into operation more swiftly.

To clone a Workflow,

1. Navigate to the **Workflows page** -> Identify the Workflow you wish to clone.
2. On mouse-over, click **Clone**, and you’re done.

<figure><img src="/files/KpZOIYZZrIH8EWsQ0S4b" alt="" width="563"><figcaption><p>Image. Clone a Workflow</p></figcaption></figure>

## Pause Workflow

By default, a newly created workflow is enabled. To pause a workflow,

1. Navigate to the **Workflows page** -> Select **one or more Workflows** from the list.
2. Click **Disable**, and you’re done.

<figure><img src="/files/MGYZxTBHZH9vhnloSScT" alt="" width="563"><figcaption><p>Image. Pause a Workflow</p></figcaption></figure>

Alternatively, you can also use the radio button next to each listed workflow to enable or disable it individually.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Actions

Add a sequence of actions that automatically get executed for your incidents.

Each Workflow has a set of predefined actions that guide how it moves forward. These actions can involve tasks like attaching Runbooks or marking an incident as SLO-affecting.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

* Each action will be executed serially, and all actions executed by a Workflow will be recorded in the Incident timeline.
* The Workflow will continue to run irrespective of the success/failure of a specific action.
  {% endhint %}

## Squadcast Actions

Here are the steps to set up each of the supported Squadcast actions:

{% hint style="info" %}
The below templating variables can be used for almost all actions however they will return values only if the trigger is "When Incident Note is added" otherwise it will be empty.

```mustache
  incident_last_note.note
  incident_last_note.user_name
  incident_last_note.user_email
```

{% endhint %}

### Attach Runbook(s)

To include attaching runbooks as an action,

1. Click on the Squadcast logo under **Select to add action**. -> In the side panel, click on **Attach Runbook(s)**.
2. From the list, search and select one or more runbooks to attach. -> Click on **Attach**.

This process will automatically attach the selected runbook(s) to your incident.

<div><figure><img src="/files/HAVlvjvW2RsF3bVcfiMY" alt=""><figcaption><p>Image. Select to add an action</p></figcaption></figure> <figure><img src="/files/kSfyL5QCSXTXqogADO0e" alt=""><figcaption><p>Image. Attach Runbook(s)</p></figcaption></figure> <figure><img src="/files/xRLiOMv4qSmNsAy46fYy" alt=""><figcaption><p>Image. Select one or more runbook(s) to attach</p></figcaption></figure></div>

### Add Communication Channel

To specify adding a communication channel as an action,

1. Click on the Squadcast logo under **Select to add action**. -> In the side panel, click on **Add Communication Channel**.
2. Choose the type of channel you want to add. -> Input the **link** and *optional* **text to display** for your Communication Channel.
3. You can include multiple communication links -> Lastly, click **Save**.

This action directly adds communication details to your communication card of the Incident.

<div><figure><img src="/files/Hyi0u0T7vDmSBvV6WbZe" alt=""><figcaption><p>Image. Select to add an action</p></figcaption></figure> <figure><img src="/files/qbJ1BOZBVDAG8dblWqQ5" alt=""><figcaption><p>Image. Add Communication Channel</p></figcaption></figure> <figure><img src="/files/aP3KEjz4WXHXKxhEkIuE" alt=""><figcaption><p>Image. Add the communication links</p></figcaption></figure></div>

### Add Incident Note

To include adding an incident note as an action,

1. Click on the **Squadcast logo** under Select to add action -> In the side panel, click on **Add Incident Note.**
2. Type in the note you want to add -> And, click **Save.**

This action automatically adds a note to the incident.

<div><figure><img src="/files/xXCHUlLnQuHHuoHcrxiu" alt=""><figcaption><p>Image. Select to add an action</p></figcaption></figure> <figure><img src="/files/4CrtWWREmBLn6exNOUQa" alt=""><figcaption><p>Image. Add Incident Note</p></figcaption></figure> <figure><img src="/files/ssvXwOuoJuOJB0cyESQE" alt=""><figcaption><p>Image. Type in the note</p></figcaption></figure></div>

### Mark Incident as SLO affecting

To include marking incidents as SLO affecting as an action,

1. Click on the **Squadcast logo** under Select to add action -> In the side panel, click on **Mark Incident as SLO Affecting.**
2. Select an **SLO** from the drop-down -> Select **one or more SLIs** from the other drop-down -> Click **Save**.

This action will automatically mark the incident as SLO-affecting.

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark> When selecting the "Mark Incident as SLO Affecting" action, please ensure that you choose an active SLO that is associated with the same service as your incident.
{% endhint %}

<div><figure><img src="/files/NixhhWgmplgixyxYN8GT" alt=""><figcaption><p>Image. Select to add an action</p></figcaption></figure> <figure><img src="/files/8zfXP3nakDBLHAG6rf65" alt=""><figcaption><p>Image. Mark the Incident as SLO Affecting</p></figcaption></figure> <figure><img src="/files/J3RByVJJIJzmFUdYjlwK" alt=""><figcaption><p>Image. Select the SLO and SLIs</p></figcaption></figure></div>

### Make an HTTP call

To include making an HTTP call as an action,

1. Click on the **Squadcast logo** under Select to add action -> In the side panel, click on **Make an HTTP call.**
2. Enter the **URL** where you want to make the HTTP call -> Select the **HTTP method** from the dropdown. Available methods are GET, POST, PUT, PATCH, and DELETE. The payload will be sent to the URL endpoint that is added.
3. Next, you can configure **additional headers**. These headers will get attached to all the API calls that will be made using this workflow.
4. Then, you can configure your payload. It supports templating variables and string concatenation.\
   \
   Here is the list of supported variables:
   * incident\_status
   * incident\_message
   * incident\_description
   * service\_id
   * service\_name
   * alert\_source\_type
   * alert\_source\_short\_name
   * payload

These variables can be accessed by appending `event.`in beginning. For instance, `event.incident_message`

4. Once you have entered all the details, click **Save**.

This action automatically makes a custom HTTP call when the trigger conditions are met.

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> The success/failure along with the response will be stored in the workflow logs.
{% endhint %}

<div><figure><img src="/files/NixhhWgmplgixyxYN8GT" alt=""><figcaption><p>Image. Select to add an action</p></figcaption></figure> <figure><img src="/files/tWGDHc12Jb2JEcr0S8Hd" alt=""><figcaption><p>Image. Make an HTTP call</p></figcaption></figure> <figure><img src="/files/km2wz0fRJ4JjtmQRUDsj" alt=""><figcaption><p>Image. Enter the details</p></figcaption></figure></div>

### Send an Email

This action automatically sends an email to one or more addresses given when the trigger conditions are met.

To include sending an email as an action,

1. Click on the **Squadcast logo** under Select to add action -> In the side panel, click on **Send an Email.**
2. Type in the following details:
   * Email Address: You can add multiple emails here with a space in the middle.
   * Subject and Body: You can utilize templating variables for the subject and body of the email. Here is the list of the supported templating variables:

     ```
       incident_id
       incident_status
       incident_message
       incident_description
       service_id
       service_name
       alert_source_type
       alert_source_short_name
       payload
     ```

     \
     It will be utilized as such: Message: `{{event.incident_message}}`
3. Once you have entered all the details, click **Save**.

<div><figure><img src="/files/t22BY2vbFTV2pbZo32mR" alt="" width="375"><figcaption><p>Image. Select to add an action</p></figcaption></figure> <figure><img src="/files/UFUdxXqjZhdrd7YYKhoB" alt="" width="375"><figcaption><p>Image. Send an Email</p></figcaption></figure> <figure><img src="/files/Cjvy4ngcTZoCQvEnhTJg" alt="" width="375"><figcaption><p>Image. Enter the details</p></figcaption></figure></div>

### Trigger Manual Webhook

This action automatically triggers the pre-configured manual webhook.

To include triggering a manual webhook as an action,

1. Click on the **Squadcast logo** under Select to add action -> In the side panel, click on **Trigger Manual Webhook.**
2. Next, select the webhook to trigger from the dropdown.
3. Once the webhook is selected, click on **Save**.

<div><figure><img src="/files/ffBaVghlmR77xxXHLh2I" alt="" width="375"><figcaption><p>Image. Select to add an action</p></figcaption></figure> <figure><img src="/files/V8ytMEsmG8sePy6lWPce" alt="" width="375"><figcaption><p>Image. Trigger Manual Webhook</p></figcaption></figure> <figure><img src="/files/pOHJzBXXLt8yOrhG3H7P" alt="" width="375"><figcaption><p>Image. Select the webhook</p></figcaption></figure></div>

### Update Priority

This action automatically updates the priority of an incident.

To include updating priority as an action,

1. Click on the **Squadcast logo** under Select to add action -> In the side panel, click on **Update Priority.**
2. Next, select the priority level from the dropdown.
3. Once done, click on **Save** to complete adding the action.

<div><figure><img src="/files/bt4wQNbeldZagG10FRRr" alt=""><figcaption><p>Image. Add Action</p></figcaption></figure> <figure><img src="/files/933VpjORM3ET8JoHZGRv" alt=""><figcaption><p>Image. Update Priority</p></figcaption></figure></div>

### Add Status Page Issue

This action automatically creates an issue in the StatusPage for the incident.

To create a status page issue,

1. Click on the **Squadcast logo** under Select to add action -> In the side panel, click on **Add Status Page Issue**.
2. Select the status page you want to update -> Enter the **Issue Title** and select the **Page Status** from the drop-down menu.
3. Next, select the **Component and related Impact**. Enter the **Issue Status** and its respective **Message**.
4. Once done, click on **Save** to complete adding the action.

## Slack Actions

Here are the steps to set up each of the supported Slack actions:

### Create Incident-Specific Slack Channel

This action automatically creates a dedicated Slack channel for the incident.

To create an incident-specific Slack channel,

1. Click on the **Slack logo** under Select to add action -> In the side panel, click on **Create Incident-Specific Slack Channel**.
2. Next, select between the two given options.
   1. You can choose to assign an auto-generated name to the Slack channel. The format used here would be `sq-<incident_title>-<last 5 digits of incident id>`
   2. Or you can choose to assign the name in this specific format by entering it in the field below.\
      \
      This option supports templating variables, for the ones shown below:

      ```
        incident_id
        incident_status
        incident_message
        incident_description
        service_id
        service_name
        alert_source_type
        alert_source_short_name
        payload
      ```

      \
      It will be utilized as such: Message: `{{event.incident_message}}`

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> We will utilize only the initial 35 characters from these templates.
{% endhint %}

3. Once done, click on **Save** to complete adding the action.

<div><figure><img src="/files/5j4pHzTdItodfBcWZ6cn" alt=""><figcaption><p>Image. Add Action</p></figcaption></figure> <figure><img src="/files/vNedqXfSSLNU5kCORvx2" alt=""><figcaption><p>Image. Create Slack Channel</p></figcaption></figure></div>

### Archive Incident-Specific Slack Channel

This action automatically archives the dedicated Slack channel for the incident.

To archive an incident-specific Slack channel,

1. Click on the **Slack logo** under Select to add action -> In the side panel, click on **Archive Incident-Specific Slack Channel**.
2. You'll have successfully added the new action.

<div><figure><img src="/files/MM6djFl7ibXn1JRX4baf" alt=""><figcaption><p>Image. Add Action</p></figcaption></figure> <figure><img src="/files/DDCH1YvHPKgqd1mzWJA5" alt=""><figcaption><p>Image. Archive Slack Channel</p></figcaption></figure></div>

### Send a Message to a Specific Slack Channel

This action automatically sends a message to a specific Slack channel.

To send a message to a Slack channel,

1. Click on the **Slack logo** under Select to add action -> In the side panel, click on **Send a Message to Specific Slack Channel.**
2. You can either input the Channel ID or select from the options in the drop-down. You can select only one channel.
3. Enter the **message** you would like to be automatically sent -> Click **Save**.
4. You'll have successfully added the new action.

<div><figure><img src="/files/k3IMCFES9LpR9rZaAluZ" alt=""><figcaption><p>Image. Add Action</p></figcaption></figure> <figure><img src="/files/83HtDwXVRpd8uTVRxqHZ" alt=""><figcaption><p>Image. Send a message to Slack Channel</p></figcaption></figure></div>

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>**:** Kindly note that the bot needs to be manually added to the respective channel in Slack for seamless integration.
{% endhint %}

### Send a Direct Message to a Slack User

This action automatically sends a direct message to a specific Slack user.

To send a message to a Slack user,

1. Click on the **Slack logo** under Select to add action -> In the side panel, click on **Send a Direct message to User.**
2. Select the user from the options in the drop-down. -> Enter the **message** you would like to be automatically sent.
3. Click **Save.** You'll have successfully added the new action.

<div><figure><img src="/files/v3sxhb2EZp9oFnT73cTw" alt=""><figcaption><p>Image. Add Action</p></figcaption></figure> <figure><img src="/files/2zmgoxWkPlxcq8lC7kvw" alt=""><figcaption><p>Image. Send a message to Slack user</p></figcaption></figure></div>

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>: In the context of API/Terraform configuration for the SendMessageToUser action, please specify the MemberID for referencing Slack users.

**Steps to Obtain MemberID:**

1. In Slack, click on your profile icon in the bottom left.
2. Select "Profile."
3. Click on the hamburger icon below your name.
4. Copy the MemberID.
   {% endhint %}

## Jira Actions

### Create a Jira Ticket

This action automatically creates a Jira ticket in Jira Cloud.

To create a ticket in Jira Cloud,

1. Click on the **Jira logo** under Select to add action -> In the side panel, click on **Create a Jira Ticket.**
2. Select the **Jira Account**, **Jira Project**, and **Issue Type** from the options in the drop-down -> Enter the **ticket title** and **message** you would like to be automatically sent.
3. Click **Save.** You'll have successfully added the new action.

This option supports templating variables, for the ones shown below:

```
  incident_id
  incident_status
  incident_message
  incident_description
  service_id
  service_name
  alert_source_type
  alert_source_short_name
  payload
```

It will be utilized as such: Message: `{{event.incident_message}}`

<div><figure><img src="/files/fVGyuG0hhreiETpGNue3" alt=""><figcaption><p>Image. Add action</p></figcaption></figure> <figure><img src="/files/b4OOJ4BVnEE0QIC19w2p" alt=""><figcaption><p>Image. Create Jira Ticket</p></figcaption></figure></div>

## MS Teams Actions

### Send a message to a Microsoft Teams Channel

This action automatically sends a direct message to a specific Microsoft Teams channel.

To send a message on Microsoft Teams,

1. Click on the **Microsoft Teams logo** under Select to add action -> In the side panel, click on **Send a message to a specific Microsoft Teams Channel.**
2. Select the **channel** from the options in the drop-down -> Enter the **message** you would like to be automatically sent.
3. Click **Save.** You'll have successfully added the new action.

This option supports templating variables, for the ones shown below:

```
  incident_id
  incident_status
  incident_message
  incident_description
  service_id
  service_name
  alert_source_type
  alert_source_short_name
  payload
```

It will be utilized as such: Message: `{{event.incident_message}}`

### Send a message to specific Microsoft Teams User

This action automatically sends a direct message to a specific Microsoft Teams user.

To send a message on Microsoft Teams,

1. Click on the **Microsoft Teams logo** under Select to add action -> In the side panel, click on **Send a message to a specific Microsoft Teams User.**
2. Select the **user name** from the options in the drop-down -> Enter the **message** you would like to be automatically sent.
3. Click **Save.** You'll have successfully added the new action.

This option supports templating variables, for the ones shown below:

```
  incident_id
  incident_status
  incident_message
  incident_description
  service_id
  service_name
  alert_source_type
  alert_source_short_name
  payload
```

It will be utilized as such: Message: `{{event.incident_message}}`

\\

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Live Call Routing

Live Call Routing enables routing incoming calls and voicemails to on-call responders.

Live Call Routing enables end users and internal employees to dial a number and report incidents or leave voicemails for the issues they are experiencing. These calls or voicemails are routed directly to on-call engineers for prompt remediation of reported issues.

The direct channel established between end users and on-call engineers simplifies the process of reporting issues. Depending on the severity or frequency of reported issues, on-call engineers can triage and ensure quick resolutions, thus ensuring that the Mean Time to Resolve (MTTR) for customer-reported issues is always in check.

{% hint style="info" %} <mark style="color:blue;">**We support the provision of both local and toll-free numbers for the following regions:**</mark>

* **United States of America, Canada, United Kingdom**: Easily provision local and toll-free numbers through Squadcast.
* **India**: Reach out to Squadcast support to obtain local and toll-free numbers.

For countries that you do not see in the selector drop-down, reach out to our Sales or Support teams for assistance.
{% endhint %}

## **Prerequisites**

{% hint style="warning" %} <mark style="color:orange;">**Important:**</mark>

* Live Call Routing is available as an add-on package for accounts on the [Enterprise plan](https://www.squadcast.com/pricing).
* Please reach out to your Squadcast point of contact or to <support@squadcast.com> to get the add-on package activated for your account to start using the feature.
  {% endhint %}

## Add a New Routing Number <a href="#add-a-new-routing-number" id="add-a-new-routing-number"></a>

To begin the setup process by adding an incoming Routing Number,

1. Navigate to the **Live Call Routing** page on the left navigation -> **Add New Routing Number.**
2. Enter the **Name**, and *optional* **Description**, and select an **Owner** for this number.
3. Select the **Country** for which you would like to have this number.
4. Select the type of number you want. The number can either be a **Local** number or a **Toll-free** number.

<figure><img src="/files/Yht7GwzlOr7iJjPGt3cc" alt="" width="563"><figcaption><p>Image. Configure a new Routing Number</p></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark> If you encounter any error in generating the number, please reach out to <support@squadcast.com>
{% endhint %}

5. Then click **Generate Number.**
6. Select the behaviour of the routing number:
   1. Play greeting and go to voicemail. Send the voicemail recording to the current on-call responder(s).
      1. The caller can leave out a voicemail after selecting the affected service and the voicemail will then be attached to the incident created.
   2. Play greeting and call the current on-call responder.

      1. When the caller places the call and selects the service, Squadcast will route the call to the current on-call person(s) in the schedule attached to the Service. Once the on-call person picks up the call, the caller can report the issue to the on-call person.
      2. When routing calls to on-call engineers, you can choose between two available strategies:\
         **Simultaneous** - Calls all on-call responders at the same time. Each on-call responder receives a call and is prompted: *“You have an incoming call from SolarWinds Incident Response. Press 1 to accept.”* The first responder to press 1 gets connected to the caller. If no one answers or an on-call responder has voicemail enabled, the call will wait and ultimately go to the fallback voicemail. This strategy is useful when faster response times are critical. *This is the default option.*\
         **Sequential** - Calls on-call responders one after another, in order. Each on-call responder receives a call and is prompted: *“You have an incoming call from SolarWinds Incident Response. Press 1 to accept.”* Once they press 1, they get connected to the caller. If the on-call responder does not answer or has voicemail enabled, the call will wait and then move on to the next on-call responder in the rotation. If no on-call responder answers, the call goes to the fallback voicemail. This option will help you for call rollovers when engineers do not respond in time.

      <figure><img src="/files/LIRZIBReeK7dJ02d5xg0" alt=""><figcaption></figcaption></figure>

{% hint style="info" %} <mark style="color:$tint;">**Note:**</mark>&#x20;

1. The above options are available only when the **Preferred Flow of Call** is set to **Play greeting and call the current on-call responder**.
2. If **Simultaneous** is selected: An incident will be created for the reported issue. The incident goes to the Acknowledged state and is assigned to the on-call responder who received the incoming call.
   1. If multiple responders are on-call, Squadcast will try to connect the call to 10 people (max), and the first of these responders to answer the call will be connected with the caller, and the rest of the connection attempts will be canceled.
   2. If no on-call responders pick up the incoming call, the call then goes to voicemail. The voicemail will then be attached to the created incident.
      {% endhint %}

<figure><img src="/files/ALROIyHyElnHP6VORo9d" alt="" width="563"><figcaption><p>Image. Setup the LCR configuration</p></figcaption></figure>

7. Select the total duration of the call. The call will automatically disconnect after this specified time limit.
8. Craft your greeting message for callers in the text field. This message will be converted from text to speech and will be the first thing callers hear when they dial the number.
9. Structure the message to be read out during the call. This text will also be converted to speech and will play after each key press during the call.
10. Configure the Map Keypad:
    * For each key, a map
      1. A Service
      2. Provide an alias name for the selected Service
      3. Attach Schedules
11. Click **Save**.

<figure><img src="/files/EKPvjXxY2ilsfLVcoM0s" alt="" width="563"><figcaption><p>Image. Save the configuration details</p></figcaption></figure>

That’s it, now you have set up your Routing Number. We recommend testing this number out internally before putting it out for your end users to call.

### Edit a Configured Routing Number <a href="#edit-a-routing-number-config" id="edit-a-routing-number-config"></a>

To edit a configuration for an existing Routing Number,

1. Navigate to the **Live Call Routing** page, hover over the desired configuration, and click **Edit**.
2. Make your changes and then click **Save**.

<div><figure><img src="/files/6Johnio9rdgmOrPMe55m" alt=""><figcaption><p>Image. Edit a configured Routing Number</p></figcaption></figure> <figure><img src="/files/eLwtvVannaf3ATxd2JdJ" alt=""><figcaption><p>Image. Edit the details</p></figcaption></figure></div>

{% hint style="info" %} <mark style="color:$tint;">**Note:**</mark> Please note that you cannot edit the Routing Number, country, or number type. To use a new number, you must add a new Routing Number.
{% endhint %}

## Delete a Routing Number <a href="#delete-a-routing-number" id="delete-a-routing-number"></a>

To delete a Routing Number,

1. Navigate to the **Live Call Routing** page, hover over the number you wish to remove, and click on the **Delete** option.
2. Confirm the deletion in the pop-up confirmation dialog to complete the process.

<div><figure><img src="/files/cNpCkxrq1ygWPzlKZzkk" alt=""><figcaption><p>Image. Delete a Routing Number</p></figcaption></figure> <figure><img src="/files/Vc8nVxWbrtDp0FABp1KU" alt=""><figcaption><p>Image. Confirm Deletion</p></figcaption></figure></div>

## Sessions

In the Sessions section, you can view all the sessions associated with a routing number along with their respective details, as listed in the table below. To access this information for a specific routing number, simply open the Routing number details page and navigate to the Sessions section.

<table><thead><tr><th width="249">Field</th><th>Description</th></tr></thead><tbody><tr><td>Caller ID</td><td>The number from the call is indicated.</td></tr><tr><td>Incident ID</td><td>The Incident ID of the incident created for the call.</td></tr><tr><td>Recording</td><td>The recording associated with the call.</td></tr><tr><td>Assigned To</td><td>To whom the incident got assigned to.</td></tr><tr><td>Selected Service</td><td>The selected service by the caller during the call.</td></tr><tr><td>Duration</td><td>Total duration of the call. From the user initiating it to the end.</td></tr></tbody></table>

To view further details about a session, hover on a session, click on View Session.

Here you can view the session details and to whom the call was routed to.

## FAQs <a href="#faqs" id="faqs"></a>

<details>

<summary><strong>What happens if I send an SMS to the routing number?</strong></summary>

Sending an SMS to a routing number is not supported. Text messages sent to a Live Call Routing number will not initiate an incident or be directed to the on-call responder.

</details>

<details>

<summary><strong>How many routing numbers can I create?</strong></summary>

You can create a maximum of 5 routing numbers in your organization.

</details>

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Analytics

Analytics for measuring your Team's performance

{% embed url="<https://www.youtube.com/watch?feature=youtu.be&v=gSow6ih-TNs>" %}

The **Analytics Dashboard** helps you analyze the performance of your Organization/ Team, for a given time period.

{% hint style="info" %}
**Note:**

Only users with [<mark style="color:blue;">Org Level Permission</mark>](/manage-users/user-permissions-access-controls) can view Organization Analytics.
{% endhint %}

### Team Level Analytics <a href="#team-level-analytics" id="team-level-analytics"></a>

{% hint style="info" %}
**Note:**

Team Level Analytics uses Role-Based Access Control. Only the users who are part of the Team can view that Team’s performance.
{% endhint %}

Select the appropriate **Team** from the Team Picker on the top left.

1. Click on **Analytics** in the sidebar
2. By default, the selected time range is the **last 30 days**

You can select a custom time range using the utility on the top right corner of the page, to select and apply a time range for Analytics data consumption.

<figure><img src="/files/hvnq29FPPfD9genTEpk0" alt="Analytics - Incident Management using Squadcast" width="563"><figcaption></figcaption></figure>

In Team Analytics, you can see many components:

| Component                               | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| --------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Incidents                               | Total incidents of the team                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| MTTA                                    | Mean Time To Acknowledge shows how quickly your team is able to respond to an incident. This is calculated by their time to Acknowledge an incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| MTTR                                    | Mean Time To Resolve shows how quickly your team is able to resolve incidents as they arise. This is calculated by their time to Resolve an incident                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| MTTA & MTTR over time                   | <p>The image here shows the MTTA & MTTR over time for applied filters i.e Service: API and Tag: Alert type: Anomaly</p><p><img src="/files/zfFUbte8jrLjYhEDuctC" alt="MTTA &#x26; MTTR over time"><br><br><mark style="color:red;"><code>Note</code></mark>: You can compare multiple services on the MTTA/MTTR over time graph of Team Analytics.<br><br>Click <strong>Compare</strong> -> Add multiple comparison data sets. They should all be within the same team and always contain a service -> Click <strong>Done</strong>.<br><br>You can download this graph in .csv format.</p><p><img src="/files/oToTnW3NfY3HaXU8wz3G" alt="Export the MTTA &#x26; MTTR over time graph"><br></p><p><mark style="color:red;"><code>Important</code></mark>: You can add up to 5 comparison data sets. And, on applying a global filter on the page, your chosen comparison data sets will be removed.</p> |
| Open Incidents by Service               | Service-wise mention of the total number of open incidents (Triggered & Acknowledged)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Open Incidents by Users                 | User-wise mention of total number of open incidents                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Deduplicated Incidents by Service       | Service-wise mention of total number of deduplicated incidents                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Deduplicated Incidents by Alert Sources | Alert Source specific split of total number of deduplicated incidents                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Suppressed Incidents by Service         | Service-wise split of total number of suppressed incidents                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Suppressed Incidents Alert Sources      | Alert Source specific split of total number of suppressed incidents                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Reassigned Incidents by Team            | Team-wise split of total number of reassigned incidents                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |

{% hint style="info" %}
**Note:**

You can filter Team Analytics based on Services, Tags and Users. Click on **+Add Filter** -> Select the Service, Tag or User -> Click on **Close**

<img src="/files/rBOlbY3XTvArG8jejpIl" alt="How to filter Team Analytics based on Services, Tags and Users" data-size="original">
{% endhint %}

{% hint style="info" %}
**Note:**

You can export .csv files for each graph. To do so, use the download icon on the top right of each graph.

<img src="/files/c0XYjLdwDBokiKfOg8y4" alt="Export the graphs" data-size="original">
{% endhint %}

### Organization Level Analytics <a href="#organization-level-analytics" id="organization-level-analytics"></a>

{% hint style="info" %}
**Note:**

To view the Organization Level Analytics, you need to have the Org Level Analytics Permission.
{% endhint %}

A user with Org Level Analytics can view the performance of the entire Organization, irrespective of whether you’re a part of a specific team. Organization Analytics Permission gives you the ability to access analytics for all the teams as a collective, but not individual team analytics for the teams they are not a part of.

To view Organization Level Analytics, select the appropriate Organization from the top left corner of your screen.

1. Click on **Analytics** in the sidebar
2. By default, the selected time range is the **last 30 days**

You can select a custom time range using the utility on the top right corner of the page, to select and apply a time range for Analytics data consumption.

In Organization Analytics, you can see many components:

| Component                      | Description                                                                                                                                                                       |
| ------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Incidents                      | Total incident count of the Organization                                                                                                                                          |
| MTTA                           | Mean Time to Acknowledge shows the average amount of time between a system alert and a team member acknowledging it, for the entire Organization, over a specified period of time |
| MTTR                           | Mean Time to Resolution shows the average amount of time it takes to respond to or resolve an incident, for the entire Organization, over a specified period of time              |
| MTTA & MTTR over time          | ![MTTA & MTTR over time](/files/QJTbwfkGyWBfw1V5kkjs)                                                                                                                             |
| Open Incidents by Team         | Team-wise split of the total number of open incidents                                                                                                                             |
| Deduplicated Incidents by Team | Team-wise split of the total number of deduplicated incidents                                                                                                                     |
| Suppressed Incidents by Team   | Team-wise split of the total number of suppressed incidents                                                                                                                       |

{% hint style="info" %}
**Note:**

You cannot filter Organization Analytics based on teams, you need access to a team, to view their performance data.
{% endhint %}

{% hint style="info" %}
**Note:**

You can export .csv files for each graph. To do so, use the download icon on the top right of each graph.

<img src="/files/Ilib1Wssft9YBItKZmo7" alt="Export the graph in .csv format" data-size="original">
{% endhint %}

### FAQs <a href="#faqs" id="faqs"></a>

#### Please refer to the Frequently Asked Questions below that might help you fix any issues/answer your queries. <a href="#please-refer-to-the-frequently-asked-questions-below-that-might-help-you-fix-any-issuesanswer-your-q" id="please-refer-to-the-frequently-asked-questions-below-that-might-help-you-fix-any-issuesanswer-your-q"></a>

**1. What permission do I need to view Organization Analytics?**

You need to have the [Organization Analytics Permission](/manage-users/user-permissions-access-controls) to view the Organization Analytics Dashboard.

**2. Can I view any Team’s performance if I have the Organization Analytics permission?**

Organization Analytics Permission gives you the ability to access analytics for all the teams as a collective, but not individual team analytics for the teams they are not a part of.

**3. Can I select Service, Tags and Users together to filter out Team’s performance?**

Yes, you can select one of each, Services, Tags and Users together to filter out Team’s performance.

**4. Do I need to be a part of the Team to view their Team Analytics Dashboard?**

Yes, you need to be a part of a Team to view their individual Team Analytics Dashboard.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Analytics (New)

Analytics for measuring your Team's performance

{% hint style="info" %}
**Availability:**

Analytics is available on all plans with the following plan-specific features:

1. Data Retention: Access to historical data varies by plan. [Learn more](#data-retention).
2. Custom Aggregation (choose aggregation method like Mean, Median, etc.): Available on **Premium and Enterprise** plans. [Learn more](#custom-aggregation-xtta-and-xttr).
3. Transient Alert Metrics: Available exclusively on the **Enterprise** plan.
4. Saved Filters: Available on **Premium and Enterprise** plans. [Learn more](#saved-filters).
   {% endhint %}

{% hint style="info" %}
**Access Control:**

* **RBAC (Role-Based Access Control):** Users with "read analytics" permission can access team-level analytics for that specific team.
* **OBAC (Owner-Based Access Control):** All users in a team can access team-level analytics for that team.
  {% endhint %}

{% hint style="info" %}
**Scope:**

This page covers team level analytics. For organization level analytics, refer [here](/analytics/organization-level-analytics).
{% endhint %}

## Data Retention

* Enterprise Plan: Data retained for 2 years. You can filter up to 1 year of data at a time.
* Premium Plan: Data retained for 1 year.
* Pro Plan: Data retained for 6 months.
* Free Plan: Data retained for 3 months.

## Filters

The following filter fields are available:

* Current Assignee
* Service
* Service Owner
* Tags
* Priority
* Date

### Service Owner

Use this filter to view analytics for services owned by specific users or squads.

**Example:** Filter analytics to show only incidents for services owned by "Ops Squad," giving you insights into the performance of Ops Squad.

## Incident Overview

The Incident Overview section provides a summary of all incidents, including key details such as status, priority, and service impact. It offers a high-level view of incident trends and performance across your services.

| Chart Title                | Description                                                                                                                                                                                                                                                      | Screenshot                       |
| -------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------- |
| Incidents                  | Total count of incidents with a comparison with the previous time period                                                                                                                                                                                         |                                  |
| Incident Count by Status   | Total count of incidents, grouped by status                                                                                                                                                                                                                      | ![](/files/ILibWyQBAlCfDcvSNgTI) |
| Incident Count by Priority | Total count of incidents, grouped by priority                                                                                                                                                                                                                    | ![](/files/FiV9pbJzL71DDKdSyer2) |
| Incident Count Over Time   | <p>Total count of incidents, grouped by date of creation<br><br>You can further group this chart by status or priority</p>                                                                                                                                       | ![](/files/9RWolHzHJqYXUYy9VxMR) |
| Incident Count by Assignee | <p>Total count of incidents, grouped by Assignee (excluding Escalation Policies)<br><br>The top 10 assignees by incident count is displayed by default. To view the count of incidents for each assignee, you can export this chart as a CSV</p>                 | ![](/files/dF67rynR9nXHmnFtU5Nd) |
| Incident Count by Service  | <p>Total count of incidents, grouped by Service</p><p>You can further group this chart by priority<br><br>The top 10 services by incident count is displayed by default. To view the count of incidents for each service, you can export this chart as a CSV</p> | ![](/files/5fz5IMOz67QVA3q3FoOM) |

{% hint style="info" %}
**Note:** Incidents in the suppressed status are excluded from Incident overview
{% endhint %}

## Response Metrics

The Response Metrics section provides key insights into your team's performance, focusing on Mean Time to Acknowledge (MTTA) and Mean Time to Resolve (MTTR) metrics. It helps track the efficiency of incident response and resolution over time.

### Metrics

#### MTTA

Mean of TTA (Time to Acknowledge) for each incident under the applied filters.\
\
The following incidents are excluded from this calculation:

• Incidents that are in the triggered status\
• Incidents that weren't never acknowledged. These are incidents that were directly resolved after being triggered. Example: Auto-resolved incidents\
\
If there are multiple acknowledgements for an incident, we consider the TTA of the latest acknowledgement.

#### MTTR

Mean of TTR (Time to Resolve) for each incident under the applied filters.

Only incidents in the resolved status are included in this calculation

### Custom Aggregation: xTTA and xTTR

In addition to mean, you can aggregate TTA (Time to Acknowledge) and TTR (Time to Resolve) by:

* Median
* 75th percentile
* 90th percentile
* 99th percentile

Your selection will apply to all charts in the Response Metrics section

xTTA (or xTTR) refers to the method of aggregation applied to TTA and TTR metrics. "x" can represent Mean, Median, P75, P90, P99 depending on the selected option.

{% hint style="info" %}
**Note:** Custom aggregation is available on Premium and Enterprise plans. Users on Pro and Free plans can aggregate by mean only.
{% endhint %}

### Charts

| Chart Title                | Description                                                                                                                                             | Screenshot                       |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------- |
| MTTA (or xTTA)             | MTTA (or xTTA) for the current team with a comparison with the previous time period                                                                     | ![](/files/WQUqOcYdc4DPFIqvJxXU) |
| MTTR (or xTTR)             | MTTR (or xTTR) for the current team with a comparison with the previous time period                                                                     | ![](/files/L9GPsyA1bEs0kQOSnErN) |
| MTTA (or xTTA) over Time   | MTTA (or xTTA) grouped by date of incident creation                                                                                                     | ![](/files/JAfGGmqxDntVICDCvuQE) |
| MTTR (or xTTR) over Time   | MTTR (or xTTR) grouped by date of incident creation                                                                                                     | ![](/files/5X6zxOOiNqZA4te8PLGp) |
| MTTA (or xTTA) by Priority | MTTA (or xTTA) grouped by incident Priority                                                                                                             | ![](/files/bjFEiXHr6ZG1b0Z4sKZ7) |
| MTTR (or xTTR) by Priority | MTTR (or xTTR) grouped by incident priority                                                                                                             | ![](/files/hGAuvnpJWf6JZWm3OX8Y) |
| MTTA (or xTTA) by Service  | <p>MTTA (or xTTA) grouped by Service<br><br>The top 10 services by xTTA are shown by default. You can export the chart to see xTTA for all services</p> | ![](/files/hA7n9lvRSnwMAUUeTGrr) |
| MTTR (or xTTR) by Service  | <p>MTTR (or xTTR) grouped by Service<br><br>The top 10 services by xTTR are shown by default. You can export the chart to see xTTA for all services</p> | ![](/files/f1jzipvq9iOWMrDm4hHH) |

## Alert Noise Reduction

The alert noise reduction section shows how alert noise for each of your services was silenced. Notifications are not sent for these silenced alerts.

### Count of Silenced Alerts

Count of silenced alerts

\=

count of transient alerts identified using [Auto Pause Transient Alerts (APTA)](/services/auto-pause-transient-alerts-apta)

\+ count of alerts suppressed using alert [Suppression Rules](/services/alert-suppression)

\+ count of alerts deduplicated using [Key Based Deduplication](/services/alert-deduplication-rules/key-based-deduplication) or [Dedupe Rules](/services/alert-deduplication-rules/alert-deduplication-rules)

\+ count of alerts grouped using [Intelligent Alert Grouping (IAG)](/services/intelligent-alert-grouping-iag)

{% hint style="info" %}
Note: This chart shows data across all services under applied filters
{% endhint %}

### Noise Reduction by Service

<figure><img src="/files/Lkm75x9Lrb9bOkWSiZXT" alt=""><figcaption></figcaption></figure>

| Metric                | Description                                                                             |
| --------------------- | --------------------------------------------------------------------------------------- |
| Transient             | Count of transient alerts for the chosen service identified using APTA                  |
| Intelligently Grouped | Count of alerts for the service that were grouped using Intelligent Alert Grouping      |
| Deduplicated          | Count of alerts for the service that were deduped using Dedupe Keys or Dedupe Rules     |
| Suppressed            | Count of alerts for the service suppressed using Suppression Rules                      |
| Noise Reduction %     | (Count of silenced alerts for the service) ÷ (Count of incoming alerts for the service) |

### Transient Alert Metrics

<figure><img src="/files/vGqjTYNiYl6lgYHOVH0X" alt=""><figcaption></figcaption></figure>

| Metric                  | Description                                                                                                                                                                                                                             |
| ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Total Incidents         | Total count of alerts for the chosen service                                                                                                                                                                                            |
| Marked as Transient     | Count of alerts for the service that were marked as transient and suppressed using APTA                                                                                                                                                 |
| Transient               | <p>Count of alerts for the servicethat were correctly identified as transient. These incidents were auto-resolved within the APTA timeout window for the service</p><p><br></p><p>This is a subset of incidents marked as transient</p> |
| Breached Timeout Window | <p>Count of alerts for the service that breached the timeout window and were re-triggered after being marked as transient</p><p><br></p><p>This is a subset of incidents marked as transient</p>                                        |
| Non-Transient Alerts    | These are alerts for the service that weren’t marked as transient                                                                                                                                                                       |

## Export

Each chart can be exported as a CSV file.

## Saved Filters

Saved Filters lets you save your frequently used filter combinations as named views, so you don't have to manually re-apply them each time.

**Example:** The Notifications team can create a saved view with `{Service = Notifications, SMS; Priority = P1, P2; Time = Last 7 days}` and access it instantly on every visit.

{% hint style="info" %}

**Availability:** Saved Filters is available on the following plans:

* **Free & Pro:** Not available.
* **Premium:** Available. Save for Me views are unlimited. Save for Team views are limited to 50.
* **Enterprise:** Available. Save for Me and Save for Team views are both unlimited.
  {% endhint %}

### Creating a Saved Filter

<figure><img src="/files/x5cpfitGRJO0eaDQI3cC" alt="" width="375"><figcaption></figcaption></figure>

<figure><img src="/files/eUb4KVJoavF9YV9Hs3wQ" alt="" width="375"><figcaption></figcaption></figure>

1. Apply the filters you want to save using the filter bar in Analytics
2. Click **Save Filter**
3. Enter a name for the view
4. Choose the scope:
   * **Save for Me** – Only you can view and modify this saved filter
   * **Save for Team** – Any member of your team can view and modify this saved filter
5. Click **Save**

### Sharing a Saved Filter

Every saved filter has a unique URL. You can copy and share this URL with teammates to give them direct access to the view.

**Note:** Teammates accessing a shared URL will only see the saved filter if it is scoped to **Save for Team**, or if they are the creator of a **Save for Me** filter.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Organization Level Analytics

Organization Level Analytics provides a comprehensive view of incidents, response metrics, and alert noise reduction across all teams within your organization.

{% hint style="info" %}
**Note:** Users with the ‘Org Analytics’ organization permission can view organization level analytics
{% endhint %}

## Incident Overview

| Chart Title                | Description                                                                                                                                                                                                  | Screenshot                       |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------- |
| Incidents                  | Total count of incidents across all teams with a comparison with the previous time period                                                                                                                    | ![](/files/tCOcE3d0xpRvoe7bqaUl) |
| Incident Count by Status   | Total count of incidents across all teams, grouped by status                                                                                                                                                 | ![](/files/ILibWyQBAlCfDcvSNgTI) |
| Incident Count by Priority | Total count of incidents across all teams, grouped by priority                                                                                                                                               | ![](/files/FiV9pbJzL71DDKdSyer2) |
| Incident Count Over Time   | <p>Total count of incidents across all teams, grouped by date of creation<br><br>You can further group this chart by status or priority</p>                                                                  | ![](/files/9RWolHzHJqYXUYy9VxMR) |
| Incident Count by Team     | <p>Total count of incidents across all teams, grouped by Team<br><br>The top 10 teams by incident count is displayed by default. To view the count of incidents for each team, you can export this chart</p> | ![](/files/0BEgzDNFi75EBuhvPD2u) |

## Response Metrics

{% hint style="info" %}
Note: Like with team level analytics, you can aggregate TTA and TTR by mean, median, P75, P90, and P99
{% endhint %}

| Chart Title              | Description                                                                     | Screenshot                       |
| ------------------------ | ------------------------------------------------------------------------------- | -------------------------------- |
| MTTA (or xTTA)           | MTTA (or xTTA) across all teams with a comparison with the previous time period | ![](/files/WQUqOcYdc4DPFIqvJxXU) |
| MTTR (or xTTR)           | MTTR (or xTTR) across all teams with a comparison with the previous time period | ![](/files/L9GPsyA1bEs0kQOSnErN) |
| MTTA (or xTTA) over Time | MTTA (or xTTA) across all teams, grouped by date of incident creation           | ![](/files/JAfGGmqxDntVICDCvuQE) |
| MTTR (or xTTR) over Time | MTTR (or xTTR) across all teams, grouped by date of incident creation           | ![](/files/5X6zxOOiNqZA4te8PLGp) |

## Alert Noise Reduction

### Count of Silenced Alerts

Count of silenced alerts

\=

count of transient alerts identified using Auto Pause Transient Alerts (APTA)

\+ count of alerts suppressed using alert suppression rules

\+ count of alerts deduplicated using dedupe keys or dedupe rules

\+ count of alerts grouped using Intelligent Alert Grouping (IAG)

{% hint style="info" %}
Note: This chart shows data across all teams in your org
{% endhint %}

### Noise Reduction by Team

<figure><img src="/files/SwZQTXrr17TOPu2YSftC" alt=""><figcaption></figcaption></figure>

| Metric                | Description                                                                       |
| --------------------- | --------------------------------------------------------------------------------- |
| Transient             | Count of transient alerts for the chosen team identified using APTA               |
| Intelligently Grouped | Count of alerts for the team that were grouped using Intelligent Alert Grouping   |
| Deduplicated          | Count of alerts for the team that were deduped using Dedupe Keys or Dedupe Rules  |
| Suppressed            | Count of alerts for the team suppressed using Suppression Rules                   |
| Noise Reduction %     | (Count of silenced alerts for the team) ÷ (Count of incoming alerts for the team) |

## Export

Each chart can be exported as a CSV file.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# On Call Hours Per User

Analytics for measuring your Team's performance

{% hint style="info" %}
**Availability**

On Call Hours Per User is available on **Pro, Premium, and Enterprise** plans
{% endhint %}

{% hint style="info" %}
**Access Control:**

On Call Hours per User is available at a team level

* **RBAC (Role-Based Access Control):** Users with "read analytics" permission can access team-level analytics for that specific team.
* **OBAC (Owner-Based Access Control):** All users in a team can access team-level analytics for that team.
  {% endhint %}

## Data Retention

Data is retained for 6 months. You can filter upto 31 days of data at a time

## Understanding the chart

<figure><img src="/files/YqWmJogW5e3BB6aYpcCD" alt=""><figcaption></figcaption></figure>

* On Call Hours: The total number of hours a user has been on call as part of their regular schedule rotations, under applied filters. This calculation accounts for any overlapping time across multiple rotations and schedules to avoid double-counting.
* Override Hours: The total number of hours a user has been on call as part of overrides, under applied filters. This calculation accounts for any overlapping time across multiple overrides to avoid double-counting.

### Filters

The following filter fields are available

* Schedule
* Schedule Owner

{% hint style="info" %}
When filters are applied, **on-call hours** and **override hours** are recalculated for each user based on the selected schedules.

To view on-call hours across *all* schedules, make sure no filters are applied.
{% endhint %}

#### **Schedule Owner**

Use the Schedule Owner filter to view on-call hours for schedules managed by specific users or squads.

**Example:** Filter analytics to show the number of hours each user spent on schedules owned by the *Ops Squad*.

#### Saved Filters

Filters can be saved for quick reuse - [learn more about saved filters](/analytics/analytics-new#saved-filters).

## Export

You can export the On-Call Hours per User chart as a CSV file. Once requested, the export will be generated and sent to your email.

## API

The On-Call Hours per User data can also be accessed via API. Refer to the [API documentation](https://apidocs.squadcast.com/#ceb600b4-cb9d-4455-b039-6c0eb73aa206)

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Weekly Reports

Bird’s eye view of activity from the past week

Squadcast sends weekly reports every Monday at 9 AM UTC, by email. These reports contain a summary of your teams’ Squadcast activity over the last week.

<figure><img src="/files/6gmAuxOIjD5WEBR4vYC8" alt="" width="375"><figcaption></figcaption></figure>

You can opt in for weekly reports by enabling the ‘Receive Weekly Team Stats’ setting in your user profile.

<figure><img src="/files/Fa4KFXKoAI3wwpQNZgnq" alt="" width="563"><figcaption></figcaption></figure>

You will receive one email for each team you’re part of.

{% hint style="info" %}
This feature is available for accounts in Premium and Enterprise plans.
{% endhint %}

\\


# Incident Webhook (Incident Webhook/API)

Send events to create incidents in Squadcast using Incident Webhook (generic incoming Webhook)

This document will help you configure Incident Webhook to route alerts from monitoring tools or your internal (bespoke) systems into Squadcast. Incident Webhook can do both, trigger and resolve incidents in Squadcast, through HTTP POST requests.

Route detailed monitoring alerts coming in via Incident Webhook to the right users in Squadcast.

{% hint style="info" %}
**Note:**

We also support outgoing webhooks. You can find detailed information on how to configure them [<mark style="color:blue;">here</mark>](/integrations/outgoing-webhooks).
{% endhint %}

## How to configure Incident Webhook <a href="#how-to-configure-incident-webhook" id="how-to-configure-incident-webhook"></a>

### In Squadcast: Using Incident Webhook as an Alert Source <a href="#in-squadcast-using-incident-webhook-as-an-alert-source" id="in-squadcast-using-incident-webhook-as-an-alert-source"></a>

1. From the navigation bar on the left, select **Services**. Pick the applicable **Team** from the Team-picker on the top. Next, click on **Alert Sources** for the applicable Service

<figure><img src="/files/fSVdwTYvtIuFnBYn4fkh" alt="configuration Incident Webhook as an Alert Source" width="563"><figcaption></figcaption></figure>

2. Search for **Incident Webhook** from the Alert Source drop-down and copy the Webhook URL. Use this Webhook URL endpoint to send <mark style="color:red;">`HTTP POST`</mark> requests

![Selection of Incident Webhook from the Alert Source](/files/65lkslQeKw8Zc8rw6hG6)

{% hint style="warning" %} <mark style="color:orange;">**Important**</mark>**:**

For an Alert Source to turn active (indicated by a **green dot - Receiving alerts** against the name of the Alert Source in the drop-down), you can either generate a test alert or wait for a real-time alert to be generated by the Alert Source.

An Alert Source is active if there is a recorded incident via that Alert Source for the Service in the last 30 days.
{% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Add header before making POST request**</mark>

Ensure that you add a header <mark style="color:red;">`Content-Type`</mark> with value `application/json` while making the <mark style="color:red;">HTTP POST</mark> request
{% endhint %}

The body of the POST request should contain the details of your incident in the following format:

```
{
  "message": "This will be the incident message",
  "description": "This will be the incident description",
  "tags" : {
    "tagname1":"Tag value#1",
     "tagname2":"Tag value#2",
     "tagname3": {
       "color": "Valid HTML HEX Colour Notation goes here",
       "value":"Tag value#3"
     }
  },
  "priority": "P5",
  "status": "trigger",
  "event_id": "6"
}
```

{% hint style="info" %} <mark style="color:blue;">**Information on certain fields within the JSON**</mark>

Kindly note that the **message** and **description** fields in the JSON are no longer mandatory to trigger an incident in Squadcast. You can enrich your incidents by adding other details optionally, in the same format as seen above in the example JSON.&#x20;

If the **message** field is missing, the default message template of "Generic Webhook Alert" will be used automatically.

If the **status** field is missing, Squadcast will automatically default the status field to "Triggered" which would treat the incoming payload as a trigger event.

By default, incidents are triggered with an initial status. However, to resolve an incident, you must explicitly send a status update indicating that it has been resolved.
{% endhint %}

{% hint style="warning" %} <mark style="color:orange;">**Important information for Event\_ID**</mark>

* Each incident requires a unique Event ID to be entered by the user. When resolving a specific incident, you must specify the corresponding unique Event ID. In the event of multiple incidents associated with the same Event ID, resolving one incident will result in the resolution of all incidents linked to that specific Event ID.
* If you do not provide an Event ID, any previous incidents without an Event ID will be automatically marked as resolved.
* The Event ID is an optional field and should not be confused with the Incident ID. They serve different purposes.
* While the Event ID is not mandatory, we strongly recommend including it to prevent the automatic resolution of triggered incidents without an Event ID. Adding the Event ID ensures that all incidents without an assigned Event ID are not auto-resolved.
  {% endhint %}

{% hint style="info" %} <mark style="color:blue;">**Note:**</mark>

1. Allowed values for priority are `P1`, `P2`, `P3`, `P4`, and `P5`.
2. If a value other than the allowed ones or no value is passed, Squadcast will have the priority level as `Unset`. Users can manually edit the priority via the web or the mobile app.
   {% endhint %}

{% hint style="danger" %} <mark style="color:red;">**Payload Size Limitation**</mark>\
The payload size is limited to 30KB. Any payload that crosses this limit will not be processed.\
You will receive \[HTTP Status Code 413]\(<https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/413>) to notify you of this.
{% endhint %}

### Event Identification and Resolution <a href="#event-identification-and-resolution" id="event-identification-and-resolution"></a>

This section will give you an understanding of how one can associate alerts with Squadcast incidents and resolve them with an API call.

#### Typical Incident JSON <a href="#typical-incident-json" id="typical-incident-json"></a>

```
{
  "message": "This will be the incident message",
  "description": "This will be the incident description",
  "status": "trigger",
  "event_id": "6"
}
```

This triggers an incident and associates the incident with the <mark style="color:red;">`event_id`</mark> value as specified. This <mark style="color:red;">`event_id`</mark> can be used to resolve the above-created incident with an API call.

To resolve an incident, a JSON with the format shown below should be sent.

```
{
  "status": "resolve",
  "event_id": "6"
}
```

* The <mark style="color:red;">`status`</mark> field should be set to the value <mark style="color:red;">`"resolve"`</mark>
* The associated <mark style="color:red;">`event_id`</mark> should also be sent along with this

{% hint style="info" %} <mark style="color:blue;">**Resolving an Incident with an API call**</mark>**:**

To resolve an incident, **message** and **description** fields are not required to be sent.
{% endhint %}

### Add a Tag From directly Incident JSON <a href="#add-a-tag-from-directly-incident-json" id="add-a-tag-from-directly-incident-json"></a>

This section will give you an understanding of how you can add tags to an incident straight from the Incident JSON using the Incident Webhook.

#### Typical Incident JSON: <a href="#typical-incident-json-1" id="typical-incident-json-1"></a>

```
{
   "message":"This will be the incident message",
   "description": "This will be the incident description",
   "tags": {
     "tagname1":"Tag value#1",
     "tagname2":"Tag value#2",
     "tagname3": {
       "color": "Valid HTML HEX Colour Notation goes here",
       "value":"Tag value#3"
     }
   }
}
```

#### Example 1: Using `tags` to set the *Severity* for the incident <a href="#example-1-using-tags-to-set-severity-for-the-incident" id="example-1-using-tags-to-set-severity-for-the-incident"></a>

```
{
  	"message": "Error rates higher than usual",
    "description": "HTTP Error rates for srv_90 is above 90 counts/hour",
    "tags": {
    	"severity": "high"
    }
}
```

{% hint style="info" %} <mark style="color:blue;">**The default colour for Tags**</mark>**:**

If a color code is not mentioned explicitly, then the system takes the default color "**#808080**" (gray) for tags
{% endhint %}

To specify a color explicitly for `tags`:

```
{
	"message": "Error rates higher than usual",
  "description": "HTTP Error rates for srv_90 is above 90 counts/hour",
	"severity": {
  	"colour": "#FF0000",
  	"value":"backend"
  }
}
```

#### Example 2: Adding different tags to an incident <a href="#example-2-adding-different-tags-to-an-incident" id="example-2-adding-different-tags-to-an-incident"></a>

```
{
	"message": "Error rates higher than usual",
  "description": "HTTP Error rates for srv_90 is above 90 counts/hour",
	"tags" : {
   	"priority": "P1",
	  "impact_level": 5,
   	"classification": {
    	"color":"#FF0000",
     	"value":"backend"
     }
 	}
 }
```

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*


# Outgoing Webhooks

Use outbound webhooks to send incident information from Squadcast into other systems

Webhooks allow you to connect a platform you manage (either an API you create by yourself or a third-party service) to a stream of future events.

Setting up a Webhook on Squadcast enables you to receive information (referred to as events) from Squadcast as they happen. This can help you avoid continuously polling Squadcast’s REST APIs or manually checking the Squadcast web/mobile application for desired information.

{% hint style="info" %}
**Note:**

We also support *generic incoming Webhooks* for incident creation. You can find detailed information on how to use those [<mark style="color:blue;">here</mark>](/integrations/incident-webhook-incident-webhook-api)<mark style="color:blue;">.</mark>
{% endhint %}

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

Only the **Account Owner** and **Users** with the <mark style="color:red;">`Manage Webhook`</mark> permission will be able to *enable*, *disable* and *manage* Webhooks in Squadcast.

If you do not have access to this feature, please contact your account admin to give you the right permissions.

Navigate to **Settings** -> **Permissions** and enable the checkbox under **Webhooks** for the desired users.

<figure><img src="/files/F20y3Rv9zx0TgUwzG5AW" alt="Setting up Webhooks permission"><figcaption><p>Setting up Webhooks permission</p></figcaption></figure>

### **Add Webhooks** <a href="#setup-a-webhook" id="setup-a-webhook"></a>

To add a Webhook,

1. Navigate to **Settings** -> **Webhooks**
2. Click **Add Webhook**. On the next screen, you will be guided through three steps. Navigate between these steps by clicking on any of the steps on the top bar.
3. **Add Webhook Details**:

   <figure><img src="/files/OytXIdYWongvi1PbTIq8" alt="Step 1: Add Webhook Details"><figcaption><p>Step 1: Add Webhook Details</p></figcaption></figure>

   1. **Webhook Name**: Enter the **Webhook Name**.
   2. **Webhook Description** (*optional*): Enter an optional **description**.
   3. **Failure Notification Email** (*optional*): Enter an email where you want to receive failure notifications. This is particularly helpful when you (or an administrator) would want to be notified of Webhook-related failures.
   4. **URL**: Enter the **Webhook URL**. We support the addition of multiple URL endpoints, with <mark style="color:red;">POST</mark>, <mark style="color:red;">PUT</mark>, and <mark style="color:red;">PATCH</mark> methods. Incident payloads will be sent to all the URL endpoints that are added.
   5. **Additional Headers** (*optional*): You can also configure additional headers. These headers will get attached to all the Webhook calls that will be made based on this configuration. **Note**: Content-Type: application/JSON is added by default.

   Click **Save Changes**, and navigate to the next step.
4. **Choose Webhook Type**: Choose Webhook type (Manual or Automatic) and add configurations.

   <div><figure><img src="/files/DeGcK8JtFz2NVqCE3cb3" alt="Step 2(a): Configure Manual Webhook"><figcaption><p>Step 2(a): Configure Manual Webhook</p></figcaption></figure> <figure><img src="/files/cPFSTkNWPybuHPz0ufia" alt="Step 2(b): Configure Automatic Webhook"><figcaption><p>Step 2(b): Configure Automatic Webhook</p></figcaption></figure></div>

   1. **Manual Webhook**: Manually trigger Webhooks under incidents, on demand. Under Manual Webhook, select the teams that are authorized to access the Webhook. You can select All Teams or enter specific Teams, from the drop-down.
   2. **Automatic Webhook**: Automatically trigger Webhooks when the configured conditions match. To set up Automatic Webhook Configurations:

      1. **Versions**: Select the version from the drop-down.
         1. V1 supports limited events which are backward compatible
         2. V2 is the latest version and supports a lot more events
      2. **Triggers**: Select the Trigger events (conditions) for which the Webhook will be triggered.
      3. **Filters**: You can apply filters on top of events, based on Teams, Services, Alert Sources, Priorities, and Tags, either by having an individual expression or a combination of expressions/expression groups.

         Applying filters will allow the Webhook to be triggered only for events that match the filter.

      Click **Next: Configure Payload**, and navigate to the next step.
5. **Configure Payload**: Configure the payload based on your selected Webhook type.

   <div><figure><img src="/files/cCkgpYNvKGbYpEfIiMtG" alt="Step 3(a): Configure payload for Manual Webhook"><figcaption><p>Step 3(a): Configure payload for Manual Webhook</p></figcaption></figure> <figure><img src="/files/duNJt5UnJcq67I4yybtN" alt="Step 3(b): Configure payload for Automatic Webhook"><figcaption><p>Step 3(b): Configure payload for Automatic Webhook</p></figcaption></figure></div>

   1. **Manual Webhook:**
      1. **Payload Templates**: Select one of the pre-configured templates, or create your own payload. If you want to add more commonly used templates, create a PR on [<mark style="color:blue;">GitHub</mark>](https://github.com/SquadcastHub/squadcast-webhook-templates)<mark style="color:blue;">.</mark>
      2. **Payload**: You can reference your selected template payload here. You can modify the payload and validate it before saving the Webhook. You can also test the Webhook by clicking on the Test Webhook on the bottom right.
   2. **Automatic Webhook**: You can select between the standard Squadcast payload for all trigger events or customize the payload based on the pre-configured templates.
      1. **Standard Squadcast Payload**: You will find the standard payload for your selected trigger events based on the version you have selected. **Note**: You can only test the Webhook for the first trigger event you have selected in Step 2.
      2. **Custom Payload**: You can reference your selected template payload here. You can modify the payload and validate it before saving the Webhook. You can also test the Webhook by clicking on the Test Webhook on the bottom right. **Note**: You can only test the Webhook for the first trigger event you have selected in Step 2.

Click **Save** and you're done.

{% hint style="warning" %}
**Important:**

Squadcast uses the below IPs from which it sends Webhook requests. You may need to whitelist these IPs with your firewall to use Webhooks without any issues.

For US region: 34.148.46.58

For EU region: 35.246.154.28
{% endhint %}

### Supported Events <a href="#supported-events" id="supported-events"></a>

The Webhooks that you have configured can be triggered for certain Trigger Events occurring in Squadcast.

You can choose multiple Trigger Events for a Webhook. Information is sent to the provided URLs if any of the triggers match. The following event types are available for each Webhook version:

{% hint style="info" %}
**Note**:

Payloads for event types part of both versions are different for each.
{% endhint %}

<table><thead><tr><th>Resource</th><th>Event</th><th width="172">v1</th><th>v2</th></tr></thead><tbody><tr><td>Incident</td><td>triggered</td><td>✔️</td><td>✔️</td></tr><tr><td></td><td>reassigned</td><td>✔️</td><td>✔️</td></tr><tr><td></td><td>acknowledged</td><td>✔️</td><td>✔️</td></tr><tr><td></td><td>resolved</td><td>✔️</td><td>✔️</td></tr><tr><td>Communication Channel</td><td>created</td><td></td><td>✔️</td></tr><tr><td></td><td>updated</td><td></td><td>✔️</td></tr><tr><td></td><td>deleted</td><td></td><td>✔️</td></tr><tr><td>Incident Notes</td><td>created</td><td></td><td>✔️</td></tr><tr><td></td><td>updated</td><td></td><td>✔️</td></tr><tr><td></td><td>deleted</td><td></td><td>✔️</td></tr><tr><td></td><td>starred</td><td></td><td>✔️</td></tr><tr><td></td><td>unstarred</td><td></td><td>✔️</td></tr><tr><td>Incident Tags</td><td>updated</td><td></td><td>✔️</td></tr><tr><td>Incident Task</td><td>created</td><td></td><td>✔️</td></tr><tr><td></td><td>updated</td><td></td><td>✔️</td></tr><tr><td></td><td>deleted</td><td></td><td>✔️</td></tr><tr><td></td><td>completed</td><td></td><td>✔️</td></tr><tr><td></td><td>uncompleted</td><td></td><td>✔️</td></tr><tr><td>Postmortem</td><td>created</td><td></td><td>✔️</td></tr><tr><td></td><td>updated</td><td></td><td>✔️</td></tr><tr><td></td><td>deleted</td><td></td><td>✔️</td></tr><tr><td>SLO-Violating Incident</td><td>created</td><td></td><td>✔️</td></tr><tr><td></td><td>marked false positive</td><td></td><td>✔️</td></tr><tr><td></td><td>unmarked false positive</td><td></td><td>✔️</td></tr><tr><td></td><td>spent error budget</td><td></td><td>✔️</td></tr><tr><td>StatusPage</td><td>updated</td><td></td><td>✔️</td></tr></tbody></table>

{% hint style="info" %}
**Note**: Additional event types may be added to this list over time.
{% endhint %}

{% hint style="info" %}
**Note**: If your use case requires more Squadcast events to be supported, please contact our [<mark style="color:blue;">Support team</mark>](mailto:support@squadcast.com) with the details for the same.
{% endhint %}

### **Edit Webhooks**

To edit the Webhook configurations,

Navigate to **Settings** -> **Webhooks** -> Hover over any Webhook you want to edit and click **Edit Webhook**. It will open up to the guided three-step creation flow, where you can edit by navigating between these steps by clicking on any of the steps on the top bar.

<figure><img src="/files/vbsNQau8dsShMFgF2EzP" alt="Steps to edit a Webhook"><figcaption><p>Steps to edit a Webhook</p></figcaption></figure>

### **Delete Webhooks**

To delete a Webhook,

Navigate to **Settings** -> **Webhooks** -> Under more options, click **Delete**. You will receive a confirmation dialog prompt to confirm the deletion, click **Delete**.

<figure><img src="/files/GdX1tZTytkw5Iz8VYk1V" alt="Steps to delete a Webhook"><figcaption><p>Steps to delete a Webhook</p></figcaption></figure>

### Communication Protocol for Webhooks <a href="#communication-protocol-for-webhooks" id="communication-protocol-for-webhooks"></a>

A Webhook is called whenever the configured events occur in Squadcast.

A Webhook call is made using the <mark style="color:red;">`HTTP POST`</mark> method to the URL(s) that were added when the Webhook was configured, with a body that is encoded using <mark style="color:red;">`JSON`</mark>.

Squadcast expects the server that responds to the webhook to return a 2xx response code upon success. If a non-2xx response is received, **Squadcast will retry the request a maximum of 3 times**, over a period of time.

### **View Logs**

To view logs for Webhook calls that have been made,

Navigate to **Settings** -> **Webhooks** -> Hover over any Webhook you want to view the logs for and click **View Logs**. You can view the Timestamp, Status, and Payloads for each Webhook call.

<figure><img src="/files/gXzk3YbnLvL0kcFLPJix" alt="Steps to view logs for Webhook calls"><figcaption><p>Steps to view logs for Webhook calls</p></figcaption></figure>

### **Use Cases for Webhooks**

Webhooks can be leveraged in various scenarios. We have put together some common use cases.

They are:

* Building internal custom dashboards to visualize or analyze incidents
* Sending data to ticketing tools like Zendesk, Freshdesk, Shortcut, Asana, etc.
* Sending events to communication apps like Slack, MS Teams, etc.
* Alerting when a workflow is disrupted- then using the API to re-run the workflow
* Triggering internal notification systems to alert people when incidents are created/resolved
* Building your own automation plug-ins and tools

{% hint style="info" %}
**Note:**

Please contact our [<mark style="color:blue;">Support team</mark>](mailto:support@squadcast.com) if you need help integrating your Squadcast account into a third-party application using Webhooks.
{% endhint %}

### Sample Webhook Payloads

To see the sample Webhook payloads, click [<mark style="color:blue;">here</mark>](https://developer.squadcast.com/outgoing-webhooks/payload/)<mark style="color:blue;">.</mark>

### Limitations of Webhooks

1. The Webhooks API provides "at least once" delivery of Webhook events. This means that an endpoint might receive the same Webhook event more than once. You should be able to handle any possible duplicates.
2. Ordering amongst Webhooks isn't guaranteed between different topics for the same resource. For example, it's possible that an incident-triggered Webhook for a second incident might get triggered before the first incident when there are many incidents created in quick succession.
3. Webhook delivery isn't always guaranteed. You should therefore implement reconciliation jobs to fetch data from Squadcast periodically.

*Have any questions?* [*Ask the community*](https://community.squadcast.com/view/home)*.*




---

[Next Page](/llms-full.txt/1)

