Resolving incidents
How incidents close — automatically on recovery, on source changes, and by hand.
Most incidents resolve themselves. Some you'll want to close by hand. WatchFor covers both, and always keeps everyone in the loop.
Automatic resolution (recovery)
When the failing condition recovers — the site responds again, the certificate is renewed, latency drops back — the incident resolves automatically and a recovery notification goes to the same channels that were alerted.
Resolve on source change
If you change the thing that caused the incident, the incident shouldn't linger:
- Pause a monitor → its open incidents resolve.
- Disable or delete an alert rule → incidents from that rule resolve.
In each case the channels that were alerted are notified, with the reason — so nothing is left hanging "firing" forever.
Manual resolve
Owners and admins can resolve an incident by hand from the incident view — for example when you've fixed the underlying issue out of band.
- If the check is still failing, the incident simply re-opens on the next confirmed failure (the same approach PagerDuty and Opsgenie take).
- The original channels get a message saying who resolved it and why, and the incident timeline records it.
Acknowledging an incident signals "someone's on it"; resolving it closes the incident. Both are recorded on the timeline and in your activity log.