Incidents
An incident is created only when alerts are sustained and correlated enough to earn one. It arrives with a likely cause, every contributing alert attached as evidence, and one owner.
Four states, and the fourth one matters: marking something a false positive is first-class, because a promotion engine you cannot correct is a promotion engine you stop trusting.
The verdict is derived deterministically from what actually changed, so it still works when the model is unavailable. Enrichment is additive, never load-bearing.
The part that decides whether your phone rings. Grouping happens before notification, never after.
Generated runbooks, postmortems and similar-incident search are model-backed and gated behind a feature flag. Everything else on this page — promotion, grouping, the deterministic verdict, the timeline and blast radius — runs without a model.
Connect one cluster and watch a week of alerts sort themselves into the handful that actually mattered.