Invites open the exact incident summary so a responder can understand the ask before joining, delaying, or declining.
The whole response loop
Turn monitoring signals into coordinated human action.
WarnFire correlates events, finds the right people, delivers context across channels, and preserves every operational decision through resolution.
Incident lifecycle
Updates stay attached to one operational story.
Deduplication correlates repeated triggers and provider updates with the active incident. Typed details, labels, links, environment, source, severity, and raw event evidence remain inspectable instead of disappearing into notification text.
Acknowledge, resolve, and forced resolution are attributable timeline actions, making it clear who acted, when, and why.
Escalation
Page one person—or the whole tiger team.
Schedules and policies find the current responder. Sequential steps escalate deliberately; tiger-team steps fan out to an entire group when the incident needs parallel expertise immediately.
Push and email can lead the sequence, with SMS and voice reserved for incidents that justify paid escalation.
Response experience
Context reaches the person, not just their inbox.
Invite specialists during an incident. They can join now, commit to a later time, decline with context, leave, and be requested again.
Create focused Slack collaboration for an incident, synchronize key actions, and archive the room when the work is complete.
The incident timeline provides the foundation for approval and quorum workflows without separating decisions from their operational context.
Operational control
Configuration people can verify before the page.
Time-zone-aware rotations, layered coverage, handoff times, and computed timelines show who will actually be paged.
Handle swaps, absences, and temporary cover without rewriting the underlying rotation.
Keep ingest and audit evidence flowing while planned work suppresses paging.
Surface gaps, unreachable responders, unhealthy integrations, and configuration risks before production depends on them.
Safety controls
Bound storms without blocking recovery.
Trigger ceilings grow from 60 events/minute on Trial and Homelab to 5,000 on Enterprise. Resolve and acknowledge events remain available.
Separate SMS and voice pools, weighted international delivery, bounded monthly allowances, and paid-send rate limits constrain provider exposure.
Stable event identities make retries safe, while durable outboxes prevent transient provider failures from losing work.
Operational events expose ingest, notification, and collaboration failures to systems such as Wazuh without leaking credentials.