Skip to main content
What happens when a monitor fires depends on whether it is armed.

Unarmed monitors

When an unarmed monitor fires, OnePatch records the firing — its state, reason, and time — as telemetry you can query and chart. No one is paged and no incident is opened.

Armed monitors

When an armed monitor fires, OnePatch opens an incident and the agent triages it:
  1. It investigates the firing against your live telemetry.
  2. It tunes the monitor if the firing was a false alarm, proposes a fix for a real problem, or asks for an action or decision it needs from you.
An incident is itself a chat: you can watch the investigation as it happens, step in, and review any pull request before it merges. Arming is opt-in per monitor; arm one only when a firing warrants an automated response.
A firing episode opens a single incident, however many evaluations fire during it, with a cooldown after it resolves.

Follow the investigation

The incident report shows the current status, findings, and any action the agent needs from you. Open its evidence links to inspect the charts, tables, or traces behind a conclusion. Reply in the incident chat to add context or ask the agent to check something. When several incidents turn out to be the same problem, the agent merges them into one episode so you can follow one investigation. A monitor going healthy prompts the agent to reassess; it does not automatically close the incident. A merged fix still needs to deploy and be checked against telemetry. The report distinguishes a verified fix from recovery without a confirmed permanent fix.

Slack

High-severity incidents (P0 and P1) post to the #onepatch-alerts channel OnePatch creates in your connected Slack workspace. Lower-severity incidents remain in the app. The Slack card updates as the investigation progresses and links to the incident. The channel name, workspace, and connection are managed from the integrations screen. To receive a DM or text when an incident needs human help, set up paging.

Talking to the agent from Slack

Every conversation is the same agent the in-app chat uses. Slack conversations appear in the app’s sidebar with a Slack marker and the sender’s name, so they stay visible to the rest of your team. Four ways to reach it:
  • Direct message. Message the OnePatch bot and it answers as the in-app chat does. The DM is one continuing conversation.
  • @-mention in a channel. Mention the bot in a channel it has been invited to and it replies in a thread. Each thread is its own conversation; reply in the thread to keep it going.
  • Reply in an incident thread. Under an incident card in #onepatch-alerts, a reply joins that incident’s chat. No mention needed.
  • Watched channels. Point OnePatch at a channel — a bug-report or support channel, say — and it reads every new top-level message there without a mention, opening a thread on the ones that need attention.
The bot only sees channels it has been invited to. /invite @onepatch in Slack first; removing it from a channel always stops it reading there.

Watched channels

Turn watching on from the integrations screen, or from inside the channel by mentioning the bot with one of these commands as the whole message: watch this channel, start watching, stop watching, and are you watching work as well. Anything longer is a message, not a command — @onepatch watch out, the deploy is landing is a question for the agent, and the channel’s watch state stays as it was. What a watched channel does:
  • Every new top-level message from a person opens its own thread and chat. Replies in that thread continue the same conversation, so a report and its follow-up stay together.
  • A screenshot with a caption is a message; edits, deletions, and posts from other bots are not.
  • The agent stays quiet when a message doesn’t need it. A channel that gets an answer to every “thanks!” is a channel people mute.
  • Only a member of your OnePatch organization can turn watching on or off — the sender’s Slack email has to match a OnePatch account. Only public channels can be watched: everything the agent reads is visible to everyone in your organization, so a private channel is refused. So is #onepatch-alerts, where the agent would be triaging its own cards.
  • Up to 20 watched channels per organization. As a brake on a runaway channel, one channel opens at most 20 new chats an hour and all watched channels together at most 60; messages past that are dropped, and replies in threads already open are never counted.

Firing history

Every firing is recorded as telemetry, so you can chart it: