Skip to content

Review incidents

ScrinOps incidents are provider-neutral summaries for an exact project and workspace. The browser receives redacted metadata, not raw provider alerts, credentials, or log content.

Typical time
10–20 minutes
You need
An enabled incident feed in the selected scope
Outcome
A triaged incident with evidence readiness understood

Open ScrinOps, then Incidents. Select Project and Workspace. Every list, cursor, filter, detail request, and diagnosis action stays bound to that authenticated scope.

Use:

  • Search for an incident, service, or owner;
  • Status: All statuses, Open, Investigating, Mitigated, or Resolved;
  • Severity: All severities, Critical, High, Warning, or Info;
  • Provider: AWS or Azure;
  • Refresh for the current page; and
  • Previous, Next, and page size for bounded history navigation.
ScrinOps incident filter toolbar with synthetic project and workspace labels plus search, status, severity, provider, and refresh controls.
Incidents 1 of 5 · Filter incident historySynthetic ScrinOps incident filter toolbar for selecting scope and filtering incident history.

If Partial connector data appears, incident summaries remain available but evidence or work-item data is degraded. Do not interpret partial data as a full incident record.

Choose the incident title or View details. The right-side incident drawer contains Overview, Timeline, Evidence, and Audit.

Synthetic ScrinOps incident Overview with Investigating status, Warning severity, occurrence and evidence counts, and provider-neutral scope metadata.
Incidents 2 of 5 · Review incident OverviewSynthetic read-only incident Overview showing status, severity, occurrence and evidence counts, and generic scope metadata.

Timeline lists bounded occurrence summaries with firing or resolved state, severity, source kind, time, and correlation reference. It does not expose the raw CloudWatch or Azure Monitor alert body.

Synthetic ScrinOps occurrence timeline with firing and resolved provider-neutral events and generic correlation references.
Incidents 3 of 5 · Read provider-neutral occurrencesSynthetic provider-neutral Firing and Resolved occurrence summaries with generic correlations.

Evidence shows manifest metadata only:

  • source kind;
  • ready, degraded, or unavailable status;
  • record and stored-size counts;
  • redaction and truncation state;
  • collection and expiry time; and
  • a shortened digest.

Only ready, unexpired evidence can make Start diagnosis available.

Synthetic ready evidence manifest showing safe record, size, redaction, truncation, expiry, and shortened digest metadata.
Incidents 4 of 5 · Assess evidence readinessSynthetic ready evidence manifest with redaction, truncation, expiry, and shortened digest metadata.

Audit shows bounded ownership and lifecycle events such as created, assigned, status changed, evidence attached, and diagnosis started.

Synthetic ScrinOps incident lifecycle audit with generic created, evidence-attached, and status-changed entries.
Incidents 5 of 5 · Review incident lifecycle auditSynthetic bounded lifecycle audit with generic action summaries and safe actor labels.

You understand the incident state, severity, occurrence history, evidence freshness, degraded sources, ownership, and whether diagnosis is eligible.

  • No incidents found: change filters, confirm scope, and verify live alert ingestion separately.
  • Partial connector data: continue only with the available evidence and note the gap.
  • Details unavailable: retain the summary and retry; do not infer missing timeline or evidence.
  • Diagnosis unavailable: refresh evidence or wait for a ready, unexpired manifest.
  • Access denied: request the correct project/workspace permission; do not reuse identifiers from another tenant.