Acknowledge, Snooze and Escalation
Acknowledge an alert you are working on, snooze one that can wait, send an unanswered one to somebody else, and wake whoever is on call this week.
An alert that nobody answers should reach somebody else. An alert somebody is already working on should stop repeating. And the person woken at 3 a.m. should be whoever is on call this week, not whoever set up the Discord channel. Acknowledge, snooze, escalation and on-call schedules do exactly that, for network monitoring alerts, diagnoses, incidents and your alert rules alike.
Acknowledge and snooze
Every monitoring alert, diagnosis and incident has Acknowledge and Snooze buttons: on the diagnoses feed, the host and link pages, the incident page and the topology side panel. The incidents list shows who acknowledged an incident, or until when it is snoozed.
- Acknowledge (with an optional note) says "I have it". Escalation and repeat notifications stop until the alert clears or someone un-acknowledges it. The alert shows Acknowledged by Anna.
- Snooze for 15 minutes, an hour, four hours, until 08:00 tomorrow, or until a date and time (at most 7 days ahead). When it runs out the alert is live again and escalation starts over.
- Un-acknowledge starts it over at once.
Acknowledging an incident also covers the monitoring alerts and diagnoses that belong to it. An acknowledgement ends by itself when the alert resolves. Everyone who can see the network map can acknowledge; every change is in the audit log.
From the message itself
Alert messages by email, Discord, Slack, Telegram, WhatsApp and webhook carry an Acknowledge link. It opens a short confirm page (so a chat preview or a mail scanner cannot acknowledge by opening it), works once, for six hours, for that one alert. A link from an email to a person acknowledges in that person's name; a link from a shared channel records it as coming through that channel.
Escalation policies
Settings > Alerts > Escalation holds named policies made of steps: "after N minutes unacknowledged, notify ...". A step can notify any mix of:
- the alert's own settings (the channels it would have used anyway),
- chosen people, through their own notification settings (the bell, an instant email with an Acknowledge link, a push to the Field app),
- whoever is on call on a schedule,
- alert channels.
The last step can repeat every M minutes, up to K times. Optionally, the channels that were told also hear "acknowledged" and "resolved".
Which policy an alert follows depends on what it is: monitoring alerts per family (infrastructure, customer radios, internet references) and severity, diagnoses (outages or the rest), incidents, and alert rules each pick their own. Planned maintenance, a snooze and quiet hours hold an escalation; an acknowledgement stops it; the alert resolving ends it.
Every workspace starts with a Default policy that sends each alert once, to its own settings, exactly as before policies existed. Nothing changes until you edit it.
On call
Settings > Alerts > On call holds weekly rotations (or every N days) of your staff, with a handover day and time in your workspace's time zone, plus overrides for holidays and swaps. Each schedule shows who is on call now, until when, and who is next. An escalation step can page "whoever is on call", and an On call: Anna chip sits in the monitoring bar and on the incidents page.
Telegram and WhatsApp
Two more channels sit next to email, Discord, Slack and webhooks:
- Telegram: a bot token (stored encrypted) and a chat id. Follow-ups about the same problem reply to its first message, so a chat stays readable.
- WhatsApp through your own Twilio account. Outside the 24-hour window WhatsApp only delivers approved templates, so the form takes a template's Content SID; without one, plain messages work in the Twilio sandbox and when the recipient wrote to you in the last 24 hours. The form explains which case you are in.
Every channel has a Send test button.
Quieter at night
One problem is one thread where the channel allows it (Telegram replies, email threads; Discord and Slack webhooks cannot thread). Quiet hours (in Settings > Alerts > Escalation) hold warnings until the morning, while critical alerts always go out; an alert about a single customer radio is never critical.
Good to know
- Acknowledge and snooze are in the REST API, the staff mobile API behind the Field app, and the MCP server.
- If an alert is already clean again when the incident grace period ends (a host answering, a link healthy), no incident opens while it finishes closing; a fault that comes back still opens one.