07 · INCIDENT MANAGER
An incident only closes once its postmortem is approved.
Every rollback opens an incident on its own, dated from when the bad version landed. Nobody closes it by hand: it closes when someone else approves the postmortem, and the approved document goes to your repository.
Opens a WhatsApp chat. Prefer email? [email protected]
What it does
A lifecycle that can't be skipped
open, mitigated, postmortem_in_review, closed. Mitigating can be undone: if the problem came back, the incident is reopened, not duplicated. Closing can't be undone. There is no close command.
Since when
Any member opens an incident, about a Component, a System, a database or a Resource, and says when the problem began — that is where repair time is measured from. An incident opened by a rollback is dated from when the undone version reached the environment.
The postmortem
In markdown, after mitigation. Review happens through comments, which follow the line when the text moves. A question is resolved by whoever asked it, or by an approver — never by the author. An open comment doesn't block approval.
Approving closes it
Only a postmortem approver named by the organization can approve, and never the author. Approval is about completeness and quality, never blame — and that sentence is printed on every postmortem. Once approved, the document freezes and the incident closes.
In your repository
The approved postmortem is committed by the Agent to the Git repository the organization chose, at a path that never overwrites another outage's. The bytes published are the bytes approved.
The incident nobody closes
After 7 days open, the incident notifies — once — the approvers, whoever opened it, whoever mitigated it and the administrators, in a notification nobody can silence. Nothing closes on its own.
Numbers that don't get mixed
MTTR, MTTF and MTBF are reported separately by where the timestamp came from: derived from the deploy, from the start of the rollback, or declared by a person. MTTA shows as "not measured", not as zero.
How it works
The lifecycle is the mechanism: every transition has an owner, and the last one only happens through someone else's approval.
-
openmitigate -
mitigatedpostmortem submit reopen -
postmortem_in_reviewpostmortem approve -
closed
heimdall incident postmortem approve c50444ea-ac8a-4738-b28e-3cce084804f2
This postmortem is reviewed for completeness and quality, never for blame. Approving it says the account is complete enough for somebody to learn from — not that anybody is at fault.
INCIDENT STATUS APPROVED_AT WRITTEN_BY
c50444ea-ac8a-4738-b28e-3cce084804f2 closed 2026-10-10T06:07:36.523237Z f8e39903-3865-85b2-837c-3270d4eeaf23
heimdall incident postmortem approve: approving closes.Where the data lives
Everything runs in your infrastructure. The split below matters inside your company: it says who on your team can reach what.
| IN THE API, WHICH IS YOURS | IN YOUR GIT REPOSITORY |
|---|---|
The incident, the mitigation, the postmortem, the comments and the metrics, with per-organization isolation in the database. | The approved postmortem, committed by the Agent. Publishing isn't a condition for closing: if the repository is down, the incident closes anyway and publishing is retried. |
Who approves what
| ACTION | WHO |
|---|---|
| Open, mitigate, reopen, write and comment | every member — on purpose: a form only an administrator can fill in is a form nobody fills in at 3 a.m. |
| Approve the postmortem, which closes the incident | a named approver — never the author |
| Name approvers and choose the repository | owner |
With the other modules
-
06
Release Manager
The rollback opens the incident, and the incident names the deploy it undid.
-
04
Database Manager
An incident open on a database names the
break-glassinvoked on it, and never grants it. Closing the incident is the only act that ends that link. -
01
Catalog
The incident is about a catalog Component, System or Resource.
Talk to the people who build Heimdall.
Tell us how your engineers store secrets and reach the database today. We'll answer with what Heimdall would put under rules first, and how the deployment would get there.
Opens a WhatsApp chat. Prefer email? [email protected]