07 · INCIDENT MANAGER

An incident only closes once its postmortem is approved.

Every rollback opens an incident on its own, dated from when the bad version landed. Nobody closes it by hand: it closes when someone else approves the postmortem, and the approved document goes to your repository.

Opens a WhatsApp chat. Prefer email? [email protected]

What it does

A lifecycle that can't be skipped

open, mitigated, postmortem_in_review, closed. Mitigating can be undone: if the problem came back, the incident is reopened, not duplicated. Closing can't be undone. There is no close command.

Since when

Any member opens an incident, about a Component, a System, a database or a Resource, and says when the problem began — that is where repair time is measured from. An incident opened by a rollback is dated from when the undone version reached the environment.

The postmortem

In markdown, after mitigation. Review happens through comments, which follow the line when the text moves. A question is resolved by whoever asked it, or by an approver — never by the author. An open comment doesn't block approval.

Approving closes it

Only a postmortem approver named by the organization can approve, and never the author. Approval is about completeness and quality, never blame — and that sentence is printed on every postmortem. Once approved, the document freezes and the incident closes.

In your repository

The approved postmortem is committed by the Agent to the Git repository the organization chose, at a path that never overwrites another outage's. The bytes published are the bytes approved.

The incident nobody closes

After 7 days open, the incident notifies — once — the approvers, whoever opened it, whoever mitigated it and the administrators, in a notification nobody can silence. Nothing closes on its own.

Numbers that don't get mixed

MTTR, MTTF and MTBF are reported separately by where the timestamp came from: derived from the deploy, from the start of the rollback, or declared by a person. MTTA shows as "not measured", not as zero.

How it works

The lifecycle is the mechanism: every transition has an owner, and the last one only happens through someone else's approval.

  1. open mitigate
  2. mitigated postmortem submit reopen
  3. postmortem_in_review postmortem approve
  4. closed
An incident's lifecycle, as the documentation shows it.
TERMINALheimdall incident
heimdall incident postmortem approve c50444ea-ac8a-4738-b28e-3cce084804f2
This postmortem is reviewed for completeness and quality, never for blame. Approving it says the account is complete enough for somebody to learn from — not that anybody is at fault.

INCIDENT                              STATUS  APPROVED_AT                  WRITTEN_BY
c50444ea-ac8a-4738-b28e-3cce084804f2  closed  2026-10-10T06:07:36.523237Z  f8e39903-3865-85b2-837c-3270d4eeaf23
Real output of heimdall incident postmortem approve: approving closes.

Where the data lives

Everything runs in your infrastructure. The split below matters inside your company: it says who on your team can reach what.

Incident Manager: where the data lives
IN THE API, WHICH IS YOURSIN YOUR GIT REPOSITORY

The incident, the mitigation, the postmortem, the comments and the metrics, with per-organization isolation in the database.

The approved postmortem, committed by the Agent. Publishing isn't a condition for closing: if the repository is down, the incident closes anyway and publishing is retried.

See security

Who approves what

Incident Manager: who approves what
ACTIONWHO
Open, mitigate, reopen, write and comment every member — on purpose: a form only an administrator can fill in is a form nobody fills in at 3 a.m.
Approve the postmortem, which closes the incident a named approver — never the author
Name approvers and choose the repository owner

With the other modules

  • 06

    Release Manager

    The rollback opens the incident, and the incident names the deploy it undid.

  • 04

    Database Manager

    An incident open on a database names the break-glass invoked on it, and never grants it. Closing the incident is the only act that ends that link.

  • 01

    Catalog

    The incident is about a catalog Component, System or Resource.

Talk to the people who build Heimdall.

Tell us how your engineers store secrets and reach the database today. We'll answer with what Heimdall would put under rules first, and how the deployment would get there.

Talk to engineering

Opens a WhatsApp chat. Prefer email? [email protected]