Review performance, noise and postmortems
Dashboard is the live operational view; Noise dashboard and Reports are where you improve the setup after the fact.
Start a shift with the Dashboard
- Open Dashboard at the start of your shift.
- Confirm you are shown as the current responder for your workspace.
- Review any active or escalating incidents you are inheriting.
- Check the flapping-alert information for anything likely to page you.

Dashboard also shows incidents created today, acknowledgement and resolution metrics, escalation timers and recent incidents, updating through the application's real-time event connection. Use Incidents for the complete list and full detail.
Review response performance
- Open Reports.
- Review total incidents, average MTTA and average MTTR.
- Review escalated incidents and SLA breaches to see where escalation is doing a first responder's work.
- Review missed alerts and recurring-incident information.
- Compare against team benchmarks.
MTTA and MTTR are calculated from resolved incidents. If incidents are left active, the numbers understate reality.
Find and fix a noisy alert
- Open Noise dashboard and select the reporting window — 7, 14 or 30 days.
- Review the noise score and signal-to-noise percentage.
- Open Top noisy alerts and note the alerts with high volume and few actioned incidents.
- Check Flapping alerts for checks that repeatedly change state.
- Open Cloud Integration and review that metric's threshold, evaluation window and datapoints required to alarm.
- Raise the threshold, lengthen the window, or lower the severity so it no longer pages a human, then deploy.
- Re-check the next reporting window and confirm volume dropped.
Produce a postmortem
- Open the incident in Reports.
- Review the incident timeline, severity changes and progress updates.
- Generate the postmortem draft from the incident record.
- Add the root cause and any corrective actions.
- Review the whole draft before circulating it.
If no root-cause information has been recorded, the report keeps root cause as pending rather than generating one from unavailable incident data.