AI Incident Paging
Pages that find the right human, fast.
Generic alerting wakes everyone or no one. A Loomal incident agent reads each alert, classifies severity, picks the right on-call from the rotation, and escalates with full context — all from a real ops identity that audits every page.
API Primitives used
mail_list_messages
Read alert emails
Agent watches an alerts inbox for new messages from monitoring systems and parses severity, service, and impact.
vault_get
Read on-call rotation
Rotation schedules and escalation rules live in the vault, scoped to the ops identity.
mail_send
Page the right human
Agent sends the page from the ops identity with full context attached, escalating through the rotation as needed.
Alert fatigue is killing on-call.
Every team has the same problem: too many alerts, not enough signal. Engineers get paged for things that don't matter, miss the things that do, and burn out either way. The fix isn't quieter monitoring — it's smarter routing between the alert and the human.
An agent sits in that gap. It reads each alert, decides whether it's a real page or a noise event, picks the right on-call, and escalates if there's no acknowledgement. Engineers only get paged for things that actually need them.
How to build it.
01 mail_list_messages
Read the alert
Agent picks up the alert email, parses the service, severity, and metric, and decides whether to escalate.
02 vault_get
Pick the on-call
Agent reads the rotation schedule from the vault and identifies who's on for the affected service right now.
03 mail_send
Page and escalate
Agent sends the page from the ops identity. If no acknowledgement within the SLO, escalates to the next person in rotation.
Example prompt
“Watch alerts@. For any P1 alert, page the on-call from our rotation in the vault. If no one acknowledges in 5 minutes, escalate to the secondary. Page my manager if the secondary doesn't respond in 10.”
What ops teams build.
- Severity-based routing: P1 alerts page immediately; P3 batch into a digest for working hours.
- Service-aware paging: Each service has its own on-call rotation; agent picks the right one per alert.
- Multi-tier escalation: Agent escalates through primary, secondary, and manager tiers based on response SLO.
- Context enrichment: Agent attaches recent deploys, related alerts, and runbook links to every page.
- Postmortem assembly: After the incident, agent assembles a timeline of paging events and emails the team.
Why incident paging needs an agent identity.
Paging tools handle the fan-out. They don't handle the smart routing — and they certainly don't reason about which alert to page on. An agent that lives in the alert path can do both: classify intelligently and page consistently with full audit.
Loomal gives ops an identity that owns the alert inbox, the rotation data, and the page history — all in one delegation chain. Engineers stop getting paged for noise; the postmortems write themselves.
- Rotation data scoped: Schedules and escalation rules live in vault entries scoped to the ops identity.
- Per-page audit: Every page, escalation, and acknowledgement is logged with timestamp.
- Revoke on offboarding: Engineers leaving the team have their identity revoked instantly.
Page smarter, not louder.
Read, route, and escalate — fully autonomous.