Platform

An incident response platform, from the first alert to the resolved incident.

Seven stages, and CallHeim is different in the three before somebody’s phone rings — that is where the decisions live and where every rule is published. It is complete in the four after.

The CallHeim loop

Ingest, reduce, decide, page, respond, close.

Pick a stage to see what it does and the threshold it does it with.

Before the page

where CallHeim is different

After the page

response and closure

Learn → MTTA and MTTR from each incident’s timestamps
REDUCEstage 2 of 6

Duplicates collapse, flapping series stop paging, related alerts group.

Fingerprint dedup inside 300s, flap collapse at 4 transitions / 600s, title correlation at Jaccard ≥ 0.6.

In the app: Noise Rules · MaintenanceRead more →

12 alerts in, 1 incident out

fingerprinta91f…3c
collapsed11 duplicates
window300s

Ingest · Reduce · Decide

Before the page.

Everything between a webhook arriving and a person's phone lighting up.

By default, seven ordered checks

An alert passes through these before it is allowed to become an incident. Orchestration rules run first, and tenant threshold rules can add more. Each check has a threshold, and every threshold below is published.

The decision pipeline. By default seven ordered checks run on every alert; orchestration rules run before them and tenant threshold rules can add more. Most checks divert the alert out of the sequence — a flapping series with nothing open to join is the one exception that still creates an incident.

  1. Maintenance window

    Suppress if a window covering this service, team or the whole workspace is open right now.

    active windowOutcome: suppress

  2. Suppress rules

    Suppress if any tenant Noise Rule matches the alert.

    rule matchOutcome: suppress

  3. Fingerprint dedup

    Attach to the open incident that already owns this fingerprint, while repeats keep arriving. The fingerprint is the tenant, the source, and the alert’s dedup key or identity — falling back to its title. The service is not part of it.

    300s sliding windowOutcome: attach

  4. Flap collapse

    A series that keeps changing state attaches to the open incident instead of paging again. With nothing open to join, it still opens an incident.

    4 changes / 600s (fixed)Outcome: group

  5. Title correlation

    Group with an open, still-Triggered alert from the same source and the same service when their titles overlap enough.

    Jaccard ≥ 0.6 default, 600sOutcome: group

  6. Group rules

    Apply the tenant’s own grouping rules over the window.

    600s windowOutcome: group

  7. Create incident

    Nothing above matched: open the incident with the source’s severity (or the severity an orchestration rule sets), pick the Escalation Policy for the service, and page.

    elseOutcome: create

Defaults shown above. Orchestration rules run first and tenant threshold rules can add further steps.

Noise reduction in depth →Browse integrations →

Example · the pipeline's own mechanics

Watch an alert become an incident.

One alert, walked through the checks above, with the numbers those checks actually use.

01 · A webhook arrives

Inbound webhookdatadog
{
  "alert_type": "error",
  "title": "checkout-api p99 latency > 2s",
  "host": "checkout-api-canary",
}

02 · The alert gets a fingerprint

Decision receipt
fingerprint
sha256(tenant · source · dedup key)

Tenant, source and the alert’s dedup key or identity, falling back to its title. The service is not an input.

window
300s, sliding

Resets on every new repeat.

03 · Duplicates collapse, grouping does not cross sources

Decision receipt
repeats
same fingerprint

Attach to the open incident; no new page.

title grouping
Jaccard ≥ 0.6 default

Same source, same service, still Triggered, within 600s. Never across sources.

04 · Severity is the source's, plus a suggestion

Decision receipt
incident severity
P1

Mapped from what Datadog sent (or an orchestration override).

suggestion
P1, matched “latency”, “p99”

A separate suggestion from a keyword ruleset and your resolved incidents. A person applies it; it never changes severity on its own.

05 · Routed and paged

ExampleSeverity P1Status Triggered#2041

checkout-api p99 latency > 2s

service checkout-apipolicy checkout-api — default
One escalation policy owns this service. If its first tier does not answer, it advances — and there is one mandatory fallback target for the whole policy, not one per person.

How incident severity levels work →What an escalation policy is →

Page

Then it has to reach somebody.

Escalation runs on an AWS Step Functions state machine: an unanswered tier times out and advances to the next tier or the fallback.

  • Escalation policies have up to 8 tiers, per-tier timeouts from 1 to 240 minutes, and a mandatory fallback target.
  • Acknowledging an incident stops the escalation.
  • Each alert source is bound to a service, and the service’s escalation policy (or its team’s) sets who is paged.

Alerting and escalation in depth →

Example · Escalation Policy · Payments — Business Hours
T+0:00

Tier 1

The responder on call right now, paged on their own notification order.

  1. T+0:00

    Tier 1

  2. T+5:00

    No acknowledgement → tier 2

  3. T+10:00

    Still nothing → the tier chain repeats

  4. Repeats exhausted

    One fallback target, once

  5. Acknowledged

    The walk stops

Pricing

Included at every tier.

Alerting, on-call, escalation, noise reduction, incident response, public status pages and core analytics are included at every tier.

Some features are tied to plan: the REST incident API and related-incident insights on Pro and above; email-to-alert (per-workspace inbound alert e-mail addresses) on Trial, Business and Enterprise, not Starter or Pro.

See full pricing →

CallHeim

Put a rule you can read between your alerts and your on-call.

CallHeim helps teams stay in control when critical systems are not. Pick the plan that fits, connect one source, and send yourself a page.

Early access · every workspace starts with a 14-day trial for up to 5 seats, no card required