For IT operations and ITSM

IT on-call and escalation that speaks ITSM.

Some of your alerts arrive as e-mail from a system nobody will ever add a webhook to. Others come from a service desk. A tool that only accepts JSON from modern observability platforms solves the easy half.

Email ingest

For everything that only sends mail

There is an entire class of infrastructure — UPS controllers, backup software, storage arrays, an older line-of-business application — whose only alerting mechanism is SMTP. IT operations lives with that reality; observability vendors mostly do not.

Once an e-mail becomes an alert, it gets the same treatment as everything else: repeats collapse on a fingerprint within the same five-minute window, and it is routed by the same Escalation Policy as any other source.

How it works

  • Trial, Business and Enterprise plans: each workspace gets an inbound alert e-mail address for email-to-alert; mail sent to it becomes an alert. Starter and Pro do not include it.
  • Alert e-mail takes a severity hint from the subject line (for example [P1] or CRITICAL) and otherwise defaults; dedup and escalation are the same as for a webhook source.

Email-to-alert is on the Trial, Business and Enterprise plans, not Starter or Pro. The generic webhook, which covers most of the same ground for anything that can POST, is on every tier.

Your systems

Service desks, monitoring and the mail gateway.

Each alert source has a payload mapping for that tool’s webhook format and its own setup page, built and tested against sample payloads.

All incident and ITSM sources →

ServiceNow, Freshservice, Zendesk and similar tools connect as inbound alert sources: an event in your ITSM tool can raise a CallHeim alert. CallHeim does not write back to the ticket.

The IT-shaped parts

Ownership that maps to how you are organised.

Business services

Roll technical services up into the thing the business actually names — “payroll”, “the warehouse system” — with owners and tiers. Dependency views show downstream impact on screen; they do not change how an alert is routed today.

Maintenance windows

Maintenance windows suppress new alerts for a service, a team or the whole workspace, and recovery events are exempt.

Status pages

A workspace’s public status page lives at app.callheim.com/status/your-slug and your team updates it by hand.

Escalation that reaches people

Alerts route through your Escalation Policy to the on-call for that service. Pages go out by e-mail with a signed acknowledge link, live in early access.

Access

Roles, two-factor and an audit trail.

  • Five built-in roles with 22 permissions, plus per-workspace permission overrides and custom roles.
  • E-mail and password sign-in with optional authenticator-app (TOTP) two-factor authentication.
  • The audit log is append-only: no client can modify or delete an entry.

Security and trust →

CallHeim

Put a rule you can read between your alerts and your on-call.

CallHeim helps teams stay in control when critical systems are not. Explore the platform, connect one source, and send yourself a page.

Early access · every workspace starts with a 14-day trial for up to 5 seats, no card required