Once it is fixed,someone asks what actually happened.
The incident timeline is the account you need when you write things up: from the first failed check to the last notification and the moment of recovery, in order, without reconstructing it from memory.
Free plan: 3 monitors and one vantage point · 14-day Pro trial
What lands on the timeline
Opening and closing
The moment of detection and the moment recovery was confirmed, with exact times.
Alerts that went out
Every delivery, failure or suppression appears in the same chronological order.
Notes from the team
Any member can add a note — the context you would otherwise forget.
Maintenance windows
If the incident fell inside a quiet window, that is visible here.
Evidence beside the account
Per-region results
For that cycle you can see what each vantage point saw, and which one had no trouble.
Part of the response
For text responses, an excerpt of the body at the moment of failure is kept.
Safe headers
A short allowlist of response headers; sensitive ones are never stored.
Where this stops
An account, not a cause
The timeline says what happened and when; the conclusion is yours to draw — the postmortem is where you record it.
Evidence follows retention
Technical evidence is removed along with check history, so do not leave the write-up too long.
Related features
Have the account written for you
Create your first monitor so that when something breaks, its timeline is already there.
Create a free account