An incident is Stector's record of a monitor's downtime, opened automatically when a check fails and closed automatically when it recovers. This guide covers the incident lifecycle and what you can do manually.
An incident moves through up to four states: Investigating, Identified, Monitoring, and Resolved. Stector creates one automatically the moment a monitor is confirmed down, starting in Investigating with a system-posted update: "Monitor went down, incident auto-created by system." It resolves automatically once the monitor records a single successful run in each of its regions, so recovery is detected faster than failure — each region only needs one passing run instead of two consecutive failing ones.
From an incident's page at /dashboard/incidents/[id], anyone with the Member, Admin, or Owner role can post an update: a status change plus a message. The status dropdown offers Investigating, Identified, or Monitoring — Resolved isn't one of the options here. To close an incident, use the Close incident button instead.
Closing an incident is restricted to Admin and Owner roles. This is deliberate: closing is a highly visible action that affects your status page, and keeping it separate from the update form reduces the chance of an incident being marked resolved prematurely during an active outage.
Which incidents your public status page shows depends on how they were created:
Open incidents show on the status page itself, and resolved ones stay in the incident history for 90 days after they close. Email notifications to your status page subscribers follow the same rule, so subscribers aren't emailed about an incident that isn't shown on the page.
There's no per-incident visibility toggle. To keep an automated incident off your page, leave its monitor unlinked from your components. Take care when changing links during an outage: if you unlink a monitor while its incident is open, the incident disappears from your status page and subscribers won't get any further emails about it, including the resolution.