Triage new Better Stack incidents in Slack and Linear

By General Input

When Better Stack fires an incident, an agent posts a rich Slack heads-up and opens a Linear ticket so your on-call team hits the ground running.

Integrations

  • Better Stack
  • Slack
  • Linear

Type

Agentic Task

Categories

  • Engineering
  • Operations

When Better Stack sends a webhook that a new incident has been created, kick off an agent that triages the alert end to end and turns it into a useful heads-up plus a durable follow-up ticket.

Start by pulling the incident's full details and its timeline of events from Better Stack (Get Incident, List Incident Timeline). Then look up the affected monitor with Get Monitor, and grab its recent Get Monitor Response Times so you can describe what state the target is actually in right now — hard down, degraded, timing out, or slow.

Figure out who is currently on call. Use List On-call Schedules to find the relevant schedule for this monitor or team, then Get On-call Schedule to pick out the person who is on the hook right now. Keep their name and email handy for the Slack message and the Linear assignment.

For pattern context, use List Incidents filtered by the same monitor and pull the last several. If any of them resolved within the last 30 days, treat this as a probable repeat and surface that prominently at the top of the Slack message — do not bury it.

Post a rich Slack message to our incidents channel using Slack Send a Message. Include: the monitor name and URL, the likely blast radius in plain English (which service or endpoint this affects), the current status, a suspected cause synthesised from the timeline events and the response-time trend, the on-call engineer, a repeat-incident callout when applicable, and direct links back to the Better Stack incident and monitor pages so people can dig in with one click.

Then open a Linear issue with Linear Create Issue. Use List Teams and List Users to find the on-call engineer's team and Linear user id. Set the priority based on the incident severity, write a short summary, and include a follow-up checklist covering: confirm the alert is real, mitigate, root-cause, add or tune monitoring, and write a postmortem. Assign the issue to the on-call engineer when we can match them; otherwise leave it unassigned so whoever picks up the alert can grab it. Link the Better Stack incident URL in the description.

The Slack message is the primary human-facing output — make it scannable in five seconds. The Linear issue is the durable follow-up so the work of writing a postmortem and tuning monitoring does not fall off the floor after the incident resolves.

Related prompts

Explore more prompts
Call overdue Xero customers with an AI collections agentWin back LiveChat visitors whose chats went unansweredChat quality review board for LiveChat support leadsWin back no-show and cancelled appointments every morningLive Loop returns analytics with product-level drill-downNewsletter pre-flight and approval board for Mailjet sendsTurn a prospect spreadsheet into personalized sequence enrollmentsMailjet email delivery lookup console for support teamsCatch feature flags that never got switched on in productionKajabi customer support console for member access fixes