
Every production system will eventually break. It's not pessimism, it's just reality. That's why engineers go on-call, and why companies invest heavily in incident response tooling.
But here's the problem: the moment an engineer goes on call, they typically need elevated access to production systems, databases, and sensitive customer data. And that elevated access? It's often permanent, overly broad, and a security nightmare waiting to happen.
We've seen this pattern play out dozens of times: teams grant production access liberally because they need fast incident resolution, then cross their fingers hoping nothing goes wrong. It's a choice between security best practices and operational reality, and operational reality usually wins.
That tension is exactly what we're addressing with our new integration with Opal Security.
Let's be honest about what typically happens in most organizations:
Scenario 1: Permanent elevated accessEngineers get production access on day one and keep it forever. Sure, it makes incident response fast, but it also means you've got 20+ people with admin privileges who rarely need them. It's the security equivalent of giving everyone a spare key to your house.
Scenario 2: Just-in-time access requestsSomeone gets paged at 3am, then has to wait for approvals before they can even start investigating. By the time they get access, your customers have been down for 45 minutes. Not ideal.
Scenario 3: Break-glass processesYou've got emergency access mechanisms, but they're poorly documented, inconsistently enforced, and impossible to audit properly. People use them liberally because they're easier than the "proper" process.
None of these are good. What you actually want is access that's automatically granted when someone goes on call, automatically revoked when they're off, and fully auditable throughout.
That's exactly what the Opal Security & incident.io integration delivers.
The integration is straightforward: incident.io knows who's on call and when. Opal controls access to your production systems. Put them together, and you get automatic, time-bound access management tied directly to your on-call schedule.
Here's what that looks like in practice:
We've spent years building incident.io to make incident response faster and more effective. But speed isn't worth much if you're creating security vulnerabilities in the process.
This integration means you can move quickly without compromising on security posture:
Less operational overheadNo more manual access reviews, no more quarterly audits trying to figure out who still needs production access, no more tickets to provision and deprovision access. It just happens automatically based on your schedule.
This integration is part of something we think about a lot at incident.io: how do you build systems that allow your team to move quickly when it’s critical, but also maintain a secure environment.
Too often, those goals are treated as opposing forces. You can have security or you can have speed, pick one. But with this new integration, you don’t need to make this tradeoff.
The best systems allow teams to move fast because they're well-designed, not in spite of security controls. When you remove manual steps, reduce cognitive load, and automate the boring stuff, engineers can focus on actually solving problems instead of fighting with tooling.
That's what we're building here. Not just another integration, but a fundamentally better way to handle the intersection of incident response and access control.
The integration is available now for incident.io and Opal customers.
Check out the incident.io documentation and Opal's documentation to get started, or schedule a demo if you want to see it in action first.
About incident.io
incident.io is the all-in-one AI platform for on-call, incident response, and status pages. It's the incident command center built for fast-moving teams.
About Opal Security
Opal is the unified identity security platform that enables organizations to implement least privilege access at scale while maintaining operational efficiency.

Brian Hanson is Head of Channel & Alliances at incident.io, where he leads partnerships and strategic go-to-market efforts to deliver enterprise-grade incident response capabilities. With over a decade of experience building alliances and scaling SaaS growth, Brian is passionate about helping engineering teams eliminate friction, strengthen security and respond to incidents with confidence. He lives at the intersection of product, partner ecosystems and high-impact operations.
Ready for modern incident management? Book a call with one of our experts today.
