# Dark mode

*October 6, 2026*

It's 3:07am. Your phone buzzes, you squint at your laptop, and incident.io greets you with the brightness of a thousand suns. Oof.

Across the millions of pages we handle for customers, 25% of them land between the hours of 11pm and 8am for the person being paged. Our mobile app supports dark mode but over 70% of the people who would prefer that ocular respite to continue as they head to the web, end up sorely disappointed.

![Breaking news: people opening a browser at night prefer dark mode. Shocker.](https://cdn.sanity.io/images/oqy5aexb/production/b2ffbe990f56834cf87bef03af107e4a9f60b290-1353x504.png)

Up until today, it’s been a notable omission. In fact, over half of users of our web dashboard browse in dark mode. We’ve had plenty of requests for it and we’re also acutely aware that both your eyes and browser preferences have been implicitly filing this feature request for years. 

Well, it’s finally here: [incident.io](http://incident.io)’s dashboard is now available in dark mode!

![](https://cdn.sanity.io/images/oqy5aexb/production/0ba6adeb5a12774899ab8683c8ca8fc015ff99fd-1500x824.png)

Dark mode is currently in beta. To switch it on, open the command palette with ⌘K and search for "dark mode", or [head to your user preferences](https://app.incident.io/~/user-preferences/account). While this is still in beta, you may spot the odd thing that doesn't look quite right. If you do, let us know by sending feedback through ⌘K.

![](https://cdn.sanity.io/images/oqy5aexb/production/eae8dc8e575d4d2db4e4d4a1e4264e9031324a4f-1500x824.png)

## On-call

### Pausing on-call notifications

Whenever you're going on holiday or on leave you can request cover for any on-call shifts you have or remove yourself from a schedule. However this wouldn't prevent you from getting paged. If you're on a schedule you might still be paged if an escalation path pages everyone on that schedule, or if you aren't, you can still be paged by someone manually escalating to you. This isn't ideal, so users have had to find some creative ways to avoid getting paged (e.g. turning off your phone completely, removing the app from your device).

So we’ve added a way for users to pause their on-call notifications. You can go into your user preferences and schedule a pause either by choosing a future holiday that you want your notifications paused for or by choosing your own date and times. Or manage them fully via the MCP and the incident agent. Once your notifications are paused we'll:

* Prevent users from manually escalating to you,
* Skip you when we try to page you from an escalation path and notify the next person.

![](https://cdn.sanity.io/images/oqy5aexb/production/18739782392b82bf91fffada90a121886675b14c-1500x824.png)

You'll be able to see in schedules which users have their notifications paused and for when, and if you have the 24/7 coverage policy enabled we'll count a user that is on-call with their notifications paused as a gap in the schedule and notify someone about it.

Everyone can manage their own pauses by default, but organizations can turn off permissions by removing the `Pause own notifications` permission. Owners have a permission to manage pauses for other users in the case that someone needs to have their notifications resumed.

See docs [here](https://docs.incident.io/on-call/pausing-notifications).

### Shift conflict policy

We have a new policy that customers can use to notify themselves of overlapping shifts in their on-call schedules! This is great for folks that want to avoid having someone on call for both a primary and secondary rotation at the same time, for example.

![](https://cdn.sanity.io/images/oqy5aexb/production/785634347274e3d44395631f9303272ad25e8eda-1500x824.png)

The policy identifies when a user is on two or more schedules or rotations in the same time window. Users can resolve conflicts via the multiple schedules page by asking for cover or creating overrides.

Users will get warnings when creating or editing overrides, accepting cover requests, and swapping shifts if they will cause any of these shift conflicts. Users will also be notified if one of their conflicts worsens.

See the help docs [here](https://docs.incident.io/on-call/shift-conflict-policies).

### Configurable alert pulse message actions

You can now configure what actions appear on your alert pulse messages in both Slack and Microsoft Teams. So, if you have a preference on what shows up (or doesn’t) you can now customize to your organization’s needs.

![](https://cdn.sanity.io/images/oqy5aexb/production/574639967ce63e0a987215b74c53176a65df1b3e-1500x824.png)

### Alert rate limit notifications

Customers can now enable notifications for when their alerts get rate limited. Sometimes organizations can hit rate limits during large outages and have been caught by surprise. Now, with notifications you can get clear signal when events have been dropped or throttled.



Notifications can be enabled in Settings and can be sent by email to owners and admins or to a Slack or Teams channel. Plus, you can ignore any particularly noisy alert sources to avoid useless notifications.

## Investigations

### Auto-run conditions can be re-evaluated when incidents are updated

Previously if you had conditional auto-run configuration for Investigations, we would evaluate the condition once, when the incident is declared; if the incident didn’t match your conditions, an investigation wouldn’t run.

![](https://cdn.sanity.io/images/oqy5aexb/production/36c58a0e15dd81fc986071fee302d40691f67887-1500x824.png)

Some organizations want to only run on incidents which have their severity set to, for example, Major or Critical, but this may only happen after declaration. Now we’ll start the investigation as soon as the conditions match.

## Nexus

### Zendesk Help Center is now a Nexus document source

For organizations that store engineering documentation and runbooks in an internal-facing Zendesk knowledge base, they can now connect those to Nexus so that they can be read by Investigations and our agent.

![](https://cdn.sanity.io/images/oqy5aexb/production/83edbb252d0bfe38bfa905c2c98c6e8611d9ff14-1362x824.png)

We support adding whole sections of the help center or individual pages by URL.

## Response

### Video recording of incident calls with Scribe

We've just enabled a small addition to Scribe to make video recordings of your incident calls possible by opting-in via Settings.

Users can download call recordings within an incident's call notes shortly after a call has ended. Recordings are deleted when call notes are deleted, either manually or according to any call notes data retention policy enabled.

![](https://cdn.sanity.io/images/oqy5aexb/production/b616edd1e5fe8240048275418ceb4d467be8fe5d-1500x824.png)

This will only be available when Scribe is in the call, and transcripts are available. See full docs [here](https://docs.incident.io/ai/scribe).

### "Open in app" on both desktop and mobile

When we first shipped the Desktop app we added a "Pin to desktop" link in the catch-up message we post when you first join the channel. This opens that incident to the desktop app allowing you to see updates, begin debugging.

But what if you're viewing the incident in Slack on your phone? Well now you can simply click the same button and go straight to the incident and investigation inside the mobile app!

![](https://cdn.sanity.io/images/oqy5aexb/production/7509270502fb2a00f90c790ecae9887d9c7b1324-1191x608.png)

The same thing works in Microsoft Teams - there’s now an “Open in app” button on the investigation summary.

### Follow-up categorization

Admins can now define categories of follow-ups within Settings (e.g. detection, prevention). These categories are presented in the dashboard, and the follow-ups node of a post-mortem document.

![](https://cdn.sanity.io/images/oqy5aexb/production/c9f19186aa038f1b3e2cd66b84ac5e6b40d93a2d-1500x824.png)

This allows organizations to nudge responders about particular categories when creating follow-ups (e.g. how could we have detected this faster), and supports more flexible routing (e.g. to export follow-ups to different teams or issue trackers).

## Platform

### New SDKs

We’ve built out a whole slew of SDKs for you to leverage. Check out:

* Pulumi ([Official registry](https://www.pulumi.com/registry/packages/incident/), [GitHub repo](https://github.com/incident-io/pulumi-incident/))
* Rust SDK (Published to [crates.io](https://crates.io/crates/incident-io), [GitHub repo](https://github.com/incident-io/sdk-ruby))
* Python SDK (Published to [PyPi](https://pypi.org/project/incident-io/), [GitHub repo](https://github.com/incident-io/sdk-python))
* PHP SDK (Published to [Packagist](https://packagist.org/packages/incident-io/sdk-php), [GitHub repo](https://github.com/incident-io/sdk-php))
* TypeScript SDK (Published to [NPM](https://www.npmjs.com/package/@incident-io/sdk), [GitHub repo](https://github.com/incident-io/sdk-ts))
* Ruby SDK (Pubished to [RubyGems](https://rubygems.org/gems/incident_io_api), [GitHub repo](https://github.com/incident-io/sdk-ruby))
* .NET SDK (Published to [Nuget](https://www.nuget.org/packages/IncidentIo), [GitHub repo](https://github.com/incident-io/sdk-net))

### Ask the agent for a chart

You can now ask the agent for a graph in chat, and it replies with a real Insights chart as an image!

Some things to note:

* You can narrow it down: for example "missed high-urgency escalations, split by team" keeps the urgency filter.
* You can ask the agent for any any Insights chart, or it’ll build you a custom one for you.
* Charts only count public incidents. If a preset normally includes private incidents, the agent will say that it has removed them.

![](https://cdn.sanity.io/images/oqy5aexb/production/4861aa935ced10eb2f953b467b21435e60f18a47-1332x824.png)

### Custom color palettes in Insights

You can now set your own color palettes for Insights charts, for the whole organization or for one chart. New functionality includes:

* Organization palettes: create named palettes in Settings → Organization and pick a default. Charts on custom dashboards and in scheduled reports then use your palette automatically.
* A default for each type of chart: set different defaults for categorical, sequential (e.g. severity) and diverging charts.
* Per-chart palettes: choose a palette for one chart in the panel editor. You can use one of your organization's palettes or one of ours. If nothing fits, create a new palette from the picker and the chart uses it immediately.
* Color-blind friendly: new red-green friendly and blue-yellow friendly palettes.

![](https://cdn.sanity.io/images/oqy5aexb/production/32b3ca785e2fde41bc70ca8b7347d5faa017de6f-1332x824.png)

### Slack's latest agent API

Slack have introduced a new Agent API for apps and we have migrated to it.

Now when talking to the app you have a single place for your conversations (no history tab and annoying notifications pointing you to the wrong place). As before you can chat to the agent via the agent button (top right) in a split view, or as before when DM'ing the bot.

We now support navigating around Slack channels and the Agent will now know which channel you are looking at - this is helpful when dipping in and out of several incidents.

## What else we've shipped

## New
* [on-call] Alert and alert group timelines are now available in the mobile app.
* [on-call] See who's on holiday when requesting cover on mobile.
* [on-call] Expressions are now aware of who's on-call for a rotation, so customers can set up workflows that use this. For example: Assigning whoever is on-call for the "Tech Lead" rota to be automatically assigned as incident lead.
* [response] You can now choose whether SMS subscription updates include the incident call link, with a new organization-level setting to leave it out.
* [response] When subscribing to incident updates, you can now toggle whether you want to include the incident call URL.
* [response] You can now edit a posted incident update from the mobile app.
* [response] If you use an emoji to auto-create a follow-up, we'll now use the agent to look at the context of the channel and write a good ticket, similar to if you said `@incident make a followup from this message`
* [response] Create incident from escalation in the mobile app.
* [response] Resolve incidents in bulk from the mobile app.
* [platform] Long-press the app icon and jump straight to what you need. Raise an incident, escalate to someone or request cover without ever touching the home screen.
* [platform] JavaScript expressions now support ES6.
* [platform] You can now opt in, from Settings → Organization, to show users' verified on-call phone numbers on their User catalog entries. This lets you look up who to call, including by asking @incident in Slack.
* [platform] You can now search for custom fields in the dashboard.
* [platform] You can now add items to a glossary (via the [Dashboard](https://app.incident.io/~/settings/glossary) or the MCP) which helps our agent understand your organization's context.

## Improvements
* [on-call] Incident updates and alert updates in the mobile app now appear as a timeline that shows absolute times, so you can see exactly when something happened instead of doing the math on "6h ago."
* [on-call] SMS notifications to Ethiopia now send from the registered "[incident.io](http://incident.io)" sender ID, so messages keep arriving ahead of Ethio Telecom blocking unregistered senders. Replying to these messages by SMS isn't supported.
* [on-call] You can now add and verify Kosovo (+383) phone numbers from the [incident.io](http://incident.io) mobile app, and Kosovo is listed in our supported countries for on-call notifications.
* [response] When you ask the AI agent to create a follow-up or action, it now replies with the link so you can click through to see exactly what was created and edit it straight away.
* [response] Incident overviews on mobile got a bit of polish to be easier to consume.
* [response] The [incident.io](http://incident.io) agent can now reopen a closed incident when you ask, matching what you can already do with /inc update, the dashboard, and the API.
* [response] The catalog importer Docker image now runs as a non-root user by default, so it works with stricter container security policies.
* [response] The MTTX insights dashboard now lists every configured metric in its pickers. Metrics with no data in the selected date range or filters are greyed out with a tooltip, so newly added metrics no longer look like they're missing.
* [investigations] The Grafana connection check now warns you when the image renderer isn't available, so you know dashboard screenshots won't be included in investigations. The warning is advisory and doesn't affect your connection.
* [investigations] Self-hosted GitLab setup now makes it clear that code access should be routed through a proxy, and GitHub Enterprise Server connections now require one. This avoids connectivity errors when investigations access your repositories.
* [investigations] Investigation auto-run can now be evaluated on incident updates, not just at creation. Investigations start once an incident later matches your conditions, such as when severity is set during triage, and still run at most once.
* [investigations] The incident agent now recognizes when you have only one connected repository and uses it, instead of asking which repository to inspect.
* [investigations] Searching for a dashboard to add now also shows dashboards you've already added, marked as already added, so a search no longer looks like it came up empty.
* [status-pages] We've clarified the status page history window setting. It's now labeled "History window size" and explains that it controls how many days of system status and history show at once on your public page.
* [platform] We are about 3x as fast in both the dashboard and in Slack experiences with the incident agent.

## Bug fixes
* [on-call] Fixed an issue on Android where a new escalation page could show the previous alert's details with no alarm sound after you dismissed the full-screen alarm. New pages now display the correct alert and play the sound.
* [on-call] Fixed an issue where acknowledging a page from the full-screen alarm notification on Android could fail, letting the escalation continue to the next level. The Android app now waits for a connection and allows more time and retries, so acknowledgements land far more reliably.
* [on-call] Fixed an issue where long attribute names on the alert details page overflowed into their values. Names now wrap within the label column, and text values line up with their labels.
* [on-call] Fixed an issue where advanced parsing on email alert sources could intermittently fail to apply, causing resolve emails to create new alerts instead of resolving existing ones. Email transforms now retry if they don't parse on the first attempt.
* [on-call] Fixed an issue where the holiday calendars settings on a schedule prompted you to connect HR software even when an HRIS like HiBob or BambooHR was already connected.
* [on-call] Fixed an issue where an archived team that owned a schedule or workflow couldn't be removed. The "Owned by" picker now shows archived owners as checked rows, so you can untick them.
* [on-call] Fixed an issue where creating an escalation path with Terraform failed with a 403 error when using an API key with team-scoped permissions for the owning team.
* [on-call] Fixed an issue where alert images, such as Datadog and Grafana charts, were missing from Slack escalation notifications even with the Images toggle enabled.
* [on-call] Fixed an issue where Slack alert messages could still show "Create or attach incident" after the alert had been grouped into an existing incident.
* [on-call] Fixed an issue where the AI assistant could describe an on-call override that had already ended as a normal rotation shift. It now recognizes past overrides and can tell you who created them.
* [on-call] Fixed an issue where incidents created from alerts rerouted at the end of a maintenance window could keep their placeholder name instead of getting an AI-generated one.
* [on-call] Fixed an issue where alert requests deduplicated into an already-firing alert weren't linked to that alert, making them look like dropped alerts. They now link to the existing alert.
* [on-call] Fixed an issue where team members couldn't see private alerts, incidents or escalations shared with their team when the team's members attribute was derived from a catalog backlink.
* [on-call] Fixed an issue where the DND column in the On-call readiness mobile install breakdown showed red for Android devices on recent app versions that can already page through Do Not Disturb.
* [on-call] Fixed an issue where the incident preview on an alert route didn't update when you switched between incident templates.
* [on-call] Fixed an issue where alert source attributes built with an if/else expression couldn't be saved after choosing "Plain text (single line)" as the return type. Return types that can't be saved are no longer offered.
* [on-call] Fixed an issue where creating an alert route in Terraform with an empty owning_team_ids list failed with an "inconsistent result after apply" error. Upgrade to provider v7.1.1 or v6.13.1 to get the fix.
* [on-call] Fixed an issue where escalation paths couldn't be saved when a round-robin level was set to wait until working hours begin or end.
* [on-call] Fixed an issue where incident templates set a Text custom field to an empty string when its First wins or Last wins expression resolved to nothing. The field now stays unset.
* [on-call] Fixed an issue where the next and previous arrows in the schedule editor preview kept scrolling through days instead of moving once. Each click now moves the preview a single step.
* [on-call] Fixed an issue where pressing + on a payload key after choosing to create a new alert attribute crashed the page.
* [on-call] Fixed an issue where renamed PagerDuty, Opsgenie, and Splunk services kept showing their old names in Insights filters and new escalation timeline items. Current names now come from the catalog.
* [on-call] Fixed an issue where the Terraform provider rejected escalation paths with a repeat followed by a reassignment to another escalation path, even though the API and dashboard allow it.
* [on-call] Fixed an issue where alert filters could show the name of a deleted catalog entry instead of the live entry sharing the same identifier.
* [on-call] Fixed an issue where escalation paths didn't appear when reassigning an escalation if your Escalate form had no escalation path element.
* [on-call] Fixed an issue where the Android app's schedule calendar could hide a shift when two schedules handed over at the same time.
* [on-call] Fixed an issue where some PagerDuty v3 schedules, such as those with weekend shifts spanning multiple days or weekday-only rotations, couldn't be imported and were flagged as unverifiable.
* [on-call] Fixed an issue where Jira alert sources connected via OAuth could silently stop receiving alerts because their webhooks weren't refreshed before expiring.
* [on-call] Fixed an issue where closing an incident with an adopted Jira alert ticket created a new alert from our own update to the ticket, which could page your team again later.
* [on-call] Fixed an issue where the Escalate modal in Slack showed only a handful of services before you searched. It now lists up to 50 services you can scroll through.
* [on-call] Fixed an issue where an alert route API or Terraform config could set escalation targets with a single value, which was accepted but never paged anyone. The API now returns a clear 422 and asks you to use array_value instead.
* [on-call] Fixed an issue where creating a policy through the API when you've hit your plan's policy limit returned a 500 error. It now returns a clear 422 explaining the limit, so tools like Terraform stop retrying and show the reason.
* [on-call] Fixed an issue where the schedule view could cut short or hide leave when two back-to-back time-off bookings synced from your HRIS shared the same label.
* [response] Fixed an issue where connecting privileged Slack access on Slack Enterprise Grid requested an org-level install and failed with a confusing Slack error. Connect now requests the right token for the user going through the flow.
* [response] Stopped the [incident.io](http://incident.io) agent posting a redundant message after a suggestion card in Slack threads. The card now appears on its own, with no duplicate reply.
* [response] Fixed an issue where a confusing "do you want us to continue with this request?" message could appear in the incident channel when someone posted an update just before a suggested update was sent.
* [response] Fixed an issue where the Save button stayed disabled after your first edit to a custom channel name format on an incident type.
* [response] Fixed an issue where you couldn't turn off "Task is required" on tasks in a post-incident flow created from an existing flow. Server errors on the task form are now shown instead of Save silently doing nothing.
* [response] Fixed an issue where exporting a follow-up to a Jira Server project with many custom fields timed out. We now fetch the project's create screen configuration once per export instead of once per field.
* [response] Fixed an issue where the incident name field in the Slack /inc close form lost focus when you paused typing.
* [response] Fixed an issue where you couldn't edit or clear a custom field value on an incident if the field's conditions no longer applied, such as a value pointing at an archived catalog entry. Fields with a stored value are now always editable.
* [response] Fixed an issue where the post-mortems list showed a misleading total that only counted the loaded page. The total is now hidden rather than shown incorrectly.
* [response] Fixed an issue where Terraform exported from a workflow that merges values with a concatenate operation failed to apply with a 422 error. The export now includes the concatenate block and requires provider v6.9.0 or later.
* [response] Fixed an issue where bulleted or numbered lists inside a quote block appeared as an empty quote bar in Slack incident updates. Lists now render within the quote.
* [response] Fixed an issue where long timelines in exported post-mortem PDFs overlapped the page footer and left blank pages. Timeline tables now flow cleanly across pages.
* [response] Fixed an issue where exported post-mortems showed outdated timestamps and durations after an incident's timestamps were edited. Exports now use the incident's current values.
* [response] Fixed an issue where a user created via SCIM could stay unlinked from their Slack account if a deactivated user still held that Slack ID. Slack sync now moves the link to the active user.
* [response] Fixed an issue where Cortex custom entities couldn't be added as fields on escalation forms, which caused the Create field drawer to fail with an error.
* [response] Fixed an issue where parsing a value into a catalog entry could match an entry by name instead of the intended external ID, routing alerts to the wrong team. Matching now prefers external ID, then alias, then name, and live entries over archived ones.
* [response] Fixed an issue where creating a policy could intermittently crash the page when adding a Query expression.
* [response] Fixed an issue where the same person could appear as two Cortex users, leaving one copy without a linked [incident.io](http://incident.io) user and missing from their teams.
* [response] Fixed an issue where filtering incidents by a catalog attribute on a role or participant could switch to a different catalog type that shared the same attribute name.
* [response] Fixed an issue where the hover pop-up on the Time spent on incidents dashboard hid the durations when an incident had a long title. Long titles now wrap so the numbers stay visible.
* [response] Fixed an issue where debrief invite posts in Slack could show an attendee as a raw Slack ID ending in "-deduplicated" instead of a mention, caused by matching calendar attendees to deactivated users.
* [response] Fixed an issue where Scribe's final takeaways for a postmortem session could be overwritten by a delayed update after the session ended.
* [response] Fixed an issue where the Jira Cloud Label catalog dropped most labels from one site when multiple Jira sites were connected. Labels from all connected sites now sync.
* [response] Fixed an issue where the Slack user sync could wrongly deactivate users in Slack Enterprise Grid organizations, resetting their roles (such as Owner or Admin) to the standard User role.
* [response] Fixed an issue where users without the "Update incident fields" or "Manage incident lifecycle" permissions couldn't fill in the name and type fields when creating a retrospective incident.
* [response] Fixed an issue where a Jira integration that lost access (for example, after access was removed in Jira) appeared as uninstalled. It now shows as having a connection problem that needs reconnecting.
* [response] Fixed an issue where the GitHub pull request card in an incident channel kept showing the old title after the PR was renamed. The card now updates to the new title.
* [response] Fixed an issue where rich text attributes didn't appear in the condition picker. You can now use "is set" and "is not set" style conditions on them in workflows.
* [response] Fixed an issue where attaching a closed Zendesk ticket to an incident marked the whole Zendesk integration as disconnected.
* [response] Fixed an issue where the /inc command in Slack ignored your declare form's default of Triage and preselected Active incident instead.
* [response] Fixed an issue where adding a query expression to a rich-text field in a workflow step, such as a Slack message, saved the expression but left the drawer open and didn't insert the variable.
* [investigations] Fixed an issue where the AI assistant stayed silent when someone asked it a direct follow-up question in an investigation heads-up thread in Slack. It now replies to those questions without needing an @ mention.
* [investigations] Fixed an issue where investigations kept trying to clone repositories from a GitHub installation that had been removed, causing them to fail. Investigations now skip repositories they can no longer access.
* [investigations] Fixed an issue where investigation Slack messages could include internal implementation details, such as how checks are run or raw provider error names. Messages now stick to what's relevant to your incident.
* [investigations] Fixed an issue where auto-run investigations with a severity condition never started if severity was set after the incident was created.
* [investigations] Fixed an issue where users without the "View telemetry" permission saw a permission error toast on every page load.
* [investigations] Fixed an issue where AI investigations could include citations pointing to identifiers that don't exist. Invented references are now rejected before they reach investigation output.
* [investigations] Fixed an issue where repositories could be wrongly removed from Investigations when you connect multiple GitHub accounts to [incident.io](http://incident.io).
* [status-pages] Fixed an issue where "Request an update" on an internal status page incident failed silently when the linked incident had no Slack or Teams channel. The button is now hidden in that case, and any remaining errors show a clear message.
* [status-pages] Fixed an issue where workflow expressions in a status page step's Resolved message showed as "(not set)" when the incident closed. The expression's value now appears in the published update.
* [status-pages] Fixed an issue where scrolling down a status page could run past the footer into a blank white screen.
* [status-pages] Fixed an issue where the incident summary, affected component names, and lead name on internal status pages were near-black and unreadable in the dark theme.
* [platform] Fixed an issue where creating a follow-up from a ticket URL through the MCP server failed with an unhelpful internal error when authenticating with an API key.

## Blog posts
- [Building Investigations: what it takes to build an AI SRE](https://incident.io/blog/building-investigations-what-it-takes-to-build-an-ai-sre)