Flexible filtering in Insights

August 4, 2026

When filtering on the incidents page, you've always been able to choose between Matches all and Matches any. That second mode is now available in Insights too, so you can express conditions across fields in a single view. For example:

  • "All incidents in scope for the major incident report"Severity is one of [Critical, Major] OR Has external status page = Yes
  • "All incidents for this field, before and after a migration"Impacted product = Payments OR Affected features contains Payments, e.g. where older incidents carry the old value on one field and newer ones the new value on another.

This is available across all our new built-in Insights dashboards, with custom dashboards to follow shortly.

In addition to that, there’s far more filtering options available for incidents: you can now filter on all the properties supported on the incident list page, such as:

  • If a timestamp is set
  • If an incident has follow-ups or a post-mortem
  • If the incident has a public statuspage

Post-incident flow dashboard glow up

The Post-incident flow dashboard in Insights has had a refresh, now with near real-time data and new ways to slice it. Use it to understand how incidents move through your post-incident flow — what proportion complete, opt out, or get stuck — how quickly and reliably tasks like debriefs and post-mortems get done, and where your post-mortems currently sit, from never opened through to completed.

You can now:

  • See what proportion of flows or tasks are complete with a new ratio chart, and compare across custom fields like team
  • Check completion rates by task type, so you can tell whether you're consistently getting a group of tasks (like post-mortems) done
  • Understand how consistently your team is writing and reviewing post-mortem documents

Webhook delivery logs for workflows

We now record every webhook a workflow sends, so you can see exactly what happened and debug any errors you’re experiencing. You'll find this in two places: when you open a specific run in workflow activity, or when you edit a webhook step in the workflow editor.

We keep the full request and response for 7 days, and redact any secrets or Authorization headers.

Scribe and the agent can see in-call chat

Previously, Scribe only listened to what was said on a call, and missed things dropped into the call chat — like a dashboard link.

We now include in-call chat in the transcript, so Scribe can include it in call notes and ‘key moments’ shared in Slack. The agent can also see the chat and use it to answer questions, or investigate your incident.

This works with no additional setup.

Recent escalations alongside escalation paths

When viewing an escalation path, we'll now show its recent escalations on the right-hand side, so it’s easier to understand how a path is being used.

We’ll also show you this information when someone goes to delete the path, so it’s easier to see if something’s relying on a given path before removing it.

Smoother PagerDuty migrations

We've made it easier to import PagerDuty schedules and escalation policies

  • PagerDuty Teams now automatically have members, making them eligible as team types without any changes
  • When switching to a team type that doesn't have an escalation path attribute, we automatically create it
  • When importing escalation policies, we automatically assign owning teams, making alert routes much easier to set up
  • We've added support for the PagerDuty V3 Schedules API, so we can import schedules we previously couldn't

There's also a new in-app guide that points you to next steps once you've connected PagerDuty to help get started

Saved views for alerts on mobile

You can now view your saved views for alerts on mobile. These are view-only on mobile — you can't create new ones there, but any you've built on web are available to open, for both organisation-level and team-level views.

We've also added filtering of alerts by attributes so you can filter by team, feature and more.

Alert pulse channels can group alerts

If you have an alert route with grouping enabled and send messages to Slack or Microsoft Teams, you can now opt into having those pulse messages reflect your alert groups rather than posting each alert individually. The first alert posts as a regular message; when another alert joins the group, we turn it into a group message summarizing the number of alerts and their status.

What else we've shipped

New

New

  • The public API now returns rate-limit headers on all authenticated requests, making specific limits discoverable directly.
  • We’ve added new workflow run endpoints to the public API so you can programatically track if your workflows are running as expected.
  • You can now add permanent members to Slack groups — in the UI, API and Terraform — handy if you want to stay in the loop on everything your on-call team gets paged for.
  • You can now see exactly where an incident was announced, right from the incident homepage, and remove announcements that you don’t want any more.
  • You can now set labels, description, and priority when creating a follow-up with a workflow
  • You can now template the description when exporting follow ups to external issue trackers (such as Jira and Linear)
  • You can now change how components are grouped on a status page with sub pages after it's been created, directly from the Components settings tab.
  • You can now show a "Last updated" column on the incidents list and see it in the incident sidebar, making it easy to check when an incident last changed alongside the Date Updated filter.
  • We've added AI-generated call notes to our MCP integration, so your AI agents can reference what was discussed on incident calls alongside the rest of your incident data.
  • If you ungroup an alert, or list of alerts, and choose to create an incident from them, we'll pre-fill the incident form with an AI suggested incident name, if your alert route has opted into that
Improvements

Improvements

  • Retrospective incidents no longer create a Slack channel by default, and now have a higher rate limit of 300 per key per hour (up from 10), making bulk historical imports much quicker.
  • You can now delete your own call routes, as long as we haven't assigned them a number yet.
  • Insights: expand any chart to fullscreen so x-axis labels don't overlap on busy charts.
  • Insights: search within chart legends to find and select a specific series.
  • Insights: catalog-backed table values like teams and escalation paths are now styled, with info and links on hover.
  • Insights: a new "None" group-by option shows a single ungrouped series.
  • Don't display custom Slack emoji with digit-only names (like :45:) inside timestamps
  • Preserve filters when navigating in catalog
  • You can now type or paste a UTC timestamp directly when adding custom timeline events.
  • You can now filter the incidents list by Link type custom fields, using "is set" or "is blank", handy for tracking which incidents still need a runbook, RCA doc, or other link added.
  • The catalog-importer Docker image is now published as a multi-architecture image, so it runs reliably on ARM nodes (like AWS Graviton) as well as amd64.
  • Retrospective incidents created via the API no longer automatically create a new Slack channel by default. You can link to an existing channel with slack_channel_id, or create one later from the dashboard.
  • We now support scheduled email and Slack policy reports for on-call/vacation overlap and schedule-gap policies
  • Accepting a multi-day cover request that's already partially covered now only takes the remaining uncovered time, instead of overwriting the first responder's accepted partial cover.
  • Alert details pages now display any images attached to an alert (like Grafana panel screenshots) directly on the page, with a full-screen gallery view when you click through. Previously these images only showed up in Slack channel messages, so anyone working alerts without an incident or pulse channel had no way to see them.
  • We've added guidance on avoiding iOS call screening interfering with phone escalation notifications, including how to set up the incident.io contact card with Emergency Bypass.
  • Alerts from Jira now preserve formatting from the ticket into the alert description
Bug

Bug fixes

  • Fixed a bug where re-connecting a Slack Enterprise Grid workspace that had previously been removed
  • Fixed an issue where rewriting or deleting the text a post-mortem comment was anchored to could make the comment disappear without a trace. Detached comments now surface clearly so they can be read and resolved, and edits that don't fully remove the anchored text keep the comment attached.
  • Fixed a bug where the "Missed high urgency escalations" figure in Insights could be inflated for escalations with repeated levels, over-counting missed pages for a single escalation.
  • Fixed a bug where pressing Ctrl+Z to undo an edit in the post-mortem editor would correctly revert the change but also jump the page to the bottom of the document.
  • Fixed a bug where creating a custom field with a "list anyone can add to" would keep showing the "you must supply at least 1 option" error even after options had been added, blocking save.
  • Fixed a bug where two workflows adding the same value to a multi-select custom field at the same time could both succeed, leaving a duplicate entry on the incident.
  • Fixed an issue in the mobile app where it was hard to identify the "Preferences" page button if you had no Slack/Teams avatar image
  • Fixed a bug where the on-call alerts filter chip would show blank when a catalog filter was applied using an alias in the URL, even though the filter was applied correctly. The chip now correctly displays the catalog entry's name.
  • Fixed a bug where accepting a shift swap on an in-hours or partial-day rotation could fail with "the shifts offered to swap have changed," even though both people still held their shifts.
  • Fixed a bug where updating an alert source via the API or Terraform could intermittently fail with a "reference not found in scope" error whenever one expression referenced another inside a branch condition.


So good, you’ll break things on purpose

Ready for modern incident management? Book a call with one of our experts today.

Signup image

We’d love to talk to you about

  • All-in-one incident management
  • Our unmatched speed of deployment
  • Why we’re loved by users and easily adopted
  • How we work for the whole organization