AtlasWork, planned itself.

The AI-native, all-in-one work platform. Tasks, projects, CRM, contracts, and analytics in one calm workspace.

All systems operational
  • SOC 2 II
  • ISO 27001
  • HIPAA
  • GDPR

Product

  • Overview
  • PDF tools
  • Diagram tools
  • People & HR
  • Integrations
  • Marketplace
  • Pricing

Resources

  • Guides
  • Glossary
  • Compare
  • Docs
  • API reference
  • Support
  • Changelog
  • Status

Company

  • About
  • Careers
  • Press
  • Contact

Legal & trust

  • Trust center
  • Security
  • Privacy
  • Terms
  • DPA
  • GDPR
  • SLA
  • Refunds
  • Google API data
Atlas, a product by wrxstack.com·© 2026 wrxstack·All rights reserved
PrivacyTermsSecurityStatus
Skip to documentation
Docs
Back to Atlas

Start here

  • Overview

Developer

  • REST API guide
  • Authentication
  • API reference
  • MCP (AI agents)
  • MCP tools reference
  • SDKs
  • Quick actions
  • Changelog

Webhooks

  • Overview
  • Quickstart
  • Events
  • Payloads and headers
  • Security and signing
  • Delivery and retries
  • Managing via API

Connect

  • Connectors
  • Integrations

Product

  • Collaboration and chat

Reference

  • Glossary
  • Keyboard shortcuts
  • Module reference

Tools reference

Service operations

Every Service operations tool, with the scope it needs, its arguments and the API operation it calls.

All areasTasksProjectsPortfoliosBoardsGoalsHabitsCommentsTime trackingWorkloadCRMGrowth suiteContractseSignPDF StudioFormsCalendarBookingMeetingsChatHuddlesWikiDocumentationDiagramsWhiteboardsHRPayrollClient deliveryClient onboardingService operationsStatus pageAutomationsAgentsAIReportsInsightsConnectorsNotificationsSearchWorkspace administrationAccessGovernancePrivacyBillingWebhooksAccess tokensMy accountFocusChangelogBlogTrashThemesEmail templatesMetadataCustom fieldsWalkthroughsVoiceActivityServer

65 tools

Convert service action items

Changes data

atlas_service_action_items_convert

File an incident review action item as a real task in a project, so it is tracked with the rest of the work. Calling it again returns the task already filed rather than a duplicate. Returns the action item, the task id and whether the task was created now.

Scope
service:write
Calls
POST /v1/service-ops/action-items/{actionItemId}/convert-to-task
Example prompt
File the canary deploy action item as a task in the Platform project.

Arguments

FieldTypeRequiredDescription
idstringYesThe action item id.
projectIdstringNoThe project to file the task in. Omit to use the default.

List service action items

Read only

atlas_service_action_items_list

Follow-up work from incident reviews. Use overdueOnly to answer "what did we promise to fix and have not".

Scope
service:read
Calls
GET /v1/service-ops/action-items
Example prompt
What did we promise to fix and have not?

Arguments

FieldTypeRequiredDescription
status"PROPOSED" | "ACCEPTED" | "IN_PROGRESS" | "DONE" | "DROPPED"No
ownerUserIdstringNo
overdueOnlybooleanNoOnly work that is past its due date.
limitintegerNo

Update service action items

Changes data

atlas_service_action_items_update

Update an action item from an incident review: its title, description, kind, status, owner or due date. Use this to mark one done, reassign it, or drop it with a reason. Returns the action item.

Scope
service:write
Calls
PATCH /v1/service-ops/action-items/{actionItemId}
Example prompt
Mark the canary deploy action item done.

Arguments

FieldTypeRequiredDescription
idstringYesThe action item id.
titlestringNoA new title.
descriptionstringNoA new description.
kind"PREVENT" | "DETECT" | "MITIGATE" | "PROCESS" | "DOCUMENTATION"NoWhat the action does about the failure.
status"PROPOSED" | "ACCEPTED" | "IN_PROGRESS" | "DONE" | "DROPPED"NoThe new status. DROPPED should come with droppedReason.
ownerUserIdstring | nullNoThe owner. Null unassigns it.
dueAtstring (date-time) | nullNoISO-8601 due date. Null clears it.
droppedReasonstringNoWhy the action is being dropped.

Delete service alert sources

Destructive

atlas_service_alert_sources_delete

Delete an alert source, so the monitoring system behind it can no longer declare incidents. The alerts it already sent stay in incident history. Administrators only. Returns a confirmation.

Scope
service:write
Calls
DELETE /v1/service-ops/alert-sources/{sourceId}
Example prompt
Delete the old Pingdom alert source.

Arguments

FieldTypeRequiredDescription
idstringYesThe alert source id, from atlas_service_alert_sources_list.

List service alert sources

Read only

atlas_service_alert_sources_list

The outside systems allowed to raise alerts in this workspace, with the severity and service each one defaults to and whether it declares or resolves incidents on its own. The signing secret is never included, here or anywhere else: it is shown once when the source is created and is not readable afterwards. Read only, and creating or rotating a source is not offered at all, because a credential belongs to a person.

Scope
service:read
Calls
GET /v1/service-ops/alert-sources
Example prompt
Which systems can raise alerts in this workspace?

Arguments

This tool takes no arguments.

Update service alert sources

Changes data

atlas_service_alert_sources_update

Change how an alert source behaves: its name, default severity and service, whether its alerts declare or resolve incidents on their own, and whether it is active. The signing secret is neither returned nor changed. Administrators only. Returns the source.

Scope
service:write
Calls
PATCH /v1/service-ops/alert-sources/{sourceId}
Example prompt
Stop the Datadog alert source from declaring incidents on its own.

Arguments

FieldTypeRequiredDescription
idstringYesThe alert source id, from atlas_service_alert_sources_list.
namestringNoA new name.
defaultSeverityKeystring | nullNoThe severity an alert declares at when it names none. Null clears it.
defaultServiceIdstring | nullNoThe service an alert is filed against when it names none.
autoDeclarebooleanNoWhether an alert declares an incident on its own.
autoResolvebooleanNoWhether a recovery alert resolves the incident on its own. Closing an unverified incident is a risk.
isActivebooleanNoWhether the source accepts alerts.

Cancel service customer updates

Destructive

atlas_service_customer_updates_cancel

Withdraw a customer update that has not been sent, with an optional reason. The draft is kept for the record. Returns the cancelled update.

Scope
service:write
Calls
POST /v1/service-ops/customer-updates/{updateId}/cancel
Example prompt
Withdraw the customer update draft, it is out of date.

Arguments

FieldTypeRequiredDescription
idstringYesThe customer update id.
reasonstringNoWhy the update is withdrawn.

Update service customer updates

Changes data

atlas_service_customer_updates_update

Edit a customer update that has not been sent: its subject, body or recipients. Returns the updated draft. An update that has been sent cannot be edited.

Scope
service:write
Calls
PATCH /v1/service-ops/customer-updates/{updateId}
Example prompt
Change the draft update to say a fix is rolling out.

Arguments

FieldTypeRequiredDescription
idstringYesThe customer update id.
subjectstringNoA new subject line.
bodystringNoA new message body.
affectedPartyIdsarray of stringNoA new recipient list.

List service escalation policies

Read only

atlas_service_escalation_policies_list

The escalation ladders this workspace has configured, each with its steps in order, how long each step waits before the next one fires, and who every step pages. Use this to answer "what happens if nobody acknowledges". Read only: a policy decides whose phone rings at three in the morning, so editing one belongs to a person who can see the whole ladder.

Scope
service:read
Calls
GET /v1/service-ops/escalation-policies
Example prompt
What happens if nobody acknowledges a page?

Arguments

This tool takes no arguments.

Simulate service escalation policies

Changes data

atlas_service_escalation_policies_simulate

Ask an escalation ladder who it would page at a given instant, without paging anybody. Answers, rung by rung, how far into an incident it fires, who it reaches by then, and which of its targets resolve to nobody at all because a rotation is empty or a team has no members. Says plainly when no rung reaches anybody, so only the workspace fallback responders would. Read only despite being a POST: nothing is paged, no escalation run is started and nothing is recorded. Pass an out-of-hours instant, because a ladder that looks healthy on a Tuesday afternoon is not evidence about Sunday at 3am.

Scope
service:read
Calls
POST /v1/service-ops/escalation-policies/{policyId}/simulate
Example prompt
Who would the platform ladder page at 3am on a Sunday?

Arguments

FieldTypeRequiredDescription
policyIdstringYesEscalation policy id.
atstring (date-time)NoThe instant to ask about. Defaults to now. Try an out-of-hours instant.

Acknowledge service incidents

Changes data

atlas_service_incidents_acknowledge

Acknowledge an incident on behalf of the caller, which stops the escalation policy paging the next person. Returns the updated incident. Use this when somebody has picked the incident up.

Scope
service:write
Calls
POST /v1/service-ops/incidents/{incidentId}/acknowledge
Example prompt
Acknowledge the checkout incident, I am on it.

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.

Add service incidents affected customers

Changes data

atlas_service_incidents_affected_customers_add

Record a customer affected by an incident, either a CRM account or a client onboarding, with an optional note on how they are affected. Affected customers are who a customer update is addressed to. Returns the affected party.

Scope
service:write
Calls
POST /v1/service-ops/incidents/{incidentId}/affected-parties
Example prompt
Add Acme Corp to the customers affected by INC-42.

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.
kind"ACCOUNT" | "ONBOARDING"YesACCOUNT for a CRM account, ONBOARDING for a client onboarding.
refIdstringYesThe account id or client onboarding id.
impactNotestringNoHow this customer is affected.

List service incidents affected customers

Read only

atlas_service_incidents_affected_customers_list

Which customers an incident affects, and whether anything has reached them yet. Read only: adding a customer to an incident, and anything that sends them a message, belong to a person.

Scope
service:read
Calls
GET /v1/service-ops/incidents/{incidentId}/affected-parties
Example prompt
Which customers does INC-104 affect, and have they been told?

Arguments

FieldTypeRequiredDescription
idstringYesIncident id.

Remove service incidents affected customers

Destructive

atlas_service_incidents_affected_customers_remove

Remove a customer from the affected list of an incident, when they were added by mistake or turn out not to be affected. Returns a confirmation.

Scope
service:write
Calls
DELETE /v1/service-ops/incidents/{incidentId}/affected-parties/{partyId}
Example prompt
Acme was not affected after all, take them off INC-42.

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.
partyIdstringYesThe affected party id, from atlas_service_incidents_affected_customers_list.

Delete service incidents attachments

Destructive

atlas_service_incidents_attachments_delete

Delete a file attached to an incident. The file is removed from the incident and its stored copy is purged. Returns nothing on success.

Scope
attachments:write
Calls
DELETE /service-ops/incidents/{incidentId}/attachments/{attachmentId}
Example prompt
Delete the wrong screenshot from INC-42.

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.
attachmentIdstringYesThe attachment id.

Download service incidents attachments

Read only

atlas_service_incidents_attachments_download

Get a short-lived signed URL to download one file attached to an incident. Returns the URL and when it expires.

Scope
attachments:read
Calls
GET /service-ops/incidents/{incidentId}/attachments/{attachmentId}/download
Example prompt
Get me a download link for the screenshot on INC-42.

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.
attachmentIdstringYesThe attachment id.

List service incidents attachments

Read only

atlas_service_incidents_attachments_list

List the files attached to an incident, such as logs, screenshots and exported traces, with their names, sizes and types. Also returns what the storage accepts. Use atlas_service_incidents_attachments_download for a link to one file.

Scope
attachments:read
Calls
GET /service-ops/incidents/{incidentId}/attachments
Example prompt
What files are attached to INC-42?

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.

Finalize service incidents attachments upload

Changes data

atlas_service_incidents_attachments_upload_finalize

Complete an incident file upload after the bytes have been sent to the signed URL. The stored object is checked against the declared size and type before the attachment becomes visible. Returns the attachment.

Scope
attachments:write
Calls
POST /service-ops/incidents/{incidentId}/attachments/{attachmentId}/finalize
Example prompt
Finish attaching the trace log to INC-42.

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.
attachmentIdstringYesThe attachment id.
actualSizeBytesintegerYesThe size actually uploaded, in bytes.
actualContentTypestringYesThe MIME type actually uploaded.

Start service incidents attachments upload

Changes data

atlas_service_incidents_attachments_upload_start

Begin attaching a file to an incident. Returns an attachment id, a signed upload URL, the method and headers to use, and when the URL expires. Upload the bytes to that URL, then call atlas_service_incidents_attachments_upload_finalize.

Scope
attachments:write
Calls
POST /service-ops/incidents/{incidentId}/attachments/ticket
Example prompt
Attach this trace log to INC-42.

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.
namestringYesThe file name.
contentTypestringYesThe MIME type, for example application/pdf.
sizeBytesintegerYesThe file size in bytes.

Create service incidents comments

Changes data

atlas_service_incidents_comments_create

Post a comment on an incident, or a reply when parentCommentId is given. Returns the comment. Use atlas_service_incidents_updates_create instead for a formal status update that belongs in the incident narrative.

Scope
comments:write
Calls
POST /service-ops/incidents/{incidentId}/comments
Example prompt
Comment on INC-42 that we are rolling back.

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.
bodystringYesThe comment text.
parentCommentIdstringNoThe comment this replies to.

List service incidents comments

Read only

atlas_service_incidents_comments_list

List the comment thread on an incident, oldest first, with keyset pagination. Returns items and nextCursor; follow nextCursor until it is null. Use this for the discussion around an incident, as distinct from its formal status updates.

Scope
comments:read
Calls
GET /service-ops/incidents/{incidentId}/comments
Example prompt
What has the team been saying on INC-42?

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.
cursorstringNoThe cursor from a previous page.
limitintegerNoPage size, 1 to 200. Defaults to 100.

Create service incidents

Changes data

atlas_service_incidents_create

Declare an incident. Safe to retry when an idempotencyKey is supplied. Whoever declares holds the incident commander role until somebody takes it deliberately. Declaring early and standing down costs nothing; hesitating does.

Scope
service:write
Calls
POST /v1/service-ops/incidents
Example prompt
Declare a SEV2 incident on the checkout service.

Arguments

FieldTypeRequiredDescription
titlestringYesDescribe the symptom, not the suspected cause. For example "Checkout returns 500 for all customers".
summarystringNoAny detail known at the time.
severitystringNoOmit to use whichever level this workspace has marked as its default. Choose the higher one when unsure: raising later loses time that standing down never costs.
serviceIdstringNoThe affected service, if known.
customerImpactingbooleanNoFlags the incident for customer communication.
idempotencyKeystringNoSupply this to make a retry safe rather than opening a second incident.

Draft service incidents customer updates

Changes data

atlas_service_incidents_customer_updates_draft

Draft a message to the customers affected by an incident. Nothing is sent: approving and sending belong to a person in Atlas. Returns the draft with its id.

Scope
service:write
Calls
POST /v1/service-ops/incidents/{incidentId}/customer-updates
Example prompt
Draft a customer update for INC-42 saying we are investigating.

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.
subjectstringYesThe subject line customers see.
bodystringYesThe message customers see.
affectedPartyIdsarray of stringNoWhich affected parties receive it. Omit to address every affected party at send time.

List service incidents customer updates

Read only

atlas_service_incidents_customer_updates_list

Messages drafted or sent to customers about an incident, with their approval state. Read only, deliberately: nothing that reaches a customer is worth an assistant sending on behalf of somebody else.

Scope
service:read
Calls
GET /v1/service-ops/incidents/{incidentId}/customer-updates
Example prompt
What have we sent customers about INC-104?

Arguments

FieldTypeRequiredDescription
idstringYesIncident id.

Get service incidents

Read only

atlas_service_incidents_get

Get one incident in full: the record with its derived response times, who holds each response role, every written update, and the external conversations and documents attached to it. Use this before answering any detailed question about a single incident.

Scope
service:read
Calls
GET /v1/service-ops/incidents/{incidentId}
Example prompt
Show me incident INC-104 in full.

Arguments

FieldTypeRequiredDescription
idstringYesIncident id.

Add service incidents links

Changes data

atlas_service_incidents_links_add

Attach an external conversation or document to an incident by its address. Recognises Slack, Gmail, Outlook, Teams, Google Meet, Zoom and others, and records the same address once however many times it is attached.

Scope
service:write
Calls
POST /v1/service-ops/incidents/{incidentId}/links
Example prompt
Attach the incident Slack channel to INC-104.

Arguments

FieldTypeRequiredDescription
idstringYesIncident id.
urlstringYesA Slack thread, an email thread, a Teams message, a meeting recording or any document. Recorded once even if the same address is attached twice.
titlestringNo

Remove service incidents links

Destructive

atlas_service_incidents_links_remove

Remove a link attached to an incident, such as a Slack thread or a document that turned out to be unrelated. Returns nothing on success.

Scope
service:write
Calls
DELETE /v1/service-ops/incidents/{incidentId}/links/{linkId}
Example prompt
Remove the unrelated Slack thread from INC-42.

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.
linkIdstringYesThe attached link id.

List service incidents

Read only

atlas_service_incidents_list

List incidents with optional status, severity, service and free-text filters. Each row carries the human reference, the severity key and rank it was declared at, the status, the recorded instants, who is holding the incident commander role, the affected service, how many parties are affected and when they were last told anything, when acknowledgement stops being on time, when the next customer update is owed, and whether a review exists. Use this to answer "what is broken right now" or "what happened last week". There is no field called severity on an incident: read severityKey for the code and severityRank for the ordering.

Scope
service:read
Calls
GET /v1/service-ops/incidents
Example prompt
What is broken right now?

Arguments

FieldTypeRequiredDescription
status"TRIAGE" | "INVESTIGATING" | "IDENTIFIED" | "MITIGATED" | "RESOLVED" | "CANCELLED"NoFilter to one lifecycle status.
severitystringNoFilter to one severity.
openbooleanNoOnly incidents that are neither resolved nor cancelled.
serviceIdstringNoFilter to one affected service.
qstringNoFree text over the title and the reference.
limitintegerNo

List service incidents regulatory clocks

Read only

atlas_service_incidents_regulatory_clocks_list

Notification deadlines on an incident, and which regimes Atlas thinks might apply but have not been started. Read only: starting, meeting or waiving a regulatory clock is a claim about a legal obligation and belongs to a person. The dates are a scheduling aid, not legal advice.

Scope
service:read
Calls
GET /v1/service-ops/incidents/{incidentId}/regulatory-clocks
Example prompt
Which notification deadlines apply to INC-104?

Arguments

FieldTypeRequiredDescription
idstringYesIncident id.

Export service incidents report

Read only

atlas_service_incidents_report_export

Export the full incident report: summary, timeline, responders, affected customers, communications and regulatory clocks. The md format returns the report as Markdown text to read or quote. The pdf, xlsx and docx formats return the method and path to download the file with the same credentials, because binary content cannot travel through this tool.

Scope
service:read
Calls
GET /v1/service-ops/incidents/{incidentId}/report
Example prompt
Give me the full incident report for INC-42.

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.
format"md" | "pdf" | "xlsx" | "docx"Nomd returns the report as Markdown text. pdf, xlsx and docx return the download request, because a binary file cannot travel through this tool.

Create service incidents reviews

Changes data

atlas_service_incidents_reviews_create

Open the review for an incident. Safe to call twice: if one already exists it is returned rather than a second being created.

Scope
service:write
Calls
POST /v1/service-ops/incidents/{incidentId}/postmortem
Example prompt
Open the review for INC-104.

Arguments

FieldTypeRequiredDescription
idstringYesIncident id.

Assign service incidents roles

Changes data

atlas_service_incidents_roles_assign

Assign a response role. Command roles are singular, so assigning one releases the incumbent and the handover stays on the record rather than overwriting who had it.

Scope
service:write
Calls
POST /v1/service-ops/incidents/{incidentId}/roles
Example prompt
Make Priya the incident commander on INC-104.

Arguments

FieldTypeRequiredDescription
idstringYesIncident id.
kind"INCIDENT_COMMANDER" | "OPERATIONS_LEAD" | "COMMUNICATIONS_LEAD" | "SCRIBE" | "SUBJECT_MATTER_EXPERT" | "LIAISON"YesWhich response role to assign.
userIdstringYesThe person taking the role, by id. Use atlas_service_people_search to turn a name into one rather than guessing.

Release service incidents roles

Destructive

atlas_service_incidents_roles_release

Stand somebody down from a response role on an incident, such as incident commander. The assignment is kept as history with its release time, which is what a review reads. Returns the released assignment.

Scope
service:write
Calls
DELETE /v1/service-ops/incidents/{incidentId}/roles/{roleId}
Example prompt
Stand Priya down as incident commander on INC-42.

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.
roleIdstringYesThe role assignment id, from the incident roles.

Get service incidents timeline

Read only

atlas_service_incidents_timeline_get

Read the ordered timeline of one incident: severity and status changes, role assignments, written updates, attached conversations and alert events, in the order they actually occurred. This is the record a postmortem is written from.

Scope
service:read
Calls
GET /v1/service-ops/incidents/{incidentId}/timeline
Example prompt
Walk me through what happened on incident INC-104.

Arguments

FieldTypeRequiredDescription
idstringYesIncident id.
kindstringNoFilter to one entry kind, e.g. UPDATE or SEVERITY.
limitintegerNo
cursorstringNo

Update service incidents

Changes data

atlas_service_incidents_update

Change an incident: its status (including CANCELLED to withdraw it), severity, impact, affected service, title, summary, timing, customer impact, breach suspicion or update cadence. Resolving an incident is not possible here: it belongs to a person in Atlas, who confirms the fix. Returns the updated incident. Pass expectedVersion to refuse the change if somebody else edited the incident first.

Scope
service:write
Calls
PATCH /v1/service-ops/incidents/{incidentId}
Example prompt
Mark INC-42 resolved as fixed.

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.
titlestringNoA new title.
summarystring | nullNoA new summary. Null clears it.
severitystringNoA severity key from this workspace catalogue, for example SEV1. See atlas_service_severity_levels_list.
status"TRIAGE" | "INVESTIGATING" | "IDENTIFIED" | "MITIGATED" | "CANCELLED"NoThe new lifecycle status. CANCELLED withdraws the incident. RESOLVED is not accepted: resolving belongs to a person in Atlas.
impact"NONE" | "DEGRADED" | "PARTIAL_OUTAGE" | "FULL_OUTAGE"NoHow badly the service is affected.
serviceIdstring | nullNoThe affected service. Null clears it.
occurredAtstring (date-time) | nullNoISO-8601 instant the fault began.
detectedAtstring (date-time) | nullNoISO-8601 instant the fault was noticed.
customerImpactingbooleanNoWhether customers are affected.
dataBreachSuspectedbooleanNoWhether personal data may have been exposed.
materialityDeterminedAtstring (date-time) | nullNoISO-8601 instant the incident was judged material, which starts some regulatory clocks.
cancelReasonstringNoWhy the incident is being cancelled.
resolutionKind"FIXED" | "MITIGATED" | "FALSE_ALARM" | "DUPLICATE" | "EXPECTED_BEHAVIOUR" | "WONT_FIX"NoHow the incident ended. A false alarm is left out of response figures.
resolutionNotestringNoA short note on the resolution.
duplicateOfIncidentIdstringNoThe incident this one duplicates.
commsCadenceMinutesinteger | nullNoHow often customers are promised an update, in minutes. Null returns to the severity level cadence.
expectedVersionintegerNoThe version last read. The update is refused if somebody changed the incident since.

Create service incidents updates

Changes data

atlas_service_incidents_updates_create

Post a written update on an incident. Recorded on the timeline with the status at the time of writing, so the narrative still reads correctly after the incident moves on.

Scope
service:write
Calls
POST /v1/service-ops/incidents/{incidentId}/updates
Example prompt
Post an update on INC-104 that the rollback is complete.

Arguments

FieldTypeRequiredDescription
idstringYesIncident id.
bodystringYesWhat is known now. These become the narrative of the postmortem.

Create service incidents war room

Changes data

atlas_service_incidents_war_room_create

Open the private war room chat channel for an incident, or return the one that already exists. Returns the channel id and whether it was created now. Safe to call more than once.

Scope
service:write
Calls
POST /v1/service-ops/incidents/{incidentId}/war-room
Example prompt
Open a war room for INC-42.

Arguments

FieldTypeRequiredDescription
idstringYesThe incident id.

Get service metrics

Read only

atlas_service_metrics_get

Response figures over a window: time to detect, acknowledge, mitigate and resolve, plus the time between incidents. Every average comes with the number of incidents it was computed over, and the median sits next to the mean. Incidents that ended as a false alarm, a duplicate or expected behaviour are excluded and counted separately, because neither a quickly dismissed false alarm nor a slowly dismissed one describes how well anybody responded to a real problem. Quote the sample size alongside any figure you report, and say so when the response reports the window as truncated: those figures then cover the most recent slice of the period rather than all of it.

Scope
service:read
Calls
GET /v1/service-ops/metrics
Example prompt
What was our time to resolve over the last quarter?

Arguments

FieldTypeRequiredDescription
fromDatestring (date-time)No
toDatestring (date-time)No
serviceIdstringNo

List service on call responders

Read only

atlas_service_on_call_responders_list

Who is on call right now, for every schedule. Reports schedules that resolve to NOBODY as well, because a coverage gap is the single most useful thing this can surface. Use this before asking someone to page a team.

Scope
service:read
Calls
GET /v1/service-ops/on-call/now
Example prompt
Who is on call right now?

Arguments

This tool takes no arguments.

List service on call schedules

Read only

atlas_service_on_call_schedules_list

Every on-call schedule in this workspace, with its rotation layers and its time zone. Pair with atlas_service_on_call_responders_list, which answers who is holding the pager at this moment. Read only: editing a rotation decides who gets woken up.

Scope
service:read
Calls
GET /v1/service-ops/on-call/schedules
Example prompt
Which on-call schedules do we run?

Arguments

This tool takes no arguments.

Preview service on call schedules

Read only

atlas_service_on_call_schedules_preview

The shift calendar for one schedule over a window, including any period that nobody covers. Defaults to the next fortnight, which is long enough to see the next handover. Coverage gaps are reported rather than hidden, because a gap found on a Tuesday afternoon is a rota change and a gap found mid-incident is an unanswered page.

Scope
service:read
Calls
GET /v1/service-ops/on-call/schedules/{scheduleId}/preview
Example prompt
Show the next fortnight of the platform on-call rota.

Arguments

FieldTypeRequiredDescription
scheduleIdstringYesOn-call schedule id.
fromstring (date-time)NoStart of the window. Defaults to now.
tostring (date-time)NoEnd of the window. Defaults to a fortnight after the start.

Search service people

Read only

atlas_service_people_search

Find somebody in this workspace by name, and get the id that a response role, an action item or an on-call override is recorded against. Returns the display name and the workspace role, never an email address or a picture: a name is what a picker needs, and anything more would be handing one workspace a look at another workspace directory. Only members of the caller workspace are ever returned.

Scope
service:read
Calls
GET /v1/service-ops/people
Example prompt
Find Priya so I can give her the communications lead role.

Arguments

FieldTypeRequiredDescription
qstringNoPart of a name. Omit to list the first few members.
limitintegerNo

Create service problems

Changes data

atlas_service_problems_create

Open a problem: an underlying cause behind one or more incidents, with a summary, a workaround, the affected service and an owner. Link incident reviews to it with atlas_service_reviews_update. Returns the problem.

Scope
service:write
Calls
POST /v1/service-ops/problems
Example prompt
Open a problem for the recurring connection pool exhaustion.

Arguments

FieldTypeRequiredDescription
titlestringYesThe underlying cause, in one line.
summarystringNoWhat is known about it.
workaroundstringNoHow to live with it until it is fixed.
serviceIdstringNoThe service it affects.
ownerUserIdstringNoWho owns finding the fix.

Get service problems

Read only

atlas_service_problems_get

One shared cause in full, with its workaround, the reviews that named it and the follow-up work attached to it. Quote the workaround first when somebody is mid-incident: at that moment it is the only part of this record that helps.

Scope
service:read
Calls
GET /v1/service-ops/problems/{problemId}
Example prompt
What is the workaround for the connection pool problem?

Arguments

FieldTypeRequiredDescription
idstringYesProblem id.

List service problems

Read only

atlas_service_problems_list

Shared causes behind more than one incident. A problem exists separately from the incidents it produces, because the same underlying fault opens a fresh incident every time it fires and closing each one in turn never reaches the cause. Filter by status to find known errors, which are the ones where the cause is understood and a workaround already exists.

Scope
service:read
Calls
GET /v1/service-ops/problems
Example prompt
Which shared causes are behind more than one incident?

Arguments

FieldTypeRequiredDescription
status"OPEN" | "INVESTIGATING" | "KNOWN_ERROR" | "RESOLVED" | "CLOSED"No
serviceIdstringNo
limitintegerNo

Update service problems

Changes data

atlas_service_problems_update

Update a problem: its title, summary, workaround, status, owner or service. Move it to KNOWN_ERROR once the cause is understood and to RESOLVED once it is fixed. Returns the problem.

Scope
service:write
Calls
PATCH /v1/service-ops/problems/{problemId}
Example prompt
Mark the connection pool problem as a known error with a restart workaround.

Arguments

FieldTypeRequiredDescription
idstringYesThe problem id.
titlestringNoA new title.
summarystringNoA new summary.
workaroundstringNoA new workaround.
status"OPEN" | "INVESTIGATING" | "KNOWN_ERROR" | "RESOLVED" | "CLOSED"NoThe new status. KNOWN_ERROR means the cause is understood.
ownerUserIdstring | nullNoThe owner. Null unassigns it.
serviceIdstring | nullNoThe affected service. Null clears it.

List service regulatory clocks

Read only

atlas_service_regulatory_clocks_list

Notification deadlines across the workspace, soonest first. Defaults to the ones still running, which answers "what is still owed". Ask for MET, WAIVED or MISSED to review a period that has already passed: the only question worth asking about last month is whether the deadlines were met, and a list of what is still outstanding cannot answer it. Each clock states the basis it counts from, because regimes start counting from different events. Use overdueOnly to find deadlines that have already passed.

Scope
service:read
Calls
GET /v1/service-ops/regulatory-clocks
Example prompt
Which notification deadlines are still owed?

Arguments

FieldTypeRequiredDescription
status"RUNNING" | "MET" | "WAIVED" | "MISSED" | "ALL"NoDefaults to RUNNING. ALL returns every clock whatever its state.
overdueOnlybooleanNo
limitintegerNo

List service regulatory regimes

Read only

atlas_service_regulatory_regimes_list

The notification regimes Atlas knows about, with the deadline each one sets and who it is owed to. Read this to explain why a clock is due when it is due. The dates are a scheduling aid, not legal advice, and starting, meeting or waiving a clock is a claim about a legal obligation that belongs to a person.

Scope
service:read
Calls
GET /v1/service-ops/regulatory-regimes
Example prompt
Which notification regimes does Atlas know about?

Arguments

This tool takes no arguments.

Add service reviews action items

Changes data

atlas_service_reviews_action_items_add

Add a piece of follow-up work to a review, with one owner and a date. Give it an owner: an item owned by everybody is owned by nobody, and a review cannot be published until at least one item has one.

Scope
service:write
Calls
POST /v1/service-ops/postmortems/{postmortemId}/action-items
Example prompt
Add an action item to lower the alert threshold, owned by Priya, due Friday.

Arguments

FieldTypeRequiredDescription
idstringYesReview id.
titlestringYesWhat will change.
descriptionstringNo
kind"PREVENT" | "DETECT" | "MITIGATE" | "PROCESS" | "DOCUMENTATION"No
ownerUserIdstringNoOne person. An item owned by everybody is owned by nobody.
dueAtstring (date-time)No

Add service reviews factors

Changes data

atlas_service_reviews_factors_add

Record something that contributed to an incident. Reviews carry several contributing factors rather than one root cause, because complex systems do not fail for one reason and naming a single cause usually means naming a person.

Scope
service:write
Calls
POST /v1/service-ops/postmortems/{postmortemId}/factors
Example prompt
Record that the alert threshold was set too high on the INC-104 review.

Arguments

FieldTypeRequiredDescription
idstringYesReview id.
kindstringYesWhat sort of factor this is, for example TRIGGER, DETECTION_GAP or PROCESS_GAP. There is deliberately no root cause.
summarystringYesThe factor, in one sentence.
detailstringNo
evidenceUrlstring (uri)NoA graph, a log query, a commit.

Remove service reviews factors

Destructive

atlas_service_reviews_factors_remove

Remove a contributing factor from an incident review, when it was recorded in error or turns out not to have contributed. Returns a confirmation.

Scope
service:write
Calls
DELETE /v1/service-ops/postmortems/{postmortemId}/factors/{factorId}
Example prompt
Remove the DNS factor from the INC-42 review, it did not contribute.

Arguments

FieldTypeRequiredDescription
idstringYesThe review (postmortem) id.
factorIdstringYesThe contributing factor id.

Get service reviews

Read only

atlas_service_reviews_get

Read one incident review in full, including its contributing factors, its action items, and exactly what is still missing before it can be published.

Scope
service:read
Calls
GET /v1/service-ops/postmortems/{postmortemId}
Example prompt
Show me the review for INC-104 and what is still missing.

Arguments

FieldTypeRequiredDescription
idstringYesReview id.

List service reviews

Read only

atlas_service_reviews_list

List incident reviews. A review holds what happened, the several factors that contributed, and the work that is changing because of it.

Scope
service:read
Calls
GET /v1/service-ops/postmortems
Example prompt
Which incident reviews are still open?

Arguments

FieldTypeRequiredDescription
status"DRAFT" | "IN_REVIEW" | "PUBLISHED"No
limitintegerNo

Export service reviews report

Read only

atlas_service_reviews_report_export

Export an incident review as a document. The md format returns it as Markdown text to read or quote. The pdf, xlsx and docx formats return the method and path to download the file with the same credentials, because binary content cannot travel through this tool.

Scope
service:read
Calls
GET /v1/service-ops/postmortems/{postmortemId}/report
Example prompt
Export the INC-42 review.

Arguments

FieldTypeRequiredDescription
idstringYesThe review (postmortem) id.
format"md" | "pdf" | "xlsx" | "docx"Nomd returns the review as Markdown text. pdf, xlsx and docx return the download request, because a binary file cannot travel through this tool.

Transition service reviews

Changes data

atlas_service_reviews_transition

Move an incident review between DRAFT, IN_REVIEW and PUBLISHED. Publishing is refused, with the full list of what is missing, until the review is complete and the incident is closed. Returns the review.

Scope
service:write
Calls
POST /v1/service-ops/postmortems/{postmortemId}/status
Example prompt
Send the INC-42 review for review.

Arguments

FieldTypeRequiredDescription
idstringYesThe review (postmortem) id.
status"DRAFT" | "IN_REVIEW" | "PUBLISHED"YesThe state to move the review to.
ifMatchVersionintegerNoThe version last read. The change is refused if somebody edited the review since.

Update service reviews

Changes data

atlas_service_reviews_update

Write or edit an incident review: its summary, customer impact, detection, response and recovery narratives, what went well and poorly, where luck helped, lessons, next steps, linked problem and reviewers. Only the fields given change. Pass ifMatchVersion to refuse the edit if somebody else changed the review first. Returns the review.

Scope
service:write
Calls
PATCH /v1/service-ops/postmortems/{postmortemId}
Example prompt
Add our lessons learned to the INC-42 review.

Arguments

FieldTypeRequiredDescription
idstringYesThe review (postmortem) id.
titlestringNoThe review title.
summarystringNoWhat happened, in brief.
customerImpactstringNoHow customers were affected.
detectionNarrativestringNoHow the fault was noticed.
responseNarrativestringNoHow the response unfolded.
recoveryPlanstringNoHow service was restored.
whatWentWellstringNoWhat went well.
whatWentPoorlystringNoWhat went poorly.
whereWeGotLuckystringNoWhere luck, rather than design, helped.
lessonsLearnedstringNoWhat was learned.
nextStepsstringNoWhat happens next.
problemIdstring | nullNoThe problem this incident belongs to. Null unlinks it.
reviewerUserIdsarray of stringNoThe reviewers. Replaces the list.
ifMatchVersionintegerNoThe version last read. The change is refused if somebody edited the review since.

Get service reviews vocabulary

Read only

atlas_service_reviews_vocabulary_get

The vocabularies this workspace uses: the kinds of contributing factor, the kinds of action item, and the statuses. Read this before writing to a review, so the values you send are ones the workspace actually accepts.

Scope
service:read
Calls
GET /v1/service-ops/postmortem-vocabulary
Example prompt
Which contributing factor kinds does this workspace accept?

Arguments

This tool takes no arguments.

Create service services

Changes data

atlas_service_services_create

Add a service to the catalogue that incidents and alerts are filed against, with a machine-safe key, a name, a tier and an owning team. Administrators only. Returns the service.

Scope
service:write
Calls
POST /v1/service-ops/services
Example prompt
Add a Checkout service at tier 1.

Arguments

FieldTypeRequiredDescription
keystringYesA machine-safe key used in alert payloads: lowercase letters, numbers, dashes and underscores.
namestringYesThe display name.
descriptionstringNoWhat the service does.
tierintegerNoHow critical the service is, 1 (most) to 5.
ownerTeamIdstring | nullNoThe team that owns it.

List service services

Read only

atlas_service_services_list

The services this workspace records incidents against, with the key, the name and the tier of each. Read this to turn "the checkout service" into the id that the incident, metrics and problem tools filter by. A service can carry its own escalation ladder, which beats the workspace default.

Scope
service:read
Calls
GET /v1/service-ops/services
Example prompt
Which services do we record incidents against?

Arguments

This tool takes no arguments.

Get service settings

Read only

atlas_service_settings_get

Read the incident management settings of this workspace: the fallback people paged when nobody else resolves, whether customer updates need approval, when a war room opens automatically, the reference prefix, raw alert retention and the mitigation soak time.

Scope
service:read
Calls
GET /v1/service-ops/settings
Example prompt
Do customer updates need approval in this workspace?

Arguments

This tool takes no arguments.

Update service settings

Changes data

atlas_service_settings_update

Change the incident management settings of this workspace. Only the fields given change; fallbackUserIds replaces the whole list. Administrators only. Returns the settings after the change.

Scope
service:write
Calls
PATCH /v1/service-ops/settings
Example prompt
Require approval before any customer update is sent.

Arguments

FieldTypeRequiredDescription
fallbackUserIdsarray of stringNoPeople paged when no rotation or policy resolves to anybody, in order. Replaces the list.
requireCustomerUpdateApprovalbooleanNoWhether a customer update needs approval before it can be sent.
autoCreateWarRoomChannelbooleanNoWhether a war room channel opens automatically.
autoCreateWarRoomAtRankintegerNoThe severity rank at or below which the war room opens automatically. Lower is worse.
referencePrefixstringNoThe prefix of incident references, for example INC.
storeAlertRawPayloadDaysintegerNoHow many days raw alert payloads are kept. 0 keeps none.
mitigationSoakMinutesintegerNoHow long a mitigated incident is watched before it is suggested for resolution.

List service severity levels

Read only

atlas_service_severity_levels_list

The severity catalogue this workspace actually uses, in rank order, with what each level means and the response it expects. Read this before quoting or setting a severity, so the key you use is one this workspace defines rather than one you assumed. Read only: the catalogue is the vocabulary every past incident is already recorded in, so changing it is a settings decision.

Scope
service:read
Calls
GET /v1/service-ops/severity-levels
Example prompt
What do our severity levels mean?

Arguments

This tool takes no arguments.

Update service severity levels

Changes data

atlas_service_severity_levels_update

Edit one severity level: its label, description, rank, paging urgency, acknowledgement target, customer update cadence, whether it is the default, or retire it. The key cannot change, because past incidents store it. Administrators only. Returns the level.

Scope
service:write
Calls
PATCH /v1/service-ops/severity-levels/{levelId}
Example prompt
Rename SEV1 to Critical and promise updates every 30 minutes.

Arguments

FieldTypeRequiredDescription
idstringYesThe severity level id, from atlas_service_severity_levels_list.
labelstringNoThe display label.
descriptionstring | nullNoWhat this level means. Null clears it.
rankintegerNoThe ordering. Lower is worse.
pagingUrgency"HIGH" | "LOW" | "NONE"NoHow urgently responders are paged.
responseTargetMinutesinteger | nullNoThe acknowledgement target in minutes. Null removes it.
commsCadenceMinutesinteger | nullNoHow often customers are promised an update at this level, in minutes. Null promises nothing.
isDefaultbooleanNoMake this the level used when none is given.
retiredbooleanNoRetire the level so it can no longer be chosen. Past incidents keep it.

Apply service severity presets

Changes data

atlas_service_severity_presets_apply

Replace the severity catalogue of this workspace with a preset, such as SEV1 to SEV5 or P1 to P5. Existing incidents keep the key and rank they were declared at. Administrators only. Returns the new levels as items.

Scope
service:write
Calls
POST /v1/service-ops/severity-levels/apply-preset
Example prompt
Switch our severity levels to P1 to P5.

Arguments

FieldTypeRequiredDescription
presetstringYesThe preset key, from atlas_service_severity_presets_list.

List service severity presets

Read only

atlas_service_severity_presets_list

The severity catalogues Atlas ships as starting points, for example the SEV1 to SEV5 ladder and the P1 to P4 one. Useful for explaining the options to somebody choosing between them. Applying a preset replaces the workspace catalogue and is not offered here.

Scope
service:read
Calls
GET /v1/service-ops/severity-presets
Example prompt
Which severity ladders does Atlas ship?

Arguments

This tool takes no arguments.