Service operations
Every Service operations tool, with the scope it needs, its arguments and the API operation it calls.
65 tools
Convert service action items
Changes dataatlas_service_action_items_convert
File an incident review action item as a real task in a project, so it is tracked with the rest of the work. Calling it again returns the task already filed rather than a duplicate. Returns the action item, the task id and whether the task was created now.
- Scope
service:write- Calls
- Example prompt
- File the canary deploy action item as a task in the Platform project.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The action item id. |
projectId | string | No | The project to file the task in. Omit to use the default. |
List service action items
Read onlyatlas_service_action_items_list
Follow-up work from incident reviews. Use overdueOnly to answer "what did we promise to fix and have not".
- Scope
service:read- Calls
- Example prompt
- What did we promise to fix and have not?
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
status | "PROPOSED" | "ACCEPTED" | "IN_PROGRESS" | "DONE" | "DROPPED" | No | |
ownerUserId | string | No | |
overdueOnly | boolean | No | Only work that is past its due date. |
limit | integer | No |
Update service action items
Changes dataatlas_service_action_items_update
Update an action item from an incident review: its title, description, kind, status, owner or due date. Use this to mark one done, reassign it, or drop it with a reason. Returns the action item.
- Scope
service:write- Calls
- Example prompt
- Mark the canary deploy action item done.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The action item id. |
title | string | No | A new title. |
description | string | No | A new description. |
kind | "PREVENT" | "DETECT" | "MITIGATE" | "PROCESS" | "DOCUMENTATION" | No | What the action does about the failure. |
status | "PROPOSED" | "ACCEPTED" | "IN_PROGRESS" | "DONE" | "DROPPED" | No | The new status. DROPPED should come with droppedReason. |
ownerUserId | string | null | No | The owner. Null unassigns it. |
dueAt | string (date-time) | null | No | ISO-8601 due date. Null clears it. |
droppedReason | string | No | Why the action is being dropped. |
Delete service alert sources
Destructiveatlas_service_alert_sources_delete
Delete an alert source, so the monitoring system behind it can no longer declare incidents. The alerts it already sent stay in incident history. Administrators only. Returns a confirmation.
- Scope
service:write- Calls
- Example prompt
- Delete the old Pingdom alert source.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The alert source id, from atlas_service_alert_sources_list. |
List service alert sources
Read onlyatlas_service_alert_sources_list
The outside systems allowed to raise alerts in this workspace, with the severity and service each one defaults to and whether it declares or resolves incidents on its own. The signing secret is never included, here or anywhere else: it is shown once when the source is created and is not readable afterwards. Read only, and creating or rotating a source is not offered at all, because a credential belongs to a person.
- Scope
service:read- Calls
- Example prompt
- Which systems can raise alerts in this workspace?
Arguments
This tool takes no arguments.
Update service alert sources
Changes dataatlas_service_alert_sources_update
Change how an alert source behaves: its name, default severity and service, whether its alerts declare or resolve incidents on their own, and whether it is active. The signing secret is neither returned nor changed. Administrators only. Returns the source.
- Scope
service:write- Calls
- Example prompt
- Stop the Datadog alert source from declaring incidents on its own.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The alert source id, from atlas_service_alert_sources_list. |
name | string | No | A new name. |
defaultSeverityKey | string | null | No | The severity an alert declares at when it names none. Null clears it. |
defaultServiceId | string | null | No | The service an alert is filed against when it names none. |
autoDeclare | boolean | No | Whether an alert declares an incident on its own. |
autoResolve | boolean | No | Whether a recovery alert resolves the incident on its own. Closing an unverified incident is a risk. |
isActive | boolean | No | Whether the source accepts alerts. |
Cancel service customer updates
Destructiveatlas_service_customer_updates_cancel
Withdraw a customer update that has not been sent, with an optional reason. The draft is kept for the record. Returns the cancelled update.
- Scope
service:write- Calls
- Example prompt
- Withdraw the customer update draft, it is out of date.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The customer update id. |
reason | string | No | Why the update is withdrawn. |
Update service customer updates
Changes dataatlas_service_customer_updates_update
Edit a customer update that has not been sent: its subject, body or recipients. Returns the updated draft. An update that has been sent cannot be edited.
- Scope
service:write- Calls
- Example prompt
- Change the draft update to say a fix is rolling out.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The customer update id. |
subject | string | No | A new subject line. |
body | string | No | A new message body. |
affectedPartyIds | array of string | No | A new recipient list. |
List service escalation policies
Read onlyatlas_service_escalation_policies_list
The escalation ladders this workspace has configured, each with its steps in order, how long each step waits before the next one fires, and who every step pages. Use this to answer "what happens if nobody acknowledges". Read only: a policy decides whose phone rings at three in the morning, so editing one belongs to a person who can see the whole ladder.
- Scope
service:read- Calls
- Example prompt
- What happens if nobody acknowledges a page?
Arguments
This tool takes no arguments.
Simulate service escalation policies
Changes dataatlas_service_escalation_policies_simulate
Ask an escalation ladder who it would page at a given instant, without paging anybody. Answers, rung by rung, how far into an incident it fires, who it reaches by then, and which of its targets resolve to nobody at all because a rotation is empty or a team has no members. Says plainly when no rung reaches anybody, so only the workspace fallback responders would. Read only despite being a POST: nothing is paged, no escalation run is started and nothing is recorded. Pass an out-of-hours instant, because a ladder that looks healthy on a Tuesday afternoon is not evidence about Sunday at 3am.
- Scope
service:read- Calls
- Example prompt
- Who would the platform ladder page at 3am on a Sunday?
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
policyId | string | Yes | Escalation policy id. |
at | string (date-time) | No | The instant to ask about. Defaults to now. Try an out-of-hours instant. |
Acknowledge service incidents
Changes dataatlas_service_incidents_acknowledge
Acknowledge an incident on behalf of the caller, which stops the escalation policy paging the next person. Returns the updated incident. Use this when somebody has picked the incident up.
- Scope
service:write- Calls
- Example prompt
- Acknowledge the checkout incident, I am on it.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
Add service incidents affected customers
Changes dataatlas_service_incidents_affected_customers_add
Record a customer affected by an incident, either a CRM account or a client onboarding, with an optional note on how they are affected. Affected customers are who a customer update is addressed to. Returns the affected party.
- Scope
service:write- Calls
- Example prompt
- Add Acme Corp to the customers affected by INC-42.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
kind | "ACCOUNT" | "ONBOARDING" | Yes | ACCOUNT for a CRM account, ONBOARDING for a client onboarding. |
refId | string | Yes | The account id or client onboarding id. |
impactNote | string | No | How this customer is affected. |
List service incidents affected customers
Read onlyatlas_service_incidents_affected_customers_list
Which customers an incident affects, and whether anything has reached them yet. Read only: adding a customer to an incident, and anything that sends them a message, belong to a person.
- Scope
service:read- Calls
- Example prompt
- Which customers does INC-104 affect, and have they been told?
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | Incident id. |
Remove service incidents affected customers
Destructiveatlas_service_incidents_affected_customers_remove
Remove a customer from the affected list of an incident, when they were added by mistake or turn out not to be affected. Returns a confirmation.
- Scope
service:write- Calls
- Example prompt
- Acme was not affected after all, take them off INC-42.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
partyId | string | Yes | The affected party id, from atlas_service_incidents_affected_customers_list. |
Delete service incidents attachments
Destructiveatlas_service_incidents_attachments_delete
Delete a file attached to an incident. The file is removed from the incident and its stored copy is purged. Returns nothing on success.
- Scope
attachments:write- Calls
- Example prompt
- Delete the wrong screenshot from INC-42.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
attachmentId | string | Yes | The attachment id. |
Download service incidents attachments
Read onlyatlas_service_incidents_attachments_download
Get a short-lived signed URL to download one file attached to an incident. Returns the URL and when it expires.
- Scope
attachments:read- Calls
- Example prompt
- Get me a download link for the screenshot on INC-42.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
attachmentId | string | Yes | The attachment id. |
List service incidents attachments
Read onlyatlas_service_incidents_attachments_list
List the files attached to an incident, such as logs, screenshots and exported traces, with their names, sizes and types. Also returns what the storage accepts. Use atlas_service_incidents_attachments_download for a link to one file.
- Scope
attachments:read- Calls
- Example prompt
- What files are attached to INC-42?
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
Finalize service incidents attachments upload
Changes dataatlas_service_incidents_attachments_upload_finalize
Complete an incident file upload after the bytes have been sent to the signed URL. The stored object is checked against the declared size and type before the attachment becomes visible. Returns the attachment.
- Scope
attachments:write- Calls
- Example prompt
- Finish attaching the trace log to INC-42.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
attachmentId | string | Yes | The attachment id. |
actualSizeBytes | integer | Yes | The size actually uploaded, in bytes. |
actualContentType | string | Yes | The MIME type actually uploaded. |
Start service incidents attachments upload
Changes dataatlas_service_incidents_attachments_upload_start
Begin attaching a file to an incident. Returns an attachment id, a signed upload URL, the method and headers to use, and when the URL expires. Upload the bytes to that URL, then call atlas_service_incidents_attachments_upload_finalize.
- Scope
attachments:write- Calls
- Example prompt
- Attach this trace log to INC-42.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
name | string | Yes | The file name. |
contentType | string | Yes | The MIME type, for example application/pdf. |
sizeBytes | integer | Yes | The file size in bytes. |
Create service incidents comments
Changes dataatlas_service_incidents_comments_create
Post a comment on an incident, or a reply when parentCommentId is given. Returns the comment. Use atlas_service_incidents_updates_create instead for a formal status update that belongs in the incident narrative.
- Scope
comments:write- Calls
- Example prompt
- Comment on INC-42 that we are rolling back.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
body | string | Yes | The comment text. |
parentCommentId | string | No | The comment this replies to. |
List service incidents comments
Read onlyatlas_service_incidents_comments_list
List the comment thread on an incident, oldest first, with keyset pagination. Returns items and nextCursor; follow nextCursor until it is null. Use this for the discussion around an incident, as distinct from its formal status updates.
- Scope
comments:read- Calls
- Example prompt
- What has the team been saying on INC-42?
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
cursor | string | No | The cursor from a previous page. |
limit | integer | No | Page size, 1 to 200. Defaults to 100. |
Create service incidents
Changes dataatlas_service_incidents_create
Declare an incident. Safe to retry when an idempotencyKey is supplied. Whoever declares holds the incident commander role until somebody takes it deliberately. Declaring early and standing down costs nothing; hesitating does.
- Scope
service:write- Calls
- Example prompt
- Declare a SEV2 incident on the checkout service.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
title | string | Yes | Describe the symptom, not the suspected cause. For example "Checkout returns 500 for all customers". |
summary | string | No | Any detail known at the time. |
severity | string | No | Omit to use whichever level this workspace has marked as its default. Choose the higher one when unsure: raising later loses time that standing down never costs. |
serviceId | string | No | The affected service, if known. |
customerImpacting | boolean | No | Flags the incident for customer communication. |
idempotencyKey | string | No | Supply this to make a retry safe rather than opening a second incident. |
Draft service incidents customer updates
Changes dataatlas_service_incidents_customer_updates_draft
Draft a message to the customers affected by an incident. Nothing is sent: approving and sending belong to a person in Atlas. Returns the draft with its id.
- Scope
service:write- Calls
- Example prompt
- Draft a customer update for INC-42 saying we are investigating.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
subject | string | Yes | The subject line customers see. |
body | string | Yes | The message customers see. |
affectedPartyIds | array of string | No | Which affected parties receive it. Omit to address every affected party at send time. |
List service incidents customer updates
Read onlyatlas_service_incidents_customer_updates_list
Messages drafted or sent to customers about an incident, with their approval state. Read only, deliberately: nothing that reaches a customer is worth an assistant sending on behalf of somebody else.
- Scope
service:read- Calls
- Example prompt
- What have we sent customers about INC-104?
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | Incident id. |
Get service incidents
Read onlyatlas_service_incidents_get
Get one incident in full: the record with its derived response times, who holds each response role, every written update, and the external conversations and documents attached to it. Use this before answering any detailed question about a single incident.
- Scope
service:read- Calls
- Example prompt
- Show me incident INC-104 in full.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | Incident id. |
Add service incidents links
Changes dataatlas_service_incidents_links_add
Attach an external conversation or document to an incident by its address. Recognises Slack, Gmail, Outlook, Teams, Google Meet, Zoom and others, and records the same address once however many times it is attached.
- Scope
service:write- Calls
- Example prompt
- Attach the incident Slack channel to INC-104.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | Incident id. |
url | string | Yes | A Slack thread, an email thread, a Teams message, a meeting recording or any document. Recorded once even if the same address is attached twice. |
title | string | No |
Remove service incidents links
Destructiveatlas_service_incidents_links_remove
Remove a link attached to an incident, such as a Slack thread or a document that turned out to be unrelated. Returns nothing on success.
- Scope
service:write- Calls
- Example prompt
- Remove the unrelated Slack thread from INC-42.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
linkId | string | Yes | The attached link id. |
List service incidents
Read onlyatlas_service_incidents_list
List incidents with optional status, severity, service and free-text filters. Each row carries the human reference, the severity key and rank it was declared at, the status, the recorded instants, who is holding the incident commander role, the affected service, how many parties are affected and when they were last told anything, when acknowledgement stops being on time, when the next customer update is owed, and whether a review exists. Use this to answer "what is broken right now" or "what happened last week". There is no field called severity on an incident: read severityKey for the code and severityRank for the ordering.
- Scope
service:read- Calls
- Example prompt
- What is broken right now?
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
status | "TRIAGE" | "INVESTIGATING" | "IDENTIFIED" | "MITIGATED" | "RESOLVED" | "CANCELLED" | No | Filter to one lifecycle status. |
severity | string | No | Filter to one severity. |
open | boolean | No | Only incidents that are neither resolved nor cancelled. |
serviceId | string | No | Filter to one affected service. |
q | string | No | Free text over the title and the reference. |
limit | integer | No |
List service incidents regulatory clocks
Read onlyatlas_service_incidents_regulatory_clocks_list
Notification deadlines on an incident, and which regimes Atlas thinks might apply but have not been started. Read only: starting, meeting or waiving a regulatory clock is a claim about a legal obligation and belongs to a person. The dates are a scheduling aid, not legal advice.
- Scope
service:read- Calls
- Example prompt
- Which notification deadlines apply to INC-104?
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | Incident id. |
Export service incidents report
Read onlyatlas_service_incidents_report_export
Export the full incident report: summary, timeline, responders, affected customers, communications and regulatory clocks. The md format returns the report as Markdown text to read or quote. The pdf, xlsx and docx formats return the method and path to download the file with the same credentials, because binary content cannot travel through this tool.
- Scope
service:read- Calls
- Example prompt
- Give me the full incident report for INC-42.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
format | "md" | "pdf" | "xlsx" | "docx" | No | md returns the report as Markdown text. pdf, xlsx and docx return the download request, because a binary file cannot travel through this tool. |
Create service incidents reviews
Changes dataatlas_service_incidents_reviews_create
Open the review for an incident. Safe to call twice: if one already exists it is returned rather than a second being created.
- Scope
service:write- Calls
- Example prompt
- Open the review for INC-104.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | Incident id. |
Assign service incidents roles
Changes dataatlas_service_incidents_roles_assign
Assign a response role. Command roles are singular, so assigning one releases the incumbent and the handover stays on the record rather than overwriting who had it.
- Scope
service:write- Calls
- Example prompt
- Make Priya the incident commander on INC-104.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | Incident id. |
kind | "INCIDENT_COMMANDER" | "OPERATIONS_LEAD" | "COMMUNICATIONS_LEAD" | "SCRIBE" | "SUBJECT_MATTER_EXPERT" | "LIAISON" | Yes | Which response role to assign. |
userId | string | Yes | The person taking the role, by id. Use atlas_service_people_search to turn a name into one rather than guessing. |
Release service incidents roles
Destructiveatlas_service_incidents_roles_release
Stand somebody down from a response role on an incident, such as incident commander. The assignment is kept as history with its release time, which is what a review reads. Returns the released assignment.
- Scope
service:write- Calls
- Example prompt
- Stand Priya down as incident commander on INC-42.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
roleId | string | Yes | The role assignment id, from the incident roles. |
Get service incidents timeline
Read onlyatlas_service_incidents_timeline_get
Read the ordered timeline of one incident: severity and status changes, role assignments, written updates, attached conversations and alert events, in the order they actually occurred. This is the record a postmortem is written from.
- Scope
service:read- Calls
- Example prompt
- Walk me through what happened on incident INC-104.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | Incident id. |
kind | string | No | Filter to one entry kind, e.g. UPDATE or SEVERITY. |
limit | integer | No | |
cursor | string | No |
Update service incidents
Changes dataatlas_service_incidents_update
Change an incident: its status (including CANCELLED to withdraw it), severity, impact, affected service, title, summary, timing, customer impact, breach suspicion or update cadence. Resolving an incident is not possible here: it belongs to a person in Atlas, who confirms the fix. Returns the updated incident. Pass expectedVersion to refuse the change if somebody else edited the incident first.
- Scope
service:write- Calls
- Example prompt
- Mark INC-42 resolved as fixed.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
title | string | No | A new title. |
summary | string | null | No | A new summary. Null clears it. |
severity | string | No | A severity key from this workspace catalogue, for example SEV1. See atlas_service_severity_levels_list. |
status | "TRIAGE" | "INVESTIGATING" | "IDENTIFIED" | "MITIGATED" | "CANCELLED" | No | The new lifecycle status. CANCELLED withdraws the incident. RESOLVED is not accepted: resolving belongs to a person in Atlas. |
impact | "NONE" | "DEGRADED" | "PARTIAL_OUTAGE" | "FULL_OUTAGE" | No | How badly the service is affected. |
serviceId | string | null | No | The affected service. Null clears it. |
occurredAt | string (date-time) | null | No | ISO-8601 instant the fault began. |
detectedAt | string (date-time) | null | No | ISO-8601 instant the fault was noticed. |
customerImpacting | boolean | No | Whether customers are affected. |
dataBreachSuspected | boolean | No | Whether personal data may have been exposed. |
materialityDeterminedAt | string (date-time) | null | No | ISO-8601 instant the incident was judged material, which starts some regulatory clocks. |
cancelReason | string | No | Why the incident is being cancelled. |
resolutionKind | "FIXED" | "MITIGATED" | "FALSE_ALARM" | "DUPLICATE" | "EXPECTED_BEHAVIOUR" | "WONT_FIX" | No | How the incident ended. A false alarm is left out of response figures. |
resolutionNote | string | No | A short note on the resolution. |
duplicateOfIncidentId | string | No | The incident this one duplicates. |
commsCadenceMinutes | integer | null | No | How often customers are promised an update, in minutes. Null returns to the severity level cadence. |
expectedVersion | integer | No | The version last read. The update is refused if somebody changed the incident since. |
Create service incidents updates
Changes dataatlas_service_incidents_updates_create
Post a written update on an incident. Recorded on the timeline with the status at the time of writing, so the narrative still reads correctly after the incident moves on.
- Scope
service:write- Calls
- Example prompt
- Post an update on INC-104 that the rollback is complete.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | Incident id. |
body | string | Yes | What is known now. These become the narrative of the postmortem. |
Create service incidents war room
Changes dataatlas_service_incidents_war_room_create
Open the private war room chat channel for an incident, or return the one that already exists. Returns the channel id and whether it was created now. Safe to call more than once.
- Scope
service:write- Calls
- Example prompt
- Open a war room for INC-42.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The incident id. |
Get service metrics
Read onlyatlas_service_metrics_get
Response figures over a window: time to detect, acknowledge, mitigate and resolve, plus the time between incidents. Every average comes with the number of incidents it was computed over, and the median sits next to the mean. Incidents that ended as a false alarm, a duplicate or expected behaviour are excluded and counted separately, because neither a quickly dismissed false alarm nor a slowly dismissed one describes how well anybody responded to a real problem. Quote the sample size alongside any figure you report, and say so when the response reports the window as truncated: those figures then cover the most recent slice of the period rather than all of it.
- Scope
service:read- Calls
- Example prompt
- What was our time to resolve over the last quarter?
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
fromDate | string (date-time) | No | |
toDate | string (date-time) | No | |
serviceId | string | No |
List service on call responders
Read onlyatlas_service_on_call_responders_list
Who is on call right now, for every schedule. Reports schedules that resolve to NOBODY as well, because a coverage gap is the single most useful thing this can surface. Use this before asking someone to page a team.
- Scope
service:read- Calls
- Example prompt
- Who is on call right now?
Arguments
This tool takes no arguments.
List service on call schedules
Read onlyatlas_service_on_call_schedules_list
Every on-call schedule in this workspace, with its rotation layers and its time zone. Pair with atlas_service_on_call_responders_list, which answers who is holding the pager at this moment. Read only: editing a rotation decides who gets woken up.
- Scope
service:read- Calls
- Example prompt
- Which on-call schedules do we run?
Arguments
This tool takes no arguments.
Preview service on call schedules
Read onlyatlas_service_on_call_schedules_preview
The shift calendar for one schedule over a window, including any period that nobody covers. Defaults to the next fortnight, which is long enough to see the next handover. Coverage gaps are reported rather than hidden, because a gap found on a Tuesday afternoon is a rota change and a gap found mid-incident is an unanswered page.
- Scope
service:read- Calls
- Example prompt
- Show the next fortnight of the platform on-call rota.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
scheduleId | string | Yes | On-call schedule id. |
from | string (date-time) | No | Start of the window. Defaults to now. |
to | string (date-time) | No | End of the window. Defaults to a fortnight after the start. |
Search service people
Read onlyatlas_service_people_search
Find somebody in this workspace by name, and get the id that a response role, an action item or an on-call override is recorded against. Returns the display name and the workspace role, never an email address or a picture: a name is what a picker needs, and anything more would be handing one workspace a look at another workspace directory. Only members of the caller workspace are ever returned.
- Scope
service:read- Calls
- Example prompt
- Find Priya so I can give her the communications lead role.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
q | string | No | Part of a name. Omit to list the first few members. |
limit | integer | No |
Create service problems
Changes dataatlas_service_problems_create
Open a problem: an underlying cause behind one or more incidents, with a summary, a workaround, the affected service and an owner. Link incident reviews to it with atlas_service_reviews_update. Returns the problem.
- Scope
service:write- Calls
- Example prompt
- Open a problem for the recurring connection pool exhaustion.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
title | string | Yes | The underlying cause, in one line. |
summary | string | No | What is known about it. |
workaround | string | No | How to live with it until it is fixed. |
serviceId | string | No | The service it affects. |
ownerUserId | string | No | Who owns finding the fix. |
Get service problems
Read onlyatlas_service_problems_get
One shared cause in full, with its workaround, the reviews that named it and the follow-up work attached to it. Quote the workaround first when somebody is mid-incident: at that moment it is the only part of this record that helps.
- Scope
service:read- Calls
- Example prompt
- What is the workaround for the connection pool problem?
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | Problem id. |
List service problems
Read onlyatlas_service_problems_list
Shared causes behind more than one incident. A problem exists separately from the incidents it produces, because the same underlying fault opens a fresh incident every time it fires and closing each one in turn never reaches the cause. Filter by status to find known errors, which are the ones where the cause is understood and a workaround already exists.
- Scope
service:read- Calls
- Example prompt
- Which shared causes are behind more than one incident?
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
status | "OPEN" | "INVESTIGATING" | "KNOWN_ERROR" | "RESOLVED" | "CLOSED" | No | |
serviceId | string | No | |
limit | integer | No |
Update service problems
Changes dataatlas_service_problems_update
Update a problem: its title, summary, workaround, status, owner or service. Move it to KNOWN_ERROR once the cause is understood and to RESOLVED once it is fixed. Returns the problem.
- Scope
service:write- Calls
- Example prompt
- Mark the connection pool problem as a known error with a restart workaround.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The problem id. |
title | string | No | A new title. |
summary | string | No | A new summary. |
workaround | string | No | A new workaround. |
status | "OPEN" | "INVESTIGATING" | "KNOWN_ERROR" | "RESOLVED" | "CLOSED" | No | The new status. KNOWN_ERROR means the cause is understood. |
ownerUserId | string | null | No | The owner. Null unassigns it. |
serviceId | string | null | No | The affected service. Null clears it. |
List service regulatory clocks
Read onlyatlas_service_regulatory_clocks_list
Notification deadlines across the workspace, soonest first. Defaults to the ones still running, which answers "what is still owed". Ask for MET, WAIVED or MISSED to review a period that has already passed: the only question worth asking about last month is whether the deadlines were met, and a list of what is still outstanding cannot answer it. Each clock states the basis it counts from, because regimes start counting from different events. Use overdueOnly to find deadlines that have already passed.
- Scope
service:read- Calls
- Example prompt
- Which notification deadlines are still owed?
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
status | "RUNNING" | "MET" | "WAIVED" | "MISSED" | "ALL" | No | Defaults to RUNNING. ALL returns every clock whatever its state. |
overdueOnly | boolean | No | |
limit | integer | No |
List service regulatory regimes
Read onlyatlas_service_regulatory_regimes_list
The notification regimes Atlas knows about, with the deadline each one sets and who it is owed to. Read this to explain why a clock is due when it is due. The dates are a scheduling aid, not legal advice, and starting, meeting or waiving a clock is a claim about a legal obligation that belongs to a person.
- Scope
service:read- Calls
- Example prompt
- Which notification regimes does Atlas know about?
Arguments
This tool takes no arguments.
Add service reviews action items
Changes dataatlas_service_reviews_action_items_add
Add a piece of follow-up work to a review, with one owner and a date. Give it an owner: an item owned by everybody is owned by nobody, and a review cannot be published until at least one item has one.
- Scope
service:write- Calls
- Example prompt
- Add an action item to lower the alert threshold, owned by Priya, due Friday.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | Review id. |
title | string | Yes | What will change. |
description | string | No | |
kind | "PREVENT" | "DETECT" | "MITIGATE" | "PROCESS" | "DOCUMENTATION" | No | |
ownerUserId | string | No | One person. An item owned by everybody is owned by nobody. |
dueAt | string (date-time) | No |
Add service reviews factors
Changes dataatlas_service_reviews_factors_add
Record something that contributed to an incident. Reviews carry several contributing factors rather than one root cause, because complex systems do not fail for one reason and naming a single cause usually means naming a person.
- Scope
service:write- Calls
- Example prompt
- Record that the alert threshold was set too high on the INC-104 review.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | Review id. |
kind | string | Yes | What sort of factor this is, for example TRIGGER, DETECTION_GAP or PROCESS_GAP. There is deliberately no root cause. |
summary | string | Yes | The factor, in one sentence. |
detail | string | No | |
evidenceUrl | string (uri) | No | A graph, a log query, a commit. |
Remove service reviews factors
Destructiveatlas_service_reviews_factors_remove
Remove a contributing factor from an incident review, when it was recorded in error or turns out not to have contributed. Returns a confirmation.
- Scope
service:write- Calls
- Example prompt
- Remove the DNS factor from the INC-42 review, it did not contribute.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The review (postmortem) id. |
factorId | string | Yes | The contributing factor id. |
Get service reviews
Read onlyatlas_service_reviews_get
Read one incident review in full, including its contributing factors, its action items, and exactly what is still missing before it can be published.
- Scope
service:read- Calls
- Example prompt
- Show me the review for INC-104 and what is still missing.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | Review id. |
List service reviews
Read onlyatlas_service_reviews_list
List incident reviews. A review holds what happened, the several factors that contributed, and the work that is changing because of it.
- Scope
service:read- Calls
- Example prompt
- Which incident reviews are still open?
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
status | "DRAFT" | "IN_REVIEW" | "PUBLISHED" | No | |
limit | integer | No |
Export service reviews report
Read onlyatlas_service_reviews_report_export
Export an incident review as a document. The md format returns it as Markdown text to read or quote. The pdf, xlsx and docx formats return the method and path to download the file with the same credentials, because binary content cannot travel through this tool.
- Scope
service:read- Calls
- Example prompt
- Export the INC-42 review.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The review (postmortem) id. |
format | "md" | "pdf" | "xlsx" | "docx" | No | md returns the review as Markdown text. pdf, xlsx and docx return the download request, because a binary file cannot travel through this tool. |
Transition service reviews
Changes dataatlas_service_reviews_transition
Move an incident review between DRAFT, IN_REVIEW and PUBLISHED. Publishing is refused, with the full list of what is missing, until the review is complete and the incident is closed. Returns the review.
- Scope
service:write- Calls
- Example prompt
- Send the INC-42 review for review.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The review (postmortem) id. |
status | "DRAFT" | "IN_REVIEW" | "PUBLISHED" | Yes | The state to move the review to. |
ifMatchVersion | integer | No | The version last read. The change is refused if somebody edited the review since. |
Update service reviews
Changes dataatlas_service_reviews_update
Write or edit an incident review: its summary, customer impact, detection, response and recovery narratives, what went well and poorly, where luck helped, lessons, next steps, linked problem and reviewers. Only the fields given change. Pass ifMatchVersion to refuse the edit if somebody else changed the review first. Returns the review.
- Scope
service:write- Calls
- Example prompt
- Add our lessons learned to the INC-42 review.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The review (postmortem) id. |
title | string | No | The review title. |
summary | string | No | What happened, in brief. |
customerImpact | string | No | How customers were affected. |
detectionNarrative | string | No | How the fault was noticed. |
responseNarrative | string | No | How the response unfolded. |
recoveryPlan | string | No | How service was restored. |
whatWentWell | string | No | What went well. |
whatWentPoorly | string | No | What went poorly. |
whereWeGotLucky | string | No | Where luck, rather than design, helped. |
lessonsLearned | string | No | What was learned. |
nextSteps | string | No | What happens next. |
problemId | string | null | No | The problem this incident belongs to. Null unlinks it. |
reviewerUserIds | array of string | No | The reviewers. Replaces the list. |
ifMatchVersion | integer | No | The version last read. The change is refused if somebody edited the review since. |
Get service reviews vocabulary
Read onlyatlas_service_reviews_vocabulary_get
The vocabularies this workspace uses: the kinds of contributing factor, the kinds of action item, and the statuses. Read this before writing to a review, so the values you send are ones the workspace actually accepts.
- Scope
service:read- Calls
- Example prompt
- Which contributing factor kinds does this workspace accept?
Arguments
This tool takes no arguments.
Create service services
Changes dataatlas_service_services_create
Add a service to the catalogue that incidents and alerts are filed against, with a machine-safe key, a name, a tier and an owning team. Administrators only. Returns the service.
- Scope
service:write- Calls
- Example prompt
- Add a Checkout service at tier 1.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
key | string | Yes | A machine-safe key used in alert payloads: lowercase letters, numbers, dashes and underscores. |
name | string | Yes | The display name. |
description | string | No | What the service does. |
tier | integer | No | How critical the service is, 1 (most) to 5. |
ownerTeamId | string | null | No | The team that owns it. |
List service services
Read onlyatlas_service_services_list
The services this workspace records incidents against, with the key, the name and the tier of each. Read this to turn "the checkout service" into the id that the incident, metrics and problem tools filter by. A service can carry its own escalation ladder, which beats the workspace default.
- Scope
service:read- Calls
- Example prompt
- Which services do we record incidents against?
Arguments
This tool takes no arguments.
Get service settings
Read onlyatlas_service_settings_get
Read the incident management settings of this workspace: the fallback people paged when nobody else resolves, whether customer updates need approval, when a war room opens automatically, the reference prefix, raw alert retention and the mitigation soak time.
- Scope
service:read- Calls
- Example prompt
- Do customer updates need approval in this workspace?
Arguments
This tool takes no arguments.
Update service settings
Changes dataatlas_service_settings_update
Change the incident management settings of this workspace. Only the fields given change; fallbackUserIds replaces the whole list. Administrators only. Returns the settings after the change.
- Scope
service:write- Calls
- Example prompt
- Require approval before any customer update is sent.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
fallbackUserIds | array of string | No | People paged when no rotation or policy resolves to anybody, in order. Replaces the list. |
requireCustomerUpdateApproval | boolean | No | Whether a customer update needs approval before it can be sent. |
autoCreateWarRoomChannel | boolean | No | Whether a war room channel opens automatically. |
autoCreateWarRoomAtRank | integer | No | The severity rank at or below which the war room opens automatically. Lower is worse. |
referencePrefix | string | No | The prefix of incident references, for example INC. |
storeAlertRawPayloadDays | integer | No | How many days raw alert payloads are kept. 0 keeps none. |
mitigationSoakMinutes | integer | No | How long a mitigated incident is watched before it is suggested for resolution. |
List service severity levels
Read onlyatlas_service_severity_levels_list
The severity catalogue this workspace actually uses, in rank order, with what each level means and the response it expects. Read this before quoting or setting a severity, so the key you use is one this workspace defines rather than one you assumed. Read only: the catalogue is the vocabulary every past incident is already recorded in, so changing it is a settings decision.
- Scope
service:read- Calls
- Example prompt
- What do our severity levels mean?
Arguments
This tool takes no arguments.
Update service severity levels
Changes dataatlas_service_severity_levels_update
Edit one severity level: its label, description, rank, paging urgency, acknowledgement target, customer update cadence, whether it is the default, or retire it. The key cannot change, because past incidents store it. Administrators only. Returns the level.
- Scope
service:write- Calls
- Example prompt
- Rename SEV1 to Critical and promise updates every 30 minutes.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
id | string | Yes | The severity level id, from atlas_service_severity_levels_list. |
label | string | No | The display label. |
description | string | null | No | What this level means. Null clears it. |
rank | integer | No | The ordering. Lower is worse. |
pagingUrgency | "HIGH" | "LOW" | "NONE" | No | How urgently responders are paged. |
responseTargetMinutes | integer | null | No | The acknowledgement target in minutes. Null removes it. |
commsCadenceMinutes | integer | null | No | How often customers are promised an update at this level, in minutes. Null promises nothing. |
isDefault | boolean | No | Make this the level used when none is given. |
retired | boolean | No | Retire the level so it can no longer be chosen. Past incidents keep it. |
Apply service severity presets
Changes dataatlas_service_severity_presets_apply
Replace the severity catalogue of this workspace with a preset, such as SEV1 to SEV5 or P1 to P5. Existing incidents keep the key and rank they were declared at. Administrators only. Returns the new levels as items.
- Scope
service:write- Calls
- Example prompt
- Switch our severity levels to P1 to P5.
Arguments
| Field | Type | Required | Description |
|---|---|---|---|
preset | string | Yes | The preset key, from atlas_service_severity_presets_list. |
List service severity presets
Read onlyatlas_service_severity_presets_list
The severity catalogues Atlas ships as starting points, for example the SEV1 to SEV5 ladder and the P1 to P4 one. Useful for explaining the options to somebody choosing between them. Applying a preset replaces the workspace catalogue and is not offered here.
- Scope
service:read- Calls
- Example prompt
- Which severity ladders does Atlas ship?
Arguments
This tool takes no arguments.