1. Declare an incident
Get the incident open and organized in seconds.- Know the help command —
/rootly helprun in any Slack channel shows every command available. You never need to memorize anything. - Declare with the new-incident command —
/rootly newopens the incident form. Fill in title, summary, and severity — the fields you see are configured by your org, and picking a severity kicks off automations behind the scenes. - Use private incidents when it’s sensitive — Security issues, customer escalations, or anything needing tightly controlled access should be declared private. AI features like catchup and summaries still work inside them.
2. Work from the command center
The incident channel is your home base — everything you need lives there.- Know your command center block — The pinned message at the top of the channel has the buttons and links you’ll use most: paging, updating, resolving, and links out to your team’s tools (bridge, ticketing, etc.).
-
- Catch up instantly when you join mid-incident — Use the catch-up command instead of scrolling the whole channel history.
- Ask Rootly for a summary — Get an AI-suggested summary of the incident so far, and use it as a starting point rather than writing one from scratch.
3. Know your role and your tasks
Roles come with built-in responsibilities — lean on them.- Check what role you’ve been assigned — Roles carry default tasks that get created automatically the moment you’re assigned, so check your tasks as soon as you join.
- Use roles to get oriented fast — If you’re newer to on-call or IR, seeing who holds which role tells you exactly who to go to for what.
- Mark tasks done as you go — Keeps the incident tidy and gives anyone joining later an accurate picture of what’s already been handled.
4. Update the incident & use emoji reactions
A couple small habits that save everyone time later.- Add the affected service when you know it — The moment you attach a service, its runbook attaches automatically and new tasks get created from it — no one has to remember the checklist by hand.
- React with the pin emoji on anything retro-worthy — This is the most important one: pinning builds your retrospective as you go. You can always edit or prune later, but you can’t get back a moment nobody flagged.
- Know the other emoji shortcuts — A star can turn a message into a task, and a memo/note emoji can turn one into a follow-up — check with your admin team which emoji are wired up for your org.
5. Page, escalate & resolve
Bring in the right people, and close it out cleanly.- Use any of the three paging paths — Ask Rootly who to page, run
/rootly page, or hit the Escalate button in the command center. All three reach the same on-call rotations, so use whichever is fastest in the moment. - Let severity changes do the notifying — Updating severity (e.g. to Sev 2) automatically posts to the leadership channel — you don’t need to separately ping anyone.
- Use the AI assist when you resolve — The resolution form suggests a summary for you; review and adjust it rather than writing one cold.
6. Know the web UI tabs
Everything from Slack also lives here — useful once things slow down.- Timeline — The fastest way to find your pinned messages and reconstruct what happened, in order.
- Tasks — Broken out by role assignment and by runbook, so you can see what’s outstanding at a glance.
- Follow-ups — Shows any auto-created tickets (e.g. Jira) so you can track post-incident work without leaving Rootly.
- Status page — Not automatically in sync with incident status — someone needs to manually publish updates here.
- Retro — Where the retrospective lives once the incident resolves; this is where your pinned messages end up.
- Meeting tab — Reinvite the meeting bot if it dropped, and pull up the call recording/transcript afterward.

