Small-team incident response

Incident response for small teams that still need clear ownership.

Small teams need the same core answers as large teams: what broke, who owns it, who was notified and what happened next.

Keep the workflow small but explicit

A small team can often survive with chat messages and a shared calendar until alerts become frequent, ownership becomes unclear or handoffs start to fail. IncidentRelay gives the team a defined path from alert intake to responder action without forcing a heavy enterprise process.

The basic setup is simple: create a team, create a rotation, attach channels, add one or more routes and send alerts from the monitoring system.

What the team gets

  • One current on-call owner from the rotation schedule.
  • Route matchers so alerts go to the right team instead of a noisy shared channel.
  • Acknowledge, resolve and silence actions for incident hygiene.
  • Escalation policies when the first responder does not react.
  • Incident history that remains visible after the chat scrolls away.

A practical first workflow

Start with one production route and one notification channel. Match only critical alerts first, verify the selected responder, then add lower-severity notifications when the team is confident in the routing.

StepIncidentRelay object
Who owns alerts?Team and rotation
Which alerts enter?Route source and matchers
Where do messages go?Notification channels
What happens if nobody responds?Escalation policy

Why self-hosting matters here

Small teams often care about cost and control. A self-hosted setup keeps alert data, user data and operational history inside the environment the team already manages.