An incident is Stector's record of a monitor's downtime, opened automatically when a check fails and closed automatically when it recovers. This guide covers the incident lifecycle and what you can do manually.
An incident moves through up to four states: Investigating, Identified, Monitoring, and Resolved. Stector creates one automatically the moment a monitor is confirmed down, starting in Investigating with a system-posted update: "Monitor went down, incident auto-created by system." It resolves automatically once the monitor records a single successful run in each of its regions, so recovery is detected faster than failure — each region only needs one passing run instead of two consecutive failing ones.
From an incident's page at /dashboard/incidents/[id], anyone with the Member, Admin, or Owner role can post an update: a status change plus a message. The status dropdown offers Investigating, Identified, or Monitoring — Resolved isn't one of the options here. To close an incident, use the Close incident button instead.
Closing an incident is restricted to Admin and Owner roles. This is deliberate: closing is a highly visible action that affects your status page, and keeping it separate from the update form reduces the chance of an incident being marked resolved prematurely during an active outage.
Any open incident for your team appears on your public status page automatically. There's no per-incident visibility toggle in the dashboard to hide one.