---
title: "Incident — monitoring glossary"
description: "An incident is a confirmed period of degraded or unavailable service that requires human attention. Incidents are usually opened automatically when…"
canonical: "https://lemwatch.com/glossary/incident"
source: "https://lemwatch.com"
---

# Incident

> An incident is a confirmed period of degraded or unavailable service that requires human attention. Incidents are usually opened automatically when monitoring detects sustained failures and closed when service is verified restored.

## Definition

 Mature incident management distinguishes between an alert (a single failed check), an incident (a confirmed sustained failure), and a major incident (one that triggers customer-facing communication and post-mortem). Each has its own lifecycle, severity, and routing.

 Incident records typically include: start and end times, affected components, severity, root cause, customer impact, and a post-mortem document for major incidents.

## Why it matters

 Treating every alert as an incident drowns the on-call rotation. Treating no alerts as incidents leaves outages uninvestigated. The right balance — confirm-then-escalate logic, severity-based routing, and clear ownership — is the spine of operational reliability.

 See it in the product: [Incident management](https://lemwatch.com/features).


## Related

- [Monitoring glossary](https://lemwatch.com/glossary)
- [MTTR](https://lemwatch.com/glossary/mttr)
- [Downtime](https://lemwatch.com/glossary/downtime)
- [Alert Fatigue](https://lemwatch.com/glossary/alert-fatigue)
- [Website Monitoring](https://lemwatch.com/glossary/monitoring)
- [Core Web Vitals](https://lemwatch.com/glossary/core-web-vitals)
- [All monitoring checks](https://lemwatch.com/features)
- [Indexing](https://lemwatch.com/glossary/indexing)
