AtlasWork, planned itself.

    The AI-native, all-in-one work platform. Tasks, projects, CRM, contracts, and analytics in one calm workspace.

    System status
    • SSO
    • SCIM
    • Two-factor sign-in
    • Audit log

    Product

    • Overview
    • PDF tools
    • Diagram tools
    • People & HR
    • Integrations
    • Marketplace
    • Pricing

    Resources

    • Guides
    • Glossary
    • Compare
    • Docs
    • API reference
    • Support
    • Changelog
    • Status

    Company

    • About
    • Careers
    • Press
    • Contact

    Legal & trust

    • Trust center
    • Security
    • Privacy
    • Terms
    • DPA
    • GDPR
    • SLA
    • Refunds
    • Google API data
    Atlas, a product by wrxstack.com·© 2026 wrxstack·All rights reserved
    PrivacyTermsSecurityStatus

    You are in control of your cookies

    Atlas uses strictly necessary cookies to keep you signed in. With your consent, we add anonymized product analytics, conversion attribution, and remembered preferences. Change your mind any time at /privacy/cookies.

    Off until you agree · Change it any time

    • Necessaryalways on
    • Analyticsopt-in
    • Marketingopt-in
    • Preferencesopt-in
    Skip to documentation
    Docs
    Back to Atlas

    Start here

    • Overview

    Developer

    • REST API guide
    • Authentication
    • API reference
    • MCP (AI agents)
    • MCP tools reference
    • SDKs
    • Quick actions
    • Changelog

    Webhooks

    • Overview
    • Quickstart
    • Events
    • Payloads and headers
    • Security and signing
    • Delivery and retries
    • Managing via API

    Connect

    • Connectors
    • Integrations

    Product

    • Collaboration and chat
    • Signing in and security
    • Client portal

    Reference

    • Glossary
    • Keyboard shortcuts
    • Module reference

    Tools reference

    Service operations

    Every Service operations tool, with the scope it needs, its arguments and the API operation it calls.

    All areasTasksProjectsPortfoliosBoardsGoalsHabitsCommentsTime trackingWorkloadCRMGrowth suiteContractseSignPDF StudioFormsCalendarBookingMeetingsChatHuddlesWikiDocumentationDiagramsWhiteboardsHRPayrollClient deliveryClient onboardingService operationsStatus pageAutomationsAgentsAIReportsInsightsConnectorsNotificationsSearchWorkspace administrationAccessGovernancePrivacyBillingWebhooksAccess tokensMy accountFocusChangelogBlogTrashThemesEmail templatesMetadataCustom fieldsWalkthroughsVoiceActivityServer

    65 tools

    Convert service action items

    Changes data

    atlas_service_action_items_convert

    File an incident review action item as a real task in a project, so it is tracked with the rest of the work. Calling it again returns the task already filed rather than a duplicate. Returns the action item, the task id and whether the task was created now.

    Scope
    service:write
    Calls
    POST /v1/service-ops/action-items/{actionItemId}/convert-to-task
    Example prompt
    File the canary deploy action item as a task in the Platform project.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe action item id.
    projectIdstringNoThe project to file the task in. Omit to use the default.

    List service action items

    Read only

    atlas_service_action_items_list

    Follow-up work from incident reviews. Use overdueOnly to answer "what did we promise to fix and have not".

    Scope
    service:read
    Calls
    GET /v1/service-ops/action-items
    Example prompt
    What did we promise to fix and have not?

    Arguments

    FieldTypeRequiredDescription
    status"PROPOSED" | "ACCEPTED" | "IN_PROGRESS" | "DONE" | "DROPPED"No
    ownerUserIdstringNo
    overdueOnlybooleanNoOnly work that is past its due date.
    limitintegerNo

    Update service action items

    Changes data

    atlas_service_action_items_update

    Update an action item from an incident review: its title, description, kind, status, owner or due date. Use this to mark one done, reassign it, or drop it with a reason. Returns the action item.

    Scope
    service:write
    Calls
    PATCH /v1/service-ops/action-items/{actionItemId}
    Example prompt
    Mark the canary deploy action item done.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe action item id.
    titlestringNoA new title.
    descriptionstringNoA new description.
    kind"PREVENT" | "DETECT" | "MITIGATE" | "PROCESS" | "DOCUMENTATION"NoWhat the action does about the failure.
    status"PROPOSED" | "ACCEPTED" | "IN_PROGRESS" | "DONE" | "DROPPED"NoThe new status. DROPPED should come with droppedReason.
    ownerUserIdstring | nullNoThe owner. Null unassigns it.
    dueAtstring (date-time) | nullNoISO-8601 due date. Null clears it.
    droppedReasonstringNoWhy the action is being dropped.

    Delete service alert sources

    Destructive

    atlas_service_alert_sources_delete

    Delete an alert source, so the monitoring system behind it can no longer declare incidents. The alerts it already sent stay in incident history. Administrators only. Returns a confirmation.

    Scope
    service:write
    Calls
    DELETE /v1/service-ops/alert-sources/{sourceId}
    Example prompt
    Delete the old Pingdom alert source.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe alert source id, from atlas_service_alert_sources_list.

    List service alert sources

    Read only

    atlas_service_alert_sources_list

    The outside systems allowed to raise alerts in this workspace, with the severity and service each one defaults to and whether it declares or resolves incidents on its own. The signing secret is never included, here or anywhere else: it is shown once when the source is created and is not readable afterwards. Read only, and creating or rotating a source is not offered at all, because a credential belongs to a person.

    Scope
    service:read
    Calls
    GET /v1/service-ops/alert-sources
    Example prompt
    Which systems can raise alerts in this workspace?

    Arguments

    This tool takes no arguments.

    Update service alert sources

    Changes data

    atlas_service_alert_sources_update

    Change how an alert source behaves: its name, default severity and service, whether its alerts declare or resolve incidents on their own, and whether it is active. The signing secret is neither returned nor changed. Administrators only. Returns the source.

    Scope
    service:write
    Calls
    PATCH /v1/service-ops/alert-sources/{sourceId}
    Example prompt
    Stop the Datadog alert source from declaring incidents on its own.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe alert source id, from atlas_service_alert_sources_list.
    namestringNoA new name.
    defaultSeverityKeystring | nullNoThe severity an alert declares at when it names none. Null clears it.
    defaultServiceIdstring | nullNoThe service an alert is filed against when it names none.
    autoDeclarebooleanNoWhether an alert declares an incident on its own.
    autoResolvebooleanNoWhether a recovery alert resolves the incident on its own. Closing an unverified incident is a risk.
    isActivebooleanNoWhether the source accepts alerts.

    Cancel service customer updates

    Destructive

    atlas_service_customer_updates_cancel

    Withdraw a customer update that has not been sent, with an optional reason. The draft is kept for the record. Returns the cancelled update.

    Scope
    service:write
    Calls
    POST /v1/service-ops/customer-updates/{updateId}/cancel
    Example prompt
    Withdraw the customer update draft, it is out of date.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe customer update id.
    reasonstringNoWhy the update is withdrawn.

    Update service customer updates

    Changes data

    atlas_service_customer_updates_update

    Edit a customer update that has not been sent: its subject, body or recipients. Returns the updated draft. An update that has been sent cannot be edited.

    Scope
    service:write
    Calls
    PATCH /v1/service-ops/customer-updates/{updateId}
    Example prompt
    Change the draft update to say a fix is rolling out.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe customer update id.
    subjectstringNoA new subject line.
    bodystringNoA new message body.
    affectedPartyIdsarray of stringNoA new recipient list.

    List service escalation policies

    Read only

    atlas_service_escalation_policies_list

    The escalation ladders this workspace has configured, each with its steps in order, how long each step waits before the next one fires, and who every step pages. Use this to answer "what happens if nobody acknowledges". Read only: a policy decides whose phone rings at three in the morning, so editing one belongs to a person who can see the whole ladder.

    Scope
    service:read
    Calls
    GET /v1/service-ops/escalation-policies
    Example prompt
    What happens if nobody acknowledges a page?

    Arguments

    This tool takes no arguments.

    Simulate service escalation policies

    Changes data

    atlas_service_escalation_policies_simulate

    Ask an escalation ladder who it would page at a given instant, without paging anybody. Answers, rung by rung, how far into an incident it fires, who it reaches by then, and which of its targets resolve to nobody at all because a rotation is empty or a team has no members. Says plainly when no rung reaches anybody, so only the workspace fallback responders would. Read only despite being a POST: nothing is paged, no escalation run is started and nothing is recorded. Pass an out-of-hours instant, because a ladder that looks healthy on a Tuesday afternoon is not evidence about Sunday at 3am.

    Scope
    service:read
    Calls
    POST /v1/service-ops/escalation-policies/{policyId}/simulate
    Example prompt
    Who would the platform ladder page at 3am on a Sunday?

    Arguments

    FieldTypeRequiredDescription
    policyIdstringYesEscalation policy id.
    atstring (date-time)NoThe instant to ask about. Defaults to now. Try an out-of-hours instant.

    Acknowledge service incidents

    Changes data

    atlas_service_incidents_acknowledge

    Acknowledge an incident on behalf of the caller, which stops the escalation policy paging the next person. Returns the updated incident. Use this when somebody has picked the incident up.

    Scope
    service:write
    Calls
    POST /v1/service-ops/incidents/{incidentId}/acknowledge
    Example prompt
    Acknowledge the checkout incident, I am on it.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.

    Add service incidents affected customers

    Changes data

    atlas_service_incidents_affected_customers_add

    Record a customer affected by an incident, either a CRM account or a client onboarding, with an optional note on how they are affected. Affected customers are who a customer update is addressed to. Returns the affected party.

    Scope
    service:write
    Calls
    POST /v1/service-ops/incidents/{incidentId}/affected-parties
    Example prompt
    Add Acme Corp to the customers affected by INC-42.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.
    kind"ACCOUNT" | "ONBOARDING"YesACCOUNT for a CRM account, ONBOARDING for a client onboarding.
    refIdstringYesThe account id or client onboarding id.
    impactNotestringNoHow this customer is affected.

    List service incidents affected customers

    Read only

    atlas_service_incidents_affected_customers_list

    Which customers an incident affects, and whether anything has reached them yet. Read only: adding a customer to an incident, and anything that sends them a message, belong to a person.

    Scope
    service:read
    Calls
    GET /v1/service-ops/incidents/{incidentId}/affected-parties
    Example prompt
    Which customers does INC-104 affect, and have they been told?

    Arguments

    FieldTypeRequiredDescription
    idstringYesIncident id.

    Remove service incidents affected customers

    Destructive

    atlas_service_incidents_affected_customers_remove

    Remove a customer from the affected list of an incident, when they were added by mistake or turn out not to be affected. Returns a confirmation.

    Scope
    service:write
    Calls
    DELETE /v1/service-ops/incidents/{incidentId}/affected-parties/{partyId}
    Example prompt
    Acme was not affected after all, take them off INC-42.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.
    partyIdstringYesThe affected party id, from atlas_service_incidents_affected_customers_list.

    Delete service incidents attachments

    Destructive

    atlas_service_incidents_attachments_delete

    Delete a file attached to an incident. The file is removed from the incident and its stored copy is purged. Returns nothing on success.

    Scope
    attachments:write
    Calls
    DELETE /service-ops/incidents/{incidentId}/attachments/{attachmentId}
    Example prompt
    Delete the wrong screenshot from INC-42.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.
    attachmentIdstringYesThe attachment id.

    Download service incidents attachments

    Read only

    atlas_service_incidents_attachments_download

    Get a short-lived signed URL to download one file attached to an incident. Returns the URL and when it expires.

    Scope
    attachments:read
    Calls
    GET /service-ops/incidents/{incidentId}/attachments/{attachmentId}/download
    Example prompt
    Get me a download link for the screenshot on INC-42.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.
    attachmentIdstringYesThe attachment id.

    List service incidents attachments

    Read only

    atlas_service_incidents_attachments_list

    List the files attached to an incident, such as logs, screenshots and exported traces, with their names, sizes and types. Also returns what the storage accepts. Use atlas_service_incidents_attachments_download for a link to one file.

    Scope
    attachments:read
    Calls
    GET /service-ops/incidents/{incidentId}/attachments
    Example prompt
    What files are attached to INC-42?

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.

    Finalize service incidents attachments upload

    Changes data

    atlas_service_incidents_attachments_upload_finalize

    Complete an incident file upload after the bytes have been sent to the signed URL. The stored object is checked against the declared size and type before the attachment becomes visible. Returns the attachment.

    Scope
    attachments:write
    Calls
    POST /service-ops/incidents/{incidentId}/attachments/{attachmentId}/finalize
    Example prompt
    Finish attaching the trace log to INC-42.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.
    attachmentIdstringYesThe attachment id.
    actualSizeBytesintegerYesThe size actually uploaded, in bytes.
    actualContentTypestringYesThe MIME type actually uploaded.

    Start service incidents attachments upload

    Changes data

    atlas_service_incidents_attachments_upload_start

    Begin attaching a file to an incident. Returns an attachment id, a signed upload URL, the method and headers to use, and when the URL expires. Upload the bytes to that URL, then call atlas_service_incidents_attachments_upload_finalize.

    Scope
    attachments:write
    Calls
    POST /service-ops/incidents/{incidentId}/attachments/ticket
    Example prompt
    Attach this trace log to INC-42.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.
    namestringYesThe file name.
    contentTypestringYesThe MIME type, for example application/pdf.
    sizeBytesintegerYesThe file size in bytes.

    Create service incidents comments

    Changes data

    atlas_service_incidents_comments_create

    Post a comment on an incident, or a reply when parentCommentId is given. Returns the comment. Use atlas_service_incidents_updates_create instead for a formal status update that belongs in the incident narrative.

    Scope
    comments:write
    Calls
    POST /service-ops/incidents/{incidentId}/comments
    Example prompt
    Comment on INC-42 that we are rolling back.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.
    bodystringYesThe comment text.
    parentCommentIdstringNoThe comment this replies to.

    List service incidents comments

    Read only

    atlas_service_incidents_comments_list

    List the comment thread on an incident, oldest first, with keyset pagination. Returns items and nextCursor; follow nextCursor until it is null. Use this for the discussion around an incident, as distinct from its formal status updates.

    Scope
    comments:read
    Calls
    GET /service-ops/incidents/{incidentId}/comments
    Example prompt
    What has the team been saying on INC-42?

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.
    cursorstringNoThe cursor from a previous page.
    limitintegerNoPage size, 1 to 200. Defaults to 100.

    Create service incidents

    Changes data

    atlas_service_incidents_create

    Declare an incident. Safe to retry when an idempotencyKey is supplied. Whoever declares holds the incident commander role until somebody takes it deliberately. Declaring early and standing down costs nothing; hesitating does.

    Scope
    service:write
    Calls
    POST /v1/service-ops/incidents
    Example prompt
    Declare a SEV2 incident on the checkout service.

    Arguments

    FieldTypeRequiredDescription
    titlestringYesDescribe the symptom, not the suspected cause. For example "Checkout returns 500 for all customers".
    summarystringNoAny detail known at the time.
    severitystringNoOmit to use whichever level this workspace has marked as its default. Choose the higher one when unsure: raising later loses time that standing down never costs.
    serviceIdstringNoThe affected service, if known.
    customerImpactingbooleanNoFlags the incident for customer communication.
    idempotencyKeystringNoSupply this to make a retry safe rather than opening a second incident.

    Draft service incidents customer updates

    Changes data

    atlas_service_incidents_customer_updates_draft

    Draft a message to the customers affected by an incident. Nothing is sent: approving and sending belong to a person in Atlas. Returns the draft with its id.

    Scope
    service:write
    Calls
    POST /v1/service-ops/incidents/{incidentId}/customer-updates
    Example prompt
    Draft a customer update for INC-42 saying we are investigating.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.
    subjectstringYesThe subject line customers see.
    bodystringYesThe message customers see.
    affectedPartyIdsarray of stringNoWhich affected parties receive it. Omit to address every affected party at send time.

    List service incidents customer updates

    Read only

    atlas_service_incidents_customer_updates_list

    Messages drafted or sent to customers about an incident, with their approval state. Read only, deliberately: nothing that reaches a customer is worth an assistant sending on behalf of somebody else.

    Scope
    service:read
    Calls
    GET /v1/service-ops/incidents/{incidentId}/customer-updates
    Example prompt
    What have we sent customers about INC-104?

    Arguments

    FieldTypeRequiredDescription
    idstringYesIncident id.

    Get service incidents

    Read only

    atlas_service_incidents_get

    Get one incident in full: the record with its derived response times, who holds each response role, every written update, and the external conversations and documents attached to it. Use this before answering any detailed question about a single incident.

    Scope
    service:read
    Calls
    GET /v1/service-ops/incidents/{incidentId}
    Example prompt
    Show me incident INC-104 in full.

    Arguments

    FieldTypeRequiredDescription
    idstringYesIncident id.

    Add service incidents links

    Changes data

    atlas_service_incidents_links_add

    Attach an external conversation or document to an incident by its address. Recognises Slack, Gmail, Outlook, Teams, Google Meet, Zoom and others, and records the same address once however many times it is attached.

    Scope
    service:write
    Calls
    POST /v1/service-ops/incidents/{incidentId}/links
    Example prompt
    Attach the incident Slack channel to INC-104.

    Arguments

    FieldTypeRequiredDescription
    idstringYesIncident id.
    urlstringYesA Slack thread, an email thread, a Teams message, a meeting recording or any document. Recorded once even if the same address is attached twice.
    titlestringNo

    Remove service incidents links

    Destructive

    atlas_service_incidents_links_remove

    Remove a link attached to an incident, such as a Slack thread or a document that turned out to be unrelated. Returns nothing on success.

    Scope
    service:write
    Calls
    DELETE /v1/service-ops/incidents/{incidentId}/links/{linkId}
    Example prompt
    Remove the unrelated Slack thread from INC-42.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.
    linkIdstringYesThe attached link id.

    List service incidents

    Read only

    atlas_service_incidents_list

    List incidents with optional status, severity, service and free-text filters. Each row carries the human reference, the severity key and rank it was declared at, the status, the recorded instants, who is holding the incident commander role, the affected service, how many parties are affected and when they were last told anything, when acknowledgement stops being on time, when the next customer update is owed, and whether a review exists. Use this to answer "what is broken right now" or "what happened last week". There is no field called severity on an incident: read severityKey for the code and severityRank for the ordering. Pass `nextCursor` back as `cursor` for the next page.

    Scope
    service:read
    Calls
    GET /v1/service-ops/incidents
    Example prompt
    What is broken right now?

    Arguments

    FieldTypeRequiredDescription
    status"TRIAGE" | "INVESTIGATING" | "IDENTIFIED" | "MITIGATED" | "RESOLVED" | "CANCELLED"NoFilter to one lifecycle status.
    severitystringNoFilter to one severity.
    openbooleanNoOnly incidents that are neither resolved nor cancelled.
    serviceIdstringNoFilter to one affected service.
    qstringNoFree text over the title and the reference.
    limitintegerNoPage size, 1 to 100.
    cursorstringNoThe nextCursor of the previous page. Leave it out for the first page.

    List service incidents regulatory clocks

    Read only

    atlas_service_incidents_regulatory_clocks_list

    Notification deadlines on an incident, and which regimes Atlas thinks might apply but have not been started. Read only: starting, meeting or waiving a regulatory clock is a claim about a legal obligation and belongs to a person. The dates are a scheduling aid, not legal advice.

    Scope
    service:read
    Calls
    GET /v1/service-ops/incidents/{incidentId}/regulatory-clocks
    Example prompt
    Which notification deadlines apply to INC-104?

    Arguments

    FieldTypeRequiredDescription
    idstringYesIncident id.

    Export service incidents report

    Read only

    atlas_service_incidents_report_export

    Export the full incident report: summary, timeline, responders, affected customers, communications and regulatory clocks. The md format returns the report as Markdown text to read or quote. The pdf, xlsx and docx formats return the method and path to download the file with the same credentials, because binary content cannot travel through this tool.

    Scope
    service:read
    Calls
    GET /v1/service-ops/incidents/{incidentId}/report
    Example prompt
    Give me the full incident report for INC-42.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.
    format"md" | "pdf" | "xlsx" | "docx"Nomd returns the report as Markdown text. pdf, xlsx and docx return the download request, because a binary file cannot travel through this tool.

    Create service incidents reviews

    Changes data

    atlas_service_incidents_reviews_create

    Open the review for an incident. Safe to call twice: if one already exists it is returned rather than a second being created.

    Scope
    service:write
    Calls
    POST /v1/service-ops/incidents/{incidentId}/postmortem
    Example prompt
    Open the review for INC-104.

    Arguments

    FieldTypeRequiredDescription
    idstringYesIncident id.

    Assign service incidents roles

    Changes data

    atlas_service_incidents_roles_assign

    Assign a response role. Command roles are singular, so assigning one releases the incumbent and the handover stays on the record rather than overwriting who had it.

    Scope
    service:write
    Calls
    POST /v1/service-ops/incidents/{incidentId}/roles
    Example prompt
    Make Priya the incident commander on INC-104.

    Arguments

    FieldTypeRequiredDescription
    idstringYesIncident id.
    kind"INCIDENT_COMMANDER" | "OPERATIONS_LEAD" | "COMMUNICATIONS_LEAD" | "SCRIBE" | "SUBJECT_MATTER_EXPERT" | "LIAISON"YesWhich response role to assign.
    userIdstringYesThe person taking the role, by id. Use atlas_service_people_search to turn a name into one rather than guessing.

    Release service incidents roles

    Destructive

    atlas_service_incidents_roles_release

    Stand somebody down from a response role on an incident, such as incident commander. The assignment is kept as history with its release time, which is what a review reads. Returns the released assignment.

    Scope
    service:write
    Calls
    DELETE /v1/service-ops/incidents/{incidentId}/roles/{roleId}
    Example prompt
    Stand Priya down as incident commander on INC-42.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.
    roleIdstringYesThe role assignment id, from the incident roles.

    Get service incidents timeline

    Read only

    atlas_service_incidents_timeline_get

    Read the ordered timeline of one incident: severity and status changes, role assignments, written updates, attached conversations and alert events, in the order they actually occurred. This is the record a postmortem is written from.

    Scope
    service:read
    Calls
    GET /v1/service-ops/incidents/{incidentId}/timeline
    Example prompt
    Walk me through what happened on incident INC-104.

    Arguments

    FieldTypeRequiredDescription
    idstringYesIncident id.
    kindstringNoFilter to one entry kind, e.g. UPDATE or SEVERITY.
    limitintegerNo
    cursorstringNo

    Update service incidents

    Changes data

    atlas_service_incidents_update

    Change an incident: its status (including CANCELLED to withdraw it), severity, impact, affected service, title, summary, timing, customer impact, breach suspicion or update cadence. Resolving an incident is not possible here: it belongs to a person in Atlas, who confirms the fix. Returns the updated incident. Pass expectedVersion to refuse the change if somebody else edited the incident first.

    Scope
    service:write
    Calls
    PATCH /v1/service-ops/incidents/{incidentId}
    Example prompt
    Mark INC-42 resolved as fixed.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.
    titlestringNoA new title.
    summarystring | nullNoA new summary. Null clears it.
    severitystringNoA severity key from this workspace catalogue, for example SEV1. See atlas_service_severity_levels_list.
    status"TRIAGE" | "INVESTIGATING" | "IDENTIFIED" | "MITIGATED" | "CANCELLED"NoThe new lifecycle status. CANCELLED withdraws the incident. RESOLVED is not accepted: resolving belongs to a person in Atlas.
    impact"NONE" | "DEGRADED" | "PARTIAL_OUTAGE" | "FULL_OUTAGE"NoHow badly the service is affected.
    serviceIdstring | nullNoThe affected service. Null clears it.
    occurredAtstring (date-time) | nullNoISO-8601 instant the fault began.
    detectedAtstring (date-time) | nullNoISO-8601 instant the fault was noticed.
    customerImpactingbooleanNoWhether customers are affected.
    dataBreachSuspectedbooleanNoWhether personal data may have been exposed.
    materialityDeterminedAtstring (date-time) | nullNoISO-8601 instant the incident was judged material, which starts some regulatory clocks.
    cancelReasonstringNoWhy the incident is being cancelled.
    resolutionKind"FIXED" | "MITIGATED" | "FALSE_ALARM" | "DUPLICATE" | "EXPECTED_BEHAVIOUR" | "WONT_FIX"NoHow the incident ended. A false alarm is left out of response figures.
    resolutionNotestringNoA short note on the resolution.
    duplicateOfIncidentIdstringNoThe incident this one duplicates.
    commsCadenceMinutesinteger | nullNoHow often customers are promised an update, in minutes. Null returns to the severity level cadence.
    expectedVersionintegerNoThe version last read. The update is refused if somebody changed the incident since.

    Create service incidents updates

    Changes data

    atlas_service_incidents_updates_create

    Post a written update on an incident. Recorded on the timeline with the status at the time of writing, so the narrative still reads correctly after the incident moves on.

    Scope
    service:write
    Calls
    POST /v1/service-ops/incidents/{incidentId}/updates
    Example prompt
    Post an update on INC-104 that the rollback is complete.

    Arguments

    FieldTypeRequiredDescription
    idstringYesIncident id.
    bodystringYesWhat is known now. These become the narrative of the postmortem.

    Create service incidents war room

    Changes data

    atlas_service_incidents_war_room_create

    Open the private war room chat channel for an incident, or return the one that already exists. Returns the channel id and whether it was created now. Safe to call more than once.

    Scope
    service:write
    Calls
    POST /v1/service-ops/incidents/{incidentId}/war-room
    Example prompt
    Open a war room for INC-42.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe incident id.

    Get service metrics

    Read only

    atlas_service_metrics_get

    Response figures over a window: time to detect, acknowledge, mitigate and resolve, plus the time between incidents. Every average comes with the number of incidents it was computed over, and the median sits next to the mean. Incidents that ended as a false alarm, a duplicate or expected behaviour are excluded and counted separately, because neither a quickly dismissed false alarm nor a slowly dismissed one describes how well anybody responded to a real problem. Quote the sample size alongside any figure you report, and say so when the response reports the window as truncated: those figures then cover the most recent slice of the period rather than all of it.

    Scope
    service:read
    Calls
    GET /v1/service-ops/metrics
    Example prompt
    What was our time to resolve over the last quarter?

    Arguments

    FieldTypeRequiredDescription
    fromDatestring (date-time)No
    toDatestring (date-time)No
    serviceIdstringNo

    List service on call responders

    Read only

    atlas_service_on_call_responders_list

    Who is on call right now, for every schedule. Reports schedules that resolve to NOBODY as well, because a coverage gap is the single most useful thing this can surface. Use this before asking someone to page a team.

    Scope
    service:read
    Calls
    GET /v1/service-ops/on-call/now
    Example prompt
    Who is on call right now?

    Arguments

    This tool takes no arguments.

    List service on call schedules

    Read only

    atlas_service_on_call_schedules_list

    Every on-call schedule in this workspace, with its rotation layers and its time zone. Pair with atlas_service_on_call_responders_list, which answers who is holding the pager at this moment. Read only: editing a rotation decides who gets woken up.

    Scope
    service:read
    Calls
    GET /v1/service-ops/on-call/schedules
    Example prompt
    Which on-call schedules do we run?

    Arguments

    This tool takes no arguments.

    Preview service on call schedules

    Read only

    atlas_service_on_call_schedules_preview

    The shift calendar for one schedule over a window, including any period that nobody covers. Defaults to the next fortnight, which is long enough to see the next handover. Coverage gaps are reported rather than hidden, because a gap found on a Tuesday afternoon is a rota change and a gap found mid-incident is an unanswered page.

    Scope
    service:read
    Calls
    GET /v1/service-ops/on-call/schedules/{scheduleId}/preview
    Example prompt
    Show the next fortnight of the platform on-call rota.

    Arguments

    FieldTypeRequiredDescription
    scheduleIdstringYesOn-call schedule id.
    fromstring (date-time)NoStart of the window. Defaults to now.
    tostring (date-time)NoEnd of the window. Defaults to a fortnight after the start.

    Search service people

    Read only

    atlas_service_people_search

    Find somebody in this workspace by name, and get the id that a response role, an action item or an on-call override is recorded against. Returns the display name and the workspace role, never an email address or a picture: a name is what a picker needs, and anything more would be handing one workspace a look at another workspace directory. Only members of the caller workspace are ever returned.

    Scope
    service:read
    Calls
    GET /v1/service-ops/people
    Example prompt
    Find Priya so I can give her the communications lead role.

    Arguments

    FieldTypeRequiredDescription
    qstringNoPart of a name. Omit to list the first few members.
    limitintegerNo

    Create service problems

    Changes data

    atlas_service_problems_create

    Open a problem: an underlying cause behind one or more incidents, with a summary, a workaround, the affected service and an owner. Link incident reviews to it with atlas_service_reviews_update. Returns the problem.

    Scope
    service:write
    Calls
    POST /v1/service-ops/problems
    Example prompt
    Open a problem for the recurring connection pool exhaustion.

    Arguments

    FieldTypeRequiredDescription
    titlestringYesThe underlying cause, in one line.
    summarystringNoWhat is known about it.
    workaroundstringNoHow to live with it until it is fixed.
    serviceIdstringNoThe service it affects.
    ownerUserIdstringNoWho owns finding the fix.

    Get service problems

    Read only

    atlas_service_problems_get

    One shared cause in full, with its workaround, the reviews that named it and the follow-up work attached to it. Quote the workaround first when somebody is mid-incident: at that moment it is the only part of this record that helps.

    Scope
    service:read
    Calls
    GET /v1/service-ops/problems/{problemId}
    Example prompt
    What is the workaround for the connection pool problem?

    Arguments

    FieldTypeRequiredDescription
    idstringYesProblem id.

    List service problems

    Read only

    atlas_service_problems_list

    Shared causes behind more than one incident. A problem exists separately from the incidents it produces, because the same underlying fault opens a fresh incident every time it fires and closing each one in turn never reaches the cause. Filter by status to find known errors, which are the ones where the cause is understood and a workaround already exists.

    Scope
    service:read
    Calls
    GET /v1/service-ops/problems
    Example prompt
    Which shared causes are behind more than one incident?

    Arguments

    FieldTypeRequiredDescription
    status"OPEN" | "INVESTIGATING" | "KNOWN_ERROR" | "RESOLVED" | "CLOSED"No
    serviceIdstringNo
    limitintegerNo

    Update service problems

    Changes data

    atlas_service_problems_update

    Update a problem: its title, summary, workaround, status, owner or service. Move it to KNOWN_ERROR once the cause is understood and to RESOLVED once it is fixed. Returns the problem.

    Scope
    service:write
    Calls
    PATCH /v1/service-ops/problems/{problemId}
    Example prompt
    Mark the connection pool problem as a known error with a restart workaround.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe problem id.
    titlestringNoA new title.
    summarystringNoA new summary.
    workaroundstringNoA new workaround.
    status"OPEN" | "INVESTIGATING" | "KNOWN_ERROR" | "RESOLVED" | "CLOSED"NoThe new status. KNOWN_ERROR means the cause is understood.
    ownerUserIdstring | nullNoThe owner. Null unassigns it.
    serviceIdstring | nullNoThe affected service. Null clears it.

    List service regulatory clocks

    Read only

    atlas_service_regulatory_clocks_list

    Notification deadlines across the workspace, soonest first. Defaults to the ones still running, which answers "what is still owed". Ask for MET, WAIVED or MISSED to review a period that has already passed: the only question worth asking about last month is whether the deadlines were met, and a list of what is still outstanding cannot answer it. Each clock states the basis it counts from, because regimes start counting from different events. Use overdueOnly to find deadlines that have already passed.

    Scope
    service:read
    Calls
    GET /v1/service-ops/regulatory-clocks
    Example prompt
    Which notification deadlines are still owed?

    Arguments

    FieldTypeRequiredDescription
    status"RUNNING" | "MET" | "WAIVED" | "MISSED" | "ALL"NoDefaults to RUNNING. ALL returns every clock whatever its state.
    overdueOnlybooleanNo
    limitintegerNo

    List service regulatory regimes

    Read only

    atlas_service_regulatory_regimes_list

    The notification regimes Atlas knows about, with the deadline each one sets and who it is owed to. Read this to explain why a clock is due when it is due. The dates are a scheduling aid, not legal advice, and starting, meeting or waiving a clock is a claim about a legal obligation that belongs to a person.

    Scope
    service:read
    Calls
    GET /v1/service-ops/regulatory-regimes
    Example prompt
    Which notification regimes does Atlas know about?

    Arguments

    This tool takes no arguments.

    Add service reviews action items

    Changes data

    atlas_service_reviews_action_items_add

    Add a piece of follow-up work to a review, with one owner and a date. Give it an owner: an item owned by everybody is owned by nobody, and a review cannot be published until at least one item has one.

    Scope
    service:write
    Calls
    POST /v1/service-ops/postmortems/{postmortemId}/action-items
    Example prompt
    Add an action item to lower the alert threshold, owned by Priya, due Friday.

    Arguments

    FieldTypeRequiredDescription
    idstringYesReview id.
    titlestringYesWhat will change.
    descriptionstringNo
    kind"PREVENT" | "DETECT" | "MITIGATE" | "PROCESS" | "DOCUMENTATION"No
    ownerUserIdstringNoOne person. An item owned by everybody is owned by nobody.
    dueAtstring (date-time)No

    Add service reviews factors

    Changes data

    atlas_service_reviews_factors_add

    Record something that contributed to an incident. Reviews carry several contributing factors rather than one root cause, because complex systems do not fail for one reason and naming a single cause usually means naming a person.

    Scope
    service:write
    Calls
    POST /v1/service-ops/postmortems/{postmortemId}/factors
    Example prompt
    Record that the alert threshold was set too high on the INC-104 review.

    Arguments

    FieldTypeRequiredDescription
    idstringYesReview id.
    kindstringYesWhat sort of factor this is, for example TRIGGER, DETECTION_GAP or PROCESS_GAP. There is deliberately no root cause.
    summarystringYesThe factor, in one sentence.
    detailstringNo
    evidenceUrlstring (uri)NoA graph, a log query, a commit.

    Remove service reviews factors

    Destructive

    atlas_service_reviews_factors_remove

    Remove a contributing factor from an incident review, when it was recorded in error or turns out not to have contributed. Returns a confirmation.

    Scope
    service:write
    Calls
    DELETE /v1/service-ops/postmortems/{postmortemId}/factors/{factorId}
    Example prompt
    Remove the DNS factor from the INC-42 review, it did not contribute.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe review (postmortem) id.
    factorIdstringYesThe contributing factor id.

    Get service reviews

    Read only

    atlas_service_reviews_get

    Read one incident review in full, including its contributing factors, its action items, and exactly what is still missing before it can be published.

    Scope
    service:read
    Calls
    GET /v1/service-ops/postmortems/{postmortemId}
    Example prompt
    Show me the review for INC-104 and what is still missing.

    Arguments

    FieldTypeRequiredDescription
    idstringYesReview id.

    List service reviews

    Read only

    atlas_service_reviews_list

    List incident reviews. A review holds what happened, the several factors that contributed, and the work that is changing because of it.

    Scope
    service:read
    Calls
    GET /v1/service-ops/postmortems
    Example prompt
    Which incident reviews are still open?

    Arguments

    FieldTypeRequiredDescription
    status"DRAFT" | "IN_REVIEW" | "PUBLISHED"No
    limitintegerNo

    Export service reviews report

    Read only

    atlas_service_reviews_report_export

    Export an incident review as a document. The md format returns it as Markdown text to read or quote. The pdf, xlsx and docx formats return the method and path to download the file with the same credentials, because binary content cannot travel through this tool.

    Scope
    service:read
    Calls
    GET /v1/service-ops/postmortems/{postmortemId}/report
    Example prompt
    Export the INC-42 review.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe review (postmortem) id.
    format"md" | "pdf" | "xlsx" | "docx"Nomd returns the review as Markdown text. pdf, xlsx and docx return the download request, because a binary file cannot travel through this tool.

    Transition service reviews

    Changes data

    atlas_service_reviews_transition

    Move an incident review between DRAFT, IN_REVIEW and PUBLISHED. Publishing is refused, with the full list of what is missing, until the review is complete and the incident is closed. Returns the review.

    Scope
    service:write
    Calls
    POST /v1/service-ops/postmortems/{postmortemId}/status
    Example prompt
    Send the INC-42 review for review.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe review (postmortem) id.
    status"DRAFT" | "IN_REVIEW" | "PUBLISHED"YesThe state to move the review to.
    ifMatchVersionintegerNoThe version last read. The change is refused if somebody edited the review since.

    Update service reviews

    Changes data

    atlas_service_reviews_update

    Write or edit an incident review: its summary, customer impact, detection, response and recovery narratives, what went well and poorly, where luck helped, lessons, next steps, linked problem and reviewers. Only the fields given change. Pass ifMatchVersion to refuse the edit if somebody else changed the review first. Returns the review.

    Scope
    service:write
    Calls
    PATCH /v1/service-ops/postmortems/{postmortemId}
    Example prompt
    Add our lessons learned to the INC-42 review.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe review (postmortem) id.
    titlestringNoThe review title.
    summarystringNoWhat happened, in brief.
    customerImpactstringNoHow customers were affected.
    detectionNarrativestringNoHow the fault was noticed.
    responseNarrativestringNoHow the response unfolded.
    recoveryPlanstringNoHow service was restored.
    whatWentWellstringNoWhat went well.
    whatWentPoorlystringNoWhat went poorly.
    whereWeGotLuckystringNoWhere luck, rather than design, helped.
    lessonsLearnedstringNoWhat was learned.
    nextStepsstringNoWhat happens next.
    problemIdstring | nullNoThe problem this incident belongs to. Null unlinks it.
    reviewerUserIdsarray of stringNoThe reviewers. Replaces the list.
    ifMatchVersionintegerNoThe version last read. The change is refused if somebody edited the review since.

    Get service reviews vocabulary

    Read only

    atlas_service_reviews_vocabulary_get

    The vocabularies this workspace uses: the kinds of contributing factor, the kinds of action item, and the statuses. Read this before writing to a review, so the values you send are ones the workspace actually accepts.

    Scope
    service:read
    Calls
    GET /v1/service-ops/postmortem-vocabulary
    Example prompt
    Which contributing factor kinds does this workspace accept?

    Arguments

    This tool takes no arguments.

    Create service services

    Changes data

    atlas_service_services_create

    Add a service to the catalogue that incidents and alerts are filed against, with a machine-safe key, a name, a tier and an owning team. Administrators only. Returns the service.

    Scope
    service:write
    Calls
    POST /v1/service-ops/services
    Example prompt
    Add a Checkout service at tier 1.

    Arguments

    FieldTypeRequiredDescription
    keystringYesA machine-safe key used in alert payloads: lowercase letters, numbers, dashes and underscores.
    namestringYesThe display name.
    descriptionstringNoWhat the service does.
    tierintegerNoHow critical the service is, 1 (most) to 5.
    ownerTeamIdstring | nullNoThe team that owns it.

    List service services

    Read only

    atlas_service_services_list

    The services this workspace records incidents against, with the key, the name and the tier of each. Read this to turn "the checkout service" into the id that the incident, metrics and problem tools filter by. A service can carry its own escalation ladder, which beats the workspace default.

    Scope
    service:read
    Calls
    GET /v1/service-ops/services
    Example prompt
    Which services do we record incidents against?

    Arguments

    This tool takes no arguments.

    Get service settings

    Read only

    atlas_service_settings_get

    Read the incident management settings of this workspace: the fallback people paged when nobody else resolves, whether customer updates need approval, when a war room opens automatically, the reference prefix, raw alert retention and the mitigation soak time.

    Scope
    service:read
    Calls
    GET /v1/service-ops/settings
    Example prompt
    Do customer updates need approval in this workspace?

    Arguments

    This tool takes no arguments.

    Update service settings

    Changes data

    atlas_service_settings_update

    Change the incident management settings of this workspace. Only the fields given change; fallbackUserIds replaces the whole list. Administrators only. Returns the settings after the change.

    Scope
    service:write
    Calls
    PATCH /v1/service-ops/settings
    Example prompt
    Require approval before any customer update is sent.

    Arguments

    FieldTypeRequiredDescription
    fallbackUserIdsarray of stringNoPeople paged when no rotation or policy resolves to anybody, in order. Replaces the list.
    requireCustomerUpdateApprovalbooleanNoWhether a customer update needs approval before it can be sent.
    autoCreateWarRoomChannelbooleanNoWhether a war room channel opens automatically.
    autoCreateWarRoomAtRankintegerNoThe severity rank at or below which the war room opens automatically. Lower is worse.
    referencePrefixstringNoThe prefix of incident references, for example INC.
    storeAlertRawPayloadDaysintegerNoHow many days raw alert payloads are kept. 0 keeps none.
    mitigationSoakMinutesintegerNoHow long a mitigated incident is watched before it is suggested for resolution.

    List service severity levels

    Read only

    atlas_service_severity_levels_list

    The severity catalogue this workspace actually uses, in rank order, with what each level means and the response it expects. Read this before quoting or setting a severity, so the key you use is one this workspace defines rather than one you assumed. Read only: the catalogue is the vocabulary every past incident is already recorded in, so changing it is a settings decision.

    Scope
    service:read
    Calls
    GET /v1/service-ops/severity-levels
    Example prompt
    What do our severity levels mean?

    Arguments

    This tool takes no arguments.

    Update service severity levels

    Changes data

    atlas_service_severity_levels_update

    Edit one severity level: its label, description, rank, paging urgency, acknowledgement target, customer update cadence, whether it is the default, or retire it. The key cannot change, because past incidents store it. Administrators only. Returns the level.

    Scope
    service:write
    Calls
    PATCH /v1/service-ops/severity-levels/{levelId}
    Example prompt
    Rename SEV1 to Critical and promise updates every 30 minutes.

    Arguments

    FieldTypeRequiredDescription
    idstringYesThe severity level id, from atlas_service_severity_levels_list.
    labelstringNoThe display label.
    descriptionstring | nullNoWhat this level means. Null clears it.
    rankintegerNoThe ordering. Lower is worse.
    pagingUrgency"HIGH" | "LOW" | "NONE"NoHow urgently responders are paged.
    responseTargetMinutesinteger | nullNoThe acknowledgement target in minutes. Null removes it.
    commsCadenceMinutesinteger | nullNoHow often customers are promised an update at this level, in minutes. Null promises nothing.
    isDefaultbooleanNoMake this the level used when none is given.
    retiredbooleanNoRetire the level so it can no longer be chosen. Past incidents keep it.

    Apply service severity presets

    Changes data

    atlas_service_severity_presets_apply

    Replace the severity catalogue of this workspace with a preset, such as SEV1 to SEV5 or P1 to P5. Existing incidents keep the key and rank they were declared at. Administrators only. Returns the new levels as items.

    Scope
    service:write
    Calls
    POST /v1/service-ops/severity-levels/apply-preset
    Example prompt
    Switch our severity levels to P1 to P5.

    Arguments

    FieldTypeRequiredDescription
    presetstringYesThe preset key, from atlas_service_severity_presets_list.

    List service severity presets

    Read only

    atlas_service_severity_presets_list

    The severity catalogues Atlas ships as starting points, for example the SEV1 to SEV5 ladder and the P1 to P4 one. Useful for explaining the options to somebody choosing between them. Applying a preset replaces the workspace catalogue and is not offered here.

    Scope
    service:read
    Calls
    GET /v1/service-ops/severity-presets
    Example prompt
    Which severity ladders does Atlas ship?

    Arguments

    This tool takes no arguments.