# SRE Agent - [SRE Agent documentation](https://docs.sreagent.app/index.md): Investigate alerts, fix incidents and keep work tracked with SRE Agent. - [What is SRE Agent](https://docs.sreagent.app/guides/get-started/what-is-sre-agent.md): Understand what SRE Agent does with an alert, who it is for, and which plan fits your team. - [Quickstart](https://docs.sreagent.app/guides/get-started/quickstart.md): Go from sign-up to your first AI investigation in about fifteen minutes. - [Connect your data](https://docs.sreagent.app/guides/get-started/connect-your-data.md): Add the data sources your investigations and SLOs read from, including a read-only AWS connection. - [Connect AWS with a read-only role](https://docs.sreagent.app/guides/get-started/connect-aws.md): Give SRE Agent read-only access to CloudWatch, CloudTrail and X-Ray through a role in your own AWS account. - [Triage alerts](https://docs.sreagent.app/guides/respond/alerts.md): Read, filter, acknowledge, mute and resolve the alerts your monitoring tools send to SRE Agent. - [Run and read an investigation](https://docs.sreagent.app/guides/respond/investigations.md): Start an AI investigation on an alert, read its root cause and evidence, and follow up from the result. - [Explore logs, metrics and traces](https://docs.sreagent.app/guides/respond/explore.md): Open the Explorer from an alert, scope it to one service, and read logs, metrics and traces from your own data sources. - [Set up on-call](https://docs.sreagent.app/guides/respond/on-call.md): Create a rotation, cover shifts with overrides on the calendar, choose how people are paged, and acknowledge from your phone or Slack. - [On-call notifications](https://docs.sreagent.app/guides/respond/on-call-notifications.md): Choose how you are paged, set quiet hours and acknowledge a page from your phone or Slack. - [Work incidents from Slack](https://docs.sreagent.app/guides/respond/slack.md): Connect Slack, link your account, route alerts to channels and run SRE Agent from slash commands and buttons. - [Track work on the ops board](https://docs.sreagent.app/guides/respond/ops-board.md): Use the ops board to keep incident work visible: create cards, filter and save views, set reminders and import a CSV. - [Ops board webhook and tracker sync](https://docs.sreagent.app/guides/respond/ops-board-integrations.md): Post cards to the ops board from a script or workflow, and keep cards in step with Jira, Zoho Sprints or GitHub issues. - [Connect PagerDuty](https://docs.sreagent.app/guides/respond/pagerduty.md): Page PagerDuty from SRE Agent, receive PagerDuty incidents as alerts, and keep acknowledge and resolve in step on both sides. - [Request a fix as a pull request](https://docs.sreagent.app/guides/fix/fix-requests.md): Install the GitHub App, ask for a fix in plain words, and review the draft pull request SRE Agent opens. - [Fix with Claude](https://docs.sreagent.app/guides/fix/fix-with-claude.md): Hand an alert or investigation to Claude Code on your own machine and see the result come back. - [Improve your alert rules](https://docs.sreagent.app/guides/fix/alert-suggestions.md): Turn noisy or weak alert rules into evidenced suggestions you can apply as a pull request, apply to Grafana, or dismiss. - [Set up SLOs](https://docs.sreagent.app/guides/prevent/slos.md): Create service level objectives from your own metrics, read compliance and error budget, and know what degraded and suspended mean. - [SLO settings and data sources](https://docs.sreagent.app/guides/prevent/slo-reference.md): Reference for SLO alert thresholds, tracking failure settings and the data sources an SLI can read. - [Monitor endpoints with synthetic checks](https://docs.sreagent.app/guides/prevent/synthetic-checks.md): Probe HTTP, TCP and DNS targets on a schedule, read uptime windows, and feed the results into an SLO. - [Publish a status page](https://docs.sreagent.app/guides/prevent/status-page.md): Set up a public status page with components, post incidents with an AI-drafted update, and share feeds with your customers. - [Gate deploys on reliability](https://docs.sreagent.app/guides/prevent/deploy-gate.md): Ask SRE Agent whether a service is safe to deploy from your pipeline, understand a blocked answer, and unblock it. - [Write and run runbooks](https://docs.sreagent.app/guides/prevent/runbooks.md): Install a recipe or build a runbook step by step, rehearse it with a dry run, approve it, and let it run from an alert, a schedule or a button. - [Runbook actions and step reference](https://docs.sreagent.app/guides/prevent/runbook-actions.md): Look up what each connector can do, how templates and fan-out work, how to verify a step's output, and why a step fails. - [Run runbooks as automations](https://docs.sreagent.app/guides/prevent/automations.md): Wire alerts to approved runbooks, approve or reject runs, and read the history of everything that ran. - [Use the Control Tower](https://docs.sreagent.app/guides/prevent/control-tower.md): Turn on the Control Tower, read its brief and findings, act on them or open a fix pull request, and dismiss what you do not need. - [Control Tower tickets and multi-organization view](https://docs.sreagent.app/guides/prevent/control-tower-details.md): How critical findings open tickets automatically, and how to review findings across all your organizations. - [Review security findings](https://docs.sreagent.app/guides/security-cost/security.md): Work through misplaced credentials, expiring certificates, unusual API activity, access denials and IAM findings on the Security page. - [Read the Network Map](https://docs.sreagent.app/guides/security-cost/network-map.md): Explore your Kubernetes and AWS topology, filter it by type, and tell observed links from guesses and permitted paths. - [Find and reclaim cloud waste](https://docs.sreagent.app/guides/security-cost/finops.md): Review idle, over-provisioned and orphaned resources, assign owners, and resolve cost findings from the Efficiency and FinOps pages. - [Generate compliance evidence](https://docs.sreagent.app/guides/security-cost/compliance.md): Check control status for ISO 27001, SOC 2, CIS AWS Foundations and NIST CSF, run an access review, and export a checksummed bundle for an audit period. - [Manage people and roles](https://docs.sreagent.app/guides/administer/organizations-and-roles.md): Invite teammates, set roles, review what each role can do, and group people into teams. - [Run parent and child organizations](https://docs.sreagent.app/guides/administer/parent-and-child-organizations.md): Create child organizations, mirror members, copy configuration, and understand what a child inherits. - [Sign in and join your team](https://docs.sreagent.app/guides/administer/sign-in-and-joining-your-team.md): Sign in with GitHub or Google, ask to join your team's organization, and control who can ask. - [Set up single sign-on](https://docs.sreagent.app/guides/administer/single-sign-on.md): Verify your domain, connect an OIDC or SAML identity provider, map groups to roles, and sign in with SSO. - [Control data privacy and retention](https://docs.sreagent.app/guides/administer/data-privacy-and-retention.md): Mask sensitive values before they reach an AI provider, set how long records are kept, export retention evidence, and delete an organization. - [Choose a plan and manage billing](https://docs.sreagent.app/guides/administer/plans-and-billing.md): Compare the plans, start the 14-day trial, preview a plan change before it bills, and cancel from Manage billing. - [Plan matrix](https://docs.sreagent.app/guides/reference/plan-matrix.md): See which features, allowances and support each SRE Agent plan includes. - [Limits](https://docs.sreagent.app/guides/reference/limits.md): Look up every limit you can reach: plan allowances, request rates, payload sizes, imports and override durations. - [Webhook endpoints](https://docs.sreagent.app/guides/reference/webhook-endpoints.md): Look up every inbound webhook URL, what it does, how it authenticates and which response codes to expect. - [Troubleshooting](https://docs.sreagent.app/guides/reference/troubleshooting.md): Match what you see to its cause and fix: missing alerts, investigations that do not start, undelivered pages, refused runbook steps, missing Slack messages, declined fixes, SLO problems and a locked deploy gate. - [API authentication and conventions](https://docs.sreagent.app/api-reference/overview.md): Authenticate with an API key or personal token, pick the right scope, and read or change your organization's configuration over HTTP. - [MCP tools](https://docs.sreagent.app/api-reference/mcp.md): Connect an MCP client to your organization and see every tool it can call, grouped by the access it needs. - [Read the AWS external ID](https://docs.sreagent.app/api-reference/aws_external_id/read-the-aws-external-id.md): The organization's AWS ExternalId and the platform principal a customer's IAM role trusts, the two values the Settings data source form shows for an assumed role. The ExternalId is minted on first read, the same way the form mints it. Never answers a data source's role or credentials. - [Read one image target](https://docs.sreagent.app/api-reference/image_targets/read-one-image-target.md): One image scan target by id, the same fields list_image_targets answers for it. Needs the infrastructure suite. - [Delete an image target](https://docs.sreagent.app/api-reference/image_targets/delete-an-image-target.md): Stop scanning an image and delete its scan history. An image a cluster or ECS discovery filed (discovered: true) is filed again by the next discovery run while that estate still runs it. Needs confirm: true. Needs the infrastructure suite. - [List image targets](https://docs.sreagent.app/api-reference/image_targets/list-image-targets.md): List the container images this organization scans for known vulnerabilities, with the newest scan beside each one: last_scan_status, the critical, high, medium and low counts, and scanned_at, which is when that scan finished. last_scanned_at is the target's own stamp, written when a scan completes o… - [Create an image target](https://docs.sreagent.app/api-reference/image_targets/create-an-image-target.md): Scan a container image for known vulnerabilities. The platform scans the image's packages and records what is known against them, so name the image the way the registry does, tag and all (registry.example.com/acme/api:1.4.2). One row per image per organization: an image two clusters run is one targe… - [Read one outbound config](https://docs.sreagent.app/api-reference/outbound_configs/read-one-outbound-config.md): One outbound target by id, the same fields list_outbound_configs answers for it. No token is ever returned. - [Update an outbound config](https://docs.sreagent.app/api-reference/outbound_configs/update-an-outbound-config.md): Change one target, named by the id list_outbound_configs reports; omitted fields keep their value. An omitted api_key or routing_key keeps the stored token, and an empty one is refused rather than read as a way to remove it. - [Delete an outbound config](https://docs.sreagent.app/api-reference/outbound_configs/delete-an-outbound-config.md): Remove a target, the tokens stored on it and every escalation rule that routes through it. The refusal says how many rules those are, because they go with it and nothing pages afterwards to say so. Needs confirm: true. - [List outbound configs](https://docs.sreagent.app/api-reference/outbound_configs/list-outbound-configs.md): Where this organization escalates its alerts, as the Settings page's Outbound Alerting card lists them: the system each target reaches, whether it is enabled and in what order it is tried, with rule_count saying how many escalation rules route through it. No token is ever returned; api_key_set and r… - [Create an outbound config](https://docs.sreagent.app/api-reference/outbound_configs/create-an-outbound-config.md): Add a target this organization escalates alerts to. provider_type is one of pagerduty, grafana, webhook, slack, oncall_schedule. PagerDuty pages with routing_key, a webhook and Grafana are reached at base_url, a Slack target pages the channel slack_channel names in this organization's own connected… - [List deploy policies](https://docs.sreagent.app/api-reference/deploy_policies/list-deploy-policies.md): The deploy gate's policies, one per service, as the Settings page's Deploy Policies tab shows them: the error budget threshold under which deploys are held, the two block switches, and whether the service is frozen. `frozen` is true only while a freeze is still holding deploys; a window that has pas… - [Create a deploy policy](https://docs.sreagent.app/api-reference/deploy_policies/create-a-deploy-policy.md): Create the deploy gate's policy for one service: the error budget threshold under which its deploys are held, and whether a high burn rate or an active critical incident holds them too. One policy per service. It freezes nothing: a freeze is set_deploy_freeze, and the audited override is not availab… - [Read one deploy policy](https://docs.sreagent.app/api-reference/deploy_policies/read-one-deploy-policy.md): One deploy policy by id, the same fields list_deploy_policies answers for it. - [Update a deploy policy](https://docs.sreagent.app/api-reference/deploy_policies/update-a-deploy-policy.md): Change one deploy policy, named by the id list_deploy_policies reports. Only the fields you send change. Sending service renames the service the policy gates, which is what the page's own form does. The freeze is set and lifted with set_deploy_freeze and clear_deploy_freeze, and the audited override… - [Delete a deploy policy](https://docs.sreagent.app/api-reference/deploy_policies/delete-a-deploy-policy.md): Delete a deploy policy by id. Deploys of that service are then gated by the defaults, and any freeze on it goes with it. Needs confirm: true. - [List status page components](https://docs.sreagent.app/api-reference/status_page_components/list-status-page-components.md): This organization's status page components, the same shape get_status_page answers them under "components", as its own list. Needs the status page feature. - [Create a status page component](https://docs.sreagent.app/api-reference/status_page_components/create-a-status-page-component.md): Add a customer-facing unit to the page ("API", "Dashboard"). Its public status is the worst of the SLOs it publishes, so a component with no SLO linked reports nothing. It is appended to the end of the page's order; use update_status_page_component's move to place it. - [Read one status page component](https://docs.sreagent.app/api-reference/status_page_components/read-one-status-page-component.md): One component by id, the same fields get_status_page answers for it in its components list. Answers an archived component too, since it is still addressable. - [Update a status page component](https://docs.sreagent.app/api-reference/status_page_components/update-a-status-page-component.md): Rename a component, change its description, replace the SLOs it publishes, or move it one place up or down the page. slo_ids is the full set rather than an addition: send [] to unlink everything, or omit it to leave the links alone. An archived component is refused: it is off the page, and nothing h… - [Delete a status page component](https://docs.sreagent.app/api-reference/status_page_components/delete-a-status-page-component.md): Take a component off the public page. The row is kept rather than deleted, so past incidents still name what they affected, and the SLOs it published are untouched. There is no tool to bring it back: a component archived by mistake is re-created with create_status_page_component, under a new id. Nee… - [List ticket import rules](https://docs.sreagent.app/api-reference/ticket_import_rules/list-ticket-import-rules.md): The standing import rules this organization has, one per tracker: which of that tracker's issues become cards, whether the rule is on, when it last ran and what that run did. A tracker with no rule is absent rather than answered empty. This is the only tool that answers a rule: GitHub has no credent… - [Create a ticket import rule](https://docs.sreagent.app/api-reference/ticket_import_rules/create-a-ticket-import-rule.md): Say which of a tracker's issues become cards on their own, one standing rule per tracker. An issue the rule names gets a card in Triage with its tracker item already linked, so a team that files in their own tracker still sees the work on the board. Saving a rule imports nothing by itself: it decide… - [Read one ticket import rule](https://docs.sreagent.app/api-reference/ticket_import_rules/read-one-ticket-import-rule.md): One tracker's import rule by provider, the same fields list_ticket_import_rules answers for it. Refused when that tracker has no rule. - [Update a ticket import rule](https://docs.sreagent.app/api-reference/ticket_import_rules/update-a-ticket-import-rule.md): Say which of a tracker's issues become cards on their own, one standing rule per tracker. An issue the rule names gets a card in Triage with its tracker item already linked, so a team that files in their own tracker still sees the work on the board. Saving a rule imports nothing by itself: it decide… - [Delete a ticket import rule](https://docs.sreagent.app/api-reference/ticket_import_rules/delete-a-ticket-import-rule.md): Delete the import rule for one tracker, so nothing more is imported from it. Items already imported stay on the board. Stays open on a plan that no longer includes ticket systems, like removing the tracker's credentials. Needs confirm: true. - [Read one compliance period](https://docs.sreagent.app/api-reference/compliance_periods/read-one-compliance-period.md): One audit window by id, the same fields list_compliance_periods answers for it. Needs the compliance feature. - [List compliance periods](https://docs.sreagent.app/api-reference/compliance_periods/list-compliance-periods.md): The audit windows this organization has opened, latest window first: the name, the framework, the range an export speaks for, whether the bundle has been exported and the hash it was stamped with. The evidence itself is not here; it stays in the source tables until an export freezes it. Needs the co… - [Create a compliance period](https://docs.sreagent.app/api-reference/compliance_periods/create-a-compliance-period.md): Open an audit window, which is the Compliance page's Create period: the range of time one evidence export speaks for. Creating it writes no evidence and freezes nothing; the bundle is exported from the Compliance page once the window has passed, and the export stamps the period with its manifest's h… - [Read one service binding](https://docs.sreagent.app/api-reference/service_bindings/read-one-service-binding.md): The stored override binding for `service` (and `environment`, default ""), the same shape set_service_binding answers back. This is the organization's own override row, not the resolved view: resolve_service_bindings answers what the Explorer actually queries once AWS discovery and the OpenTelemetry… - [Update a service binding](https://docs.sreagent.app/api-reference/service_bindings/update-a-service-binding.md): Correct what a service is called in one telemetry backend: the log groups, log filter, X-Ray service names and metric selectors the Explorer binds for `service` (and `environment`, default ""), overriding AWS discovery and the OpenTelemetry convention. An OMITTED column keeps its stored value (or st… - [Delete a service binding](https://docs.sreagent.app/api-reference/service_bindings/delete-a-service-binding.md): Remove the override binding for `service` (and `environment`, default ""), so the Explorer falls back to AWS discovery and the OpenTelemetry convention for it. Refused when there is no such binding. - [List service bindings](https://docs.sreagent.app/api-reference/service_bindings/list-service-bindings.md): Every Explorer telemetry binding override this organization has stored, service by service (and environment). - [Create a service binding](https://docs.sreagent.app/api-reference/service_bindings/create-a-service-binding.md): Correct what a service is called in one telemetry backend: the log groups, log filter, X-Ray service names and metric selectors the Explorer binds for `service` (and `environment`, default ""), overriding AWS discovery and the OpenTelemetry convention. An OMITTED column keeps its stored value (or st… - [Read the organization settings](https://docs.sreagent.app/api-reference/organization_settings/read-the-organization-settings.md): The organization's preferences as the Settings page shows them: timezone, alert storm grouping, the alert re-fire cooldown, automation approval TTL, investigation cooldown and pause, auto-incident bridge, monthly AI budget, and the two sign-up policies. - [Update the organization settings](https://docs.sreagent.app/api-reference/organization_settings/update-the-organization-settings.md): Change one or more preferences; omitted ones keep their value. Ranges are the page's: storm threshold at least 3, storm window 60..3600 seconds, re-fire cooldown 0..1440 minutes (0 pages on every re-fire), approval TTL 5..1440 minutes, investigation cooldown 0..1440 (0 disables), severity floor crit… - [List alert mutes](https://docs.sreagent.app/api-reference/alert_mutes/list-alert-mutes.md): Every alert mute this organization has, in force or expired: what each one suppresses, why, when it expires, where it came from, and whether it is currently in force (active). ends_at null means the mute lasts until it is removed; a non-null ends_at in the past means it has already expired, and is k… - [Create an alert mute](https://docs.sreagent.app/api-reference/alert_mutes/create-an-alert-mute.md): Stop alerts matching a pattern from paging. The pattern is a substring, matched without case against the alert's title, source and fingerprint, and stored lowercased: "highcpu" silences every alert whose title contains it, whatever its severity. duration_minutes is 1..10080 (one week); omit it for a… - [Read one alert mute](https://docs.sreagent.app/api-reference/alert_mutes/read-one-alert-mute.md): One alert mute by id, the same fields list_alert_mutes answers for it. - [Delete an alert mute](https://docs.sreagent.app/api-reference/alert_mutes/delete-an-alert-mute.md): Remove a mute, so alerts matching its pattern page again. No confirmation step, unlike the deletes that remove configuration: un-silencing is the safe direction, and list_alert_mutes answers everything needed to set the same mute again. - [List AI providers](https://docs.sreagent.app/api-reference/ai_providers/list-ai-providers.md): The AI providers this organization pays for with its own keys, as the Settings page's AI Providers card lists them: the model each one runs, where its calls are sent, whether it is enabled and in what order the router tries it. No key is ever returned; api_key_set says whether one is stored. - [Create an AI provider](https://docs.sreagent.app/api-reference/ai_providers/create-an-ai-provider.md): Add an AI provider this organization's own key pays for. provider is one of anthropic, openai, openrouter, ollama, bedrock, gemini, portkey, langchain. model_overrides pins a model per purpose, keyed by purpose: investigation, suggestion, report_generation, alert_grouping, context_compaction, pr_rev… - [Read one AI provider](https://docs.sreagent.app/api-reference/ai_providers/read-one-ai-provider.md): One AI provider by id, the same fields list_ai_providers answers for it. No key is ever returned. - [Update an AI provider](https://docs.sreagent.app/api-reference/ai_providers/update-an-ai-provider.md): Change one provider, named by the id list_ai_providers reports; omitted fields keep their value. An omitted api_key keeps the stored key, and an empty one is refused rather than read as a way to remove it. model_overrides merges per purpose, so a partial map keeps the pins it does not name, and an e… - [Delete an AI provider](https://docs.sreagent.app/api-reference/ai_providers/delete-an-ai-provider.md): Remove a provider and the key stored on it. The organization's AI work then runs on whichever provider is left, or on the platform's own, unless own_providers_only is on, in which case AI work fails until a provider is added. This is the one write here that does NOT need the bring-your-own-provider… - [Read one team](https://docs.sreagent.app/api-reference/teams/read-one-team.md): One team and its members by id, the same shape list_teams answers for it. - [Update a team](https://docs.sreagent.app/api-reference/teams/update-a-team.md): Rename a team. Everything it owns follows the rename, since ownership is by id: nothing is re-pointed and nothing is lost. Sending the name it already has is refused rather than recorded as a rename. - [Delete a team](https://docs.sreagent.app/api-reference/teams/delete-a-team.md): Delete a team. What it owned keeps existing with no owner: workloads, findings and cards are not deleted with it, they stop being anybody's. The people on it keep their accounts and their other teams. There is no tool to bring it back, and a new team of the same name is a different id that owns noth… - [List teams](https://docs.sreagent.app/api-reference/teams/list-teams.md): This organization's teams and who is on each of them, in name order. A team attributes work: it says who owns a workload, who hears about a finding, who a card goes to. It grants nothing, so being on one changes what somebody is told and never what they may do. Each member is answered by id, email a… - [Create a team](https://docs.sreagent.app/api-reference/teams/create-a-team.md): Open a new team. The name is unique within this organization and nothing else is set: add the people with add_team_member, which takes the id this answers. - [Read the status page settings](https://docs.sreagent.app/api-reference/status_page_settings/read-the-status-page-settings.md): This organization's public status page as the admin sees it: whether it is published, its title, description, branding, support link, history window, time zone and visitor options, the components customers read down the page, with the SLOs each publishes, and how many incidents are unresolved right… - [Update the status page settings](https://docs.sreagent.app/api-reference/status_page_settings/update-the-status-page-settings.md): Change one or more of the page's settings; omitted ones keep their value. enabled is the publish switch: on, the page is served to anybody with the link, off, visitors get a 404. show_history_days is 7..90, the window the page can draw; timezone is an IANA zone name and is what every timestamp custo… - [Read one connector](https://docs.sreagent.app/api-reference/connectors/read-one-connector.md): One connector by id, the same fields list_connectors answers for it. Credentials are never returned. - [Update a connector](https://docs.sreagent.app/api-reference/connectors/update-a-connector.md): Update a connector by id (name, config, metadata, enabled). Passing config replaces the stored credentials. - [Delete a connector](https://docs.sreagent.app/api-reference/connectors/delete-a-connector.md): Delete a connector by id. Needs confirm: true. - [List connectors](https://docs.sreagent.app/api-reference/connectors/list-connectors.md): List this organization's infrastructure connectors (credentials are never returned). Also answers its integration health: last_error_at, last_error_kind (auth_invalid, assume_role_denied, access_denied, malformed_query, throttled, network, other), last_error_message (a sanitized sentence), consecuti… - [Create a connector](https://docs.sreagent.app/api-reference/connectors/create-a-connector.md): Create an infrastructure connector a runbook step can act through. connector_type is one of kubernetes, ssh, aws_ecs, aws_lambda, aws_ec2, aws_eks. aws_eks is for discovery: it lists EKS clusters and the workloads Container Insights reports, and like every AWS connector it also discovers the account… - [Read one ticket integration](https://docs.sreagent.app/api-reference/ticket_integrations/read-one-ticket-integration.md): One ticket system's connection by provider, the same fields list_ticket_integrations answers for it. No credential is ever returned. - [Update a ticket integration](https://docs.sreagent.app/api-reference/ticket_integrations/update-a-ticket-integration.md): Save this organization's credentials for one ticket system, one row per provider. Zoho Sprints authenticates with client_id, client_secret and refresh_token against auth_url; Jira with account_email and api_token. Only the fields you send change, an omitted secret keeps the stored one, and the board… - [Delete a ticket integration](https://docs.sreagent.app/api-reference/ticket_integrations/delete-a-ticket-integration.md): Remove this organization's credentials for one ticket system, with the board column mapping and the create destination stored beside them. Cards already linked to an item keep their link and stop syncing, and nothing is changed in the ticket system itself. To stop writing into it without giving up t… - [List ticket integrations](https://docs.sreagent.app/api-reference/ticket_integrations/list-ticket-integrations.md): The ticket systems this organization writes into, as the Integrations page's Tickets tab lists them: the provider (zoho_sprints, jira), whether it is enabled, the API host, the board columns mapped onto its workflow, and where a new item would be filed. No credential is ever returned: client_secret_… - [Create a ticket integration](https://docs.sreagent.app/api-reference/ticket_integrations/create-a-ticket-integration.md): Save this organization's credentials for one ticket system, one row per provider. Zoho Sprints authenticates with client_id, client_secret and refresh_token against auth_url; Jira with account_email and api_token. Only the fields you send change, an omitted secret keeps the stored one, and the board… - [Read one SLO](https://docs.sreagent.app/api-reference/slos/read-one-slo.md): One SLO by id, the same fields list_slos answers for it. - [Update an SLO](https://docs.sreagent.app/api-reference/slos/update-an-slo.md): Update an SLO by id (name, target, window_days, status). Writing status: "suspended" also resolves the SLO's still-open slo_breach/slo_tracking alerts, the same as delete_slo does; a suspended SLO computes nothing, so nothing else was ever going to clear them. - [Delete an SLO](https://docs.sreagent.app/api-reference/slos/delete-an-slo.md): Delete an SLO by id, along with its measurement history. Needs confirm: true. Any of its still-open slo_breach/slo_tracking alerts (Fast Burn Rate, Slow Burn Rate, Error Budget Exhausted, Error Budget Warning, tracking failure) are resolved through the same path the alerts page's Resolve button uses… - [List SLOs](https://docs.sreagent.app/api-reference/slos/list-slos.md): List this organization's SLOs with their targets and status. - [Create an SLO](https://docs.sreagent.app/api-reference/slos/create-an-slo.md): Create an SLO against an existing SLI. target is a percentage (e.g. 99.9), window_days defaults to 30. - [Read one prompt template](https://docs.sreagent.app/api-reference/prompt_templates/read-one-prompt-template.md): One prompt template by id, the same fields list_prompt_templates answers for it. - [Update a prompt template](https://docs.sreagent.app/api-reference/prompt_templates/update-a-prompt-template.md): Change a template's name, description, content or switches; omitted ones keep their value, and a call naming only the id is refused rather than recorded as a change. The content is rescanned on every write and the scan can only ever flag: a template the scanner has flagged stays flagged and disabled… - [Delete a prompt template](https://docs.sreagent.app/api-reference/prompt_templates/delete-a-prompt-template.md): Delete a prompt template. Its content is not kept anywhere else and nothing on this surface puts it back; deleting the default for a type leaves that type on the built-in prompt. Needs confirm: true. - [List prompt templates](https://docs.sreagent.app/api-reference/prompt_templates/list-prompt-templates.md): The prompts this organization's AI work runs on, as the Settings page's Prompts card lists them: the system and user prompts for investigations, the root cause analysis and the Slack assistant, plus any custom ones. Each answers its full content, which is the point of reading it, with its type, whet… - [Create a prompt template](https://docs.sreagent.app/api-reference/prompt_templates/create-a-prompt-template.md): Write a new prompt template for this organization. prompt_type is one of investigation_system, investigation_user, slack_assistant, root_cause, custom and is fixed once written: a template for another type is another template. The content is scanned for injection patterns as it is stored, and a temp… - [List synthetic checks](https://docs.sreagent.app/api-reference/synthetic_checks/list-synthetic-checks.md): List this organization's synthetic checks with their current state (last status, last run, consecutive failures). Optionally filter by enabled or check_type. - [Create a synthetic check](https://docs.sreagent.app/api-reference/synthetic_checks/create-a-synthetic-check.md): Create a synthetic check that probes a target on an interval and alerts on failure. check_type is one of http, tcp, dns. `target` is an http(s):// URL for http, and a hostname for tcp and dns. `config` is per-type: tcp requires {"port": 443}; dns requires {"record_type": "a"} (a, aaaa, cname, mx, tx… - [Read one synthetic check](https://docs.sreagent.app/api-reference/synthetic_checks/read-one-synthetic-check.md): One synthetic check by id, the same fields list_synthetic_checks answers for it. - [Update a synthetic check](https://docs.sreagent.app/api-reference/synthetic_checks/update-a-synthetic-check.md): Update a synthetic check by id. Only the fields you pass are changed. Pass enabled:false to pause a check without deleting it and losing its history. - [Delete a synthetic check](https://docs.sreagent.app/api-reference/synthetic_checks/delete-a-synthetic-check.md): Delete a synthetic check and its probe-result history. To stop probing but keep the history, call update_synthetic_check with enabled:false instead. Needs confirm: true. - [Read one data source](https://docs.sreagent.app/api-reference/data_sources/read-one-data-source.md): One data source by id, the same fields list_data_sources answers for it. No secret is ever returned. - [Update a data source](https://docs.sreagent.app/api-reference/data_sources/update-a-data-source.md): Update a data source by id (name, url, enabled, regions, auth_type, auth_credentials). auth_credentials replaces the stored credentials; leave it out to keep them. For AWS assume-role the organization's ExternalId is applied automatically, as on create. - [Delete a data source](https://docs.sreagent.app/api-reference/data_sources/delete-a-data-source.md): Delete a data source by id. Needs confirm: true. - [List data sources](https://docs.sreagent.app/api-reference/data_sources/list-data-sources.md): List this organization's data sources: name, type, url, enabled and regions. A source that assumes an AWS role also answers role_arn and aws_account_id (the account segment of that ARN), so sources sharing one role are visible without opening each source. Also answers its integration health: last_er… - [Create a data source](https://docs.sreagent.app/api-reference/data_sources/create-a-data-source.md): Create a data source (prometheus, loki, grafana, cloudwatch_metrics, cloudwatch_logs, cloudtrail, xray, datadog_metrics, datadog_logs, newrelic_metrics, newrelic_logs, elasticsearch). For AWS assume-role the organization's ExternalId is applied automatically; pass role_arn in auth_credentials. For A… - [Export this organization's configuration as Terraform](https://docs.sreagent.app/api-reference/export/export-this-organizations-configuration-as-terraform.md): One Terraform file: a resource block and an import block per row this organization manages here, configuration fields only. A stored secret appears only as a commented pointer to the write-only argument that would manage it. Archived, inherited and discovered rows are counted in comments, and a reso… - [List SLIs](https://docs.sreagent.app/api-reference/slis/list-slis.md): List this organization's SLIs. - [Create an SLI](https://docs.sreagent.app/api-reference/slis/create-an-sli.md): Create an SLI. sli_type is one of latency, error_rate, availability, throughput, saturation. Link it to a data source with data_source_id and give it a query. The SLI's query type is the type of that data source, so an SLI created without one is a draft that nothing computes until a data source is s… - [Read one SLI](https://docs.sreagent.app/api-reference/slis/read-one-sli.md): One SLI by id, the same fields list_slis answers for it. - [Update an SLI](https://docs.sreagent.app/api-reference/slis/update-an-sli.md): Update an SLI by id (name, service, query, data_source_id, status). Setting data_source_id also sets the SLI's query type to that source's type, which is how a draft SLI is made computable. Write the query in that source's own query language. - [Delete an SLI](https://docs.sreagent.app/api-reference/slis/delete-an-sli.md): Delete an SLI by id. If SLOs are built on it, the delete also removes them and their measurement history, so it is REFUSED unless you pass cascade: true to confirm. Any of those SLOs' still-open slo_breach/slo_tracking alerts are resolved too, the same as delete_slo does. - [Read the overseer settings](https://docs.sreagent.app/api-reference/overseer_settings/read-the-overseer-settings.md): The Control Tower's configuration as its settings card shows it: whether the overseer is on, how often it runs, how assertive it may be, the token and tool-call ceilings one run may spend, whether the digest is sent, when the next run is due and why the last one was skipped. Reading this creates the… - [Update the overseer settings](https://docs.sreagent.app/api-reference/overseer_settings/update-the-overseer-settings.md): Change one or more of the Control Tower's settings; omitted ones keep their value. Turning the overseer on schedules its first run straight away, which is what the page's save does. Hourly and every_6h are the top plan's alone: every plan below it is refused and floors at daily or weekly. Needs the… - [List alert routes](https://docs.sreagent.app/api-reference/alert_routes/list-alert-routes.md): Where this organization routes one service's alerts, as the Settings page's Per-Service Alert Channels card lists them: the service, the Slack channel its alerts open in, whether the route is enabled, and the on-call schedule (if any) mentioned in the alert's thread. A disabled route means the servi… - [Create an alert route](https://docs.sreagent.app/api-reference/alert_routes/create-an-alert-route.md): Save where one service's alerts open in Slack, and which on-call schedule (if any) is mentioned in the thread when one opens. Upserts on the service, so a service that already has a route has its row edited rather than a second one grown; the save describes the route's WHOLE state, so an edit that o… - [Read one alert route](https://docs.sreagent.app/api-reference/alert_routes/read-one-alert-route.md): One alert route by id, the same fields list_alert_routes answers for it. - [Update an alert route](https://docs.sreagent.app/api-reference/alert_routes/update-an-alert-route.md): Save where one service's alerts open in Slack, and which on-call schedule (if any) is mentioned in the thread when one opens. Upserts on the service, so a service that already has a route has its row edited rather than a second one grown; the save describes the route's WHOLE state, so an edit that o… - [Delete an alert route](https://docs.sreagent.app/api-reference/alert_routes/delete-an-alert-route.md): Remove a route, named by the id list_alert_routes reports. The service's alerts return to the severity channels. Needs confirm: true. - [Read one repo setting](https://docs.sreagent.app/api-reference/repo_settings/read-one-repo-setting.md): One repository's fix settings by the row id list_repo_settings or create_repo_settings answered, as the whole repository's view: every branch row and the fix_runner, the same shape list_repo_settings answers per repository. - [Update a repo setting](https://docs.sreagent.app/api-reference/repo_settings/update-a-repo-setting.md): Change one repository settings row, named by the id list_repo_settings reports. Only the fields you send change, so sending fix_runner on its own is legal; a field sent as null is cleared (a null branch makes the row the all-branches row, a null service removes the alias). The repository itself cann… - [Delete a repo setting](https://docs.sreagent.app/api-reference/repo_settings/delete-a-repo-setting.md): Remove one repository settings row, named by the id list_repo_settings reports. The repository stays targetable by a fix request: it simply returns to a detected write fence and the platform runner. Answers the repository's remaining rows in the shape list_repo_settings answers, with an empty `branc… - [List repo settings](https://docs.sreagent.app/api-reference/repo_settings/list-repo-settings.md): List this organization's per-repository fix settings: each row's id, the branch it applies to (null means all branches), the service alias, the environment, and the write fence (path prefix and writable extensions). Each repository also reports `fix_runner`, which says who executes its fix requests:… - [Create a repo setting](https://docs.sreagent.app/api-reference/repo_settings/create-a-repo-setting.md): Create the settings row for one repository the GitHub App can reach: the write fence remediation obeys, an optional service alias, and which runner executes the repository's fix requests. A repository the App does not reach is refused rather than saved, because the fix pipeline would never read the… - [Read one status page incident](https://docs.sreagent.app/api-reference/status_page_incidents/read-one-status-page-incident.md): One incident by id, the same fields list_status_page_incidents answers for it. Answers an archived incident too, since it is still addressable. - [Update a status page incident](https://docs.sreagent.app/api-reference/status_page_incidents/update-a-status-page-incident.md): Add a line to an incident that is already published. message is what customers read. Passing status moves the incident to that phase; omitting it, or passing the phase it is already in, posts the note and leaves the phase where it is. That difference is load-bearing: moving an incident to resolved s… - [Delete a status page incident](https://docs.sreagent.app/api-reference/status_page_incidents/delete-a-status-page-incident.md): Take a resolved incident off the public page and out of its history. The row and its timeline are kept rather than deleted, so the record survives, and an incident that is not resolved is refused: archiving an open one would hide a problem customers are living through. There is no tool to bring it b… - [List status page incidents](https://docs.sreagent.app/api-reference/status_page_incidents/list-status-page-incidents.md): What this organization's public status page is telling customers: the unresolved incidents first, then the resolved ones still inside the page's history window, newest first. Each carries its phase, its impact, the components it names and its whole timeline of updates. Archived incidents are left ou… - [Create a status page incident](https://docs.sreagent.app/api-reference/status_page_incidents/create-a-status-page-incident.md): Publish an incident on the public page. first_update is the opening note customers read, and it is part of the incident rather than a follow-up: every incident the page opens posts one. An incident of major, critical or maintenance impact also emails this organization's own notification recipients,… - [List team members](https://docs.sreagent.app/api-reference/team_members/list-team-members.md): Every team membership in this organization, one row per person per team, each with its own id: the id get_team_member reads and delete_team_member removes. - [Create a team member](https://docs.sreagent.app/api-reference/team_members/create-a-team-member.md): Put somebody on a team, named by the email address they sign in with, matched without case. They must already be a member of this organization: use invite_member first for somebody who is not, and list_members to read who is. Being on a team grants nothing, so this changes who is told about the team… - [Read one team member](https://docs.sreagent.app/api-reference/team_members/read-one-team-member.md): One team membership by its own id, as list_team_members answers it. - [Delete a team member](https://docs.sreagent.app/api-reference/team_members/delete-a-team-member.md): Take somebody off one team, naming the membership by its own id. They keep their account, their role and their other teams. Needs confirm: true. - [List certificate monitors](https://docs.sreagent.app/api-reference/certificate_monitors/list-certificate-monitors.md): List the TLS certificates this organization watches, with the newest check beside each one: last_status, days_until_expiry and expires_at. A monitor no check has run against yet answers last_status "unchecked". `discovered` is true for a monitor Kubernetes or ACM discovery filed rather than a person… - [Create a certificate monitor](https://docs.sreagent.app/api-reference/certificate_monitors/create-a-certificate-monitor.md): Watch a hostname's TLS certificate. The platform opens a TLS connection to hostname:port every check_interval_hours, records what it found, and raises an alert once the certificate is within warn_days_before of expiry and a sharper one within critical_days_before. It alerts on a certificate that fai… - [Read one certificate monitor](https://docs.sreagent.app/api-reference/certificate_monitors/read-one-certificate-monitor.md): One certificate monitor by id, the same fields list_certificate_monitors answers for it. Needs the infrastructure suite. - [Delete a certificate monitor](https://docs.sreagent.app/api-reference/certificate_monitors/delete-a-certificate-monitor.md): Stop watching a host and delete its check history. Nothing announces the certificate afterwards, including one that is already failing verification. A monitor Kubernetes or ACM discovery filed (`discovered` in the listing) comes back on the next discovery run. Needs confirm: true. Needs the infrastr… - [List outbound rules](https://docs.sreagent.app/api-reference/outbound_rules/list-outbound-rules.md): Which alerts escalate to which target, as the Settings page's Automatic Escalation Rules table lists them: what each rule matches on, the target it routes through, its cooldown, whether it pages immediately or after a delay, and when it last delivered a page. A rule whose target has only ever refuse… - [Create an outbound rule](https://docs.sreagent.app/api-reference/outbound_rules/create-an-outbound-rule.md): Escalate the alerts a rule matches to one target, once per firing per alert. A rule with no match_source, match_severity or match_labels matches every alert in the organization. The target must be one of this organization's own. Setting escalate_after_minutes makes it a timed rule instead, which pag… - [Read one outbound rule](https://docs.sreagent.app/api-reference/outbound_rules/read-one-outbound-rule.md): One escalation rule by id, the same fields list_outbound_rules answers for it. - [Update an outbound rule](https://docs.sreagent.app/api-reference/outbound_rules/update-an-outbound-rule.md): Change one rule, named by the id list_outbound_rules reports; omitted fields keep their value. - [Delete an outbound rule](https://docs.sreagent.app/api-reference/outbound_rules/delete-an-outbound-rule.md): Remove one escalation rule. The target it routed through is left alone, and the alerts it matched stop paging through it. Needs confirm: true. - [Read the AI settings](https://docs.sreagent.app/api-reference/ai_settings/read-the-ai-settings.md): How this organization's AI work is routed and retried, as the Settings page's Investigation Settings card shows it: whether calls may fall back to this deployment's shared credentials, whether prompts are redacted first, how many extra attempts one provider is given for a transient failure, and whet… - [Update the AI settings](https://docs.sreagent.app/api-reference/ai_settings/update-the-ai-settings.md): Change one or more of those switches; omitted ones keep their value. own_providers_only cannot be turned on while this organization has no enabled provider of its own, because every AI feature would then fail rather than fall back; turning it off is never refused. - [Read the notification settings](https://docs.sreagent.app/api-reference/notification_settings/read-the-notification-settings.md): Who this organization emails about what: the master switch, the recipient addresses, the four category toggles (incidents, SLO, automation, security), and muted_events, the individual events silenced inside a category that is otherwise on. Everything not in muted_events is delivered. These are the o… - [Update the notification settings](https://docs.sreagent.app/api-reference/notification_settings/update-the-notification-settings.md): Change one or more email notification settings; omitted ones keep their value. recipients and muted_events each REPLACE the stored list, so send the whole list you want (and [] to empty it). A category toggle switched off silences its events whatever the mute list says. The events that can be muted… - [Read the Slack settings](https://docs.sreagent.app/api-reference/slack/read-the-slack-settings.md): This organization's Slack integration: the enabled workspace, or the first configured one, the same row configure_slack edits. name, workspace_name, team_id, enabled, priority and the four default channels; bot_token_set, signing_secret_set and app_token_set say only whether a credential is stored.… - [Update the Slack settings](https://docs.sreagent.app/api-reference/slack/update-the-slack-settings.md): Create or update this organization's Slack integration. team_id (the T... workspace id) makes inbound routing exact, but it decides which tenant a workspace's traffic belongs to, so it is only accepted when Slack confirms the bot token belongs to that workspace: pass bot_token alongside it, or insta… - [Read the GitHub settings](https://docs.sreagent.app/api-reference/github_settings/read-the-github-settings.md): How this organization's GitHub App connection stands, as the Integrations page's GitHub tab shows it: whether one is connected, the account it is installed on, the repositories it grants, the five behaviour toggles, the severity floor inline review comments start at, the grounding context repo, whet… - [Update the GitHub settings](https://docs.sreagent.app/api-reference/github_settings/update-the-github-settings.md): Change what the connected installation does: the five toggles, the severity floor inline review comments start at (critical, high, medium, low), and the grounding context repo. Only the fields you send change, and a call that names none of them is refused rather than answered as a change. - [Read the change notifications](https://docs.sreagent.app/api-reference/change_notifications/read-the-change-notifications.md): The Slack routing for infrastructure changes (deployments, scaling, pod restarts, config changes, rollbacks): whether it is on, the channel, the event types announced and the namespace filter. Read from the workspace the Settings page's card edits, which is the enabled one, else the first configured… - [Update the change notifications](https://docs.sreagent.app/api-reference/change_notifications/update-the-change-notifications.md): Change where infrastructure changes are announced, on the workspace the Settings page's card edits (the enabled one, else the first configured); omitted settings keep their value. event_types REPLACES the stored list and an empty list announces nothing; the types are deploy, scale, restart, config_c… - [Release notes](https://docs.sreagent.app/release-notes/index.md): What you can do in SRE Agent that you could not before, one page per month. - [October 2026](https://docs.sreagent.app/release-notes/2026-10.md): What you can do in SRE Agent that you could not before, as of October 2026. - [September 2026](https://docs.sreagent.app/release-notes/2026-09.md): What you can do in SRE Agent that you could not before, as of September 2026. - [August 2026](https://docs.sreagent.app/release-notes/2026-08.md): What you can do in SRE Agent that you could not before, as of August 2026. - [July 2026](https://docs.sreagent.app/release-notes/2026-07.md): What you can do in SRE Agent that you could not before, as of July 2026. - [June 2026](https://docs.sreagent.app/release-notes/2026-06.md): What you can do in SRE Agent that you could not before, as of June 2026. - [May 2026](https://docs.sreagent.app/release-notes/2026-05.md): What you can do in SRE Agent that you could not before, as of May 2026. - [April 2026](https://docs.sreagent.app/release-notes/2026-04.md): What you can do in SRE Agent that you could not before, as of April 2026. - [March 2026](https://docs.sreagent.app/release-notes/2026-03.md): What you can do in SRE Agent that you could not before, as of March 2026. ## OpenAPI Specs - [openapi](/api-reference/openapi.json) This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.