Set up Incident Command Center

Incident Command Center is currently available through an early access program (EAP). Features, interfaces, and availability may change as we continue development.

The Incident Command Center is available to customers on the Jira Service Management Premium and Enterprise plans.

Set up the Incident Command Center (ICC) to provide your incident responders with a unified solution for triaging incidents, analyzing telemetry, coordinating communications, and conducting post-incident reviews (PIRs).

はじめる前に

Make sure you have the following prerequisites in place:

  • Confirm you’re a space admin for the relevant service space.

  • Verify your site is on Jira Service Management Premium or Enterprise plan.

  • Confirm your organization admin has enabled Rovo for your site.

  • Confirm you’ve set up all the recommended integrations.

Enable ICC for a service space

To enable the Incident Command Center for your incidents:

  1. In Jira Service Management, select the service space where you want to use the Incident Command Center.

  2. [スペース設定] を選択します。

  3. Select Operations, then select Incident management.

  4. Select the Incident Command Center section.

  5. Turn on the toggle to enable the Incident Command Center for incidents in the service space.

After you enable the Incident Command Center, responders can use the AI-powered experience when they open new incidents created in that service space.

The Incident Investigation view (accessed by selecting Investigate) is now built directly into Incident Command Center.

When you turn on Incident Command Center, your investigation tools move to the integrated Investigation tab. To keep the standalone view, you can turn off Incident Command Center for your space.

Set up Incident Command Center integrations

Connect your services, developer tools, telemetry providers, and knowledge sources to power each part of the Incident Command Center (ICC) with rich context, more accurate AI-powered analysis, and actionable recommendations.

1. Populate the service list

An accurate service catalog is the foundation of effective incident management. By mapping your services, you ensure that incoming incidents are automatically linked to the right architecture components, dependencies, and responder teams. Read how to create a service

Adding services helps the Incident Command Center in the following ways:

  • Overview: Automatically populates the Affected services field and identifies service owners. Services attached to incoming alerts automatically carry over into the incident.

  • Investigation: Uses mapped upstream and downstream references to trace blast radius, pinpoint root causes, and visualize dependency graphs.

2. Connect source control tools

By linking your source code management tools, you give responders immediate visibility into recent development activity right from the Incident Command Center.

This integration powers the Investigation tab. With information on recent commits, pull request activity, and deployment diffs, ICC can help your team identify potential root causes much faster.

Connect your repositories and deployment pipelines from Bitbucket or GitHub to enable automated deployment tracking and diff analysis. Read how to connect GitHub repositories

3. Set up observability and telemetry connectors

Give your responders a live look at system health without switching tools. Integrating your monitoring tools feeds critical metrics, logs, and service health signals directly into the Incident Command Center.

The observability and telemetry connectors help with:

  • Investigation: Metrics, log anomaly detection, and topology mapping significantly cut down troubleshooting time by surfacing real-time system behavior.

  • Mitigation: This data also feeds into Rovo suggestions, delivering actionable, context-aware recovery steps.

To integrate telemetry and monitoring tools:

  • Teamwork Graph connectors: Connect monitoring and observability platforms such as Datadog, New Relic, Dynatrace, and SignalFx to ingest telemetry and logs. Read about Teamwork Graph connectors

  • MCP connectors: Map service dependencies and architecture graphs using Compass and other Model Context Protocol (MCP) tools.

Connect documentation and communication platforms to surface runbooks, standard operating procedures (SOPs), and past incident records:

  • Confluence: Link spaces containing runbooks, post-incident reviews, and troubleshooting guides.

  • Slack, Google Drive, and Microsoft SharePoint: Integrate search connectors to index organizational knowledge and past incident discussions.

Linking rich knowledge to your Incident Command Center helps with:

  • Mitigation: Recommends relevant runbooks and recovery playbooks based on connected incident data.

  • Investigation: Draws parallels to similar past incidents to accelerate root-cause analysis.

  • Post-incident review (PIR): Provides the end-to-end context needed to automatically generate a comprehensive PIR draft once the incident is resolved.

5. Configure stakeholder communication

Keeping people informed during a critical incident is essential, but writing updates from scratch takes valuable time away from resolving the issue. Set up your communication channels in advance so responders can seamlessly broadcast updates to the right audiences.

This directly powers the Communications tab. It allows ICC to automatically draft tailored updates for any audience, and gives responders the ability to publish directly to Statuspage or send internal broadcasts without ever leaving the incident.

To set up external and internal communication channels:

  • Statuspage: Connect your Statuspage instance to publish incident updates directly from the Incident Command Center to your public (external) or private (internal) status pages. This is available only for sites on Enterprise plans.

  • Stakeholder notification groups: Configure your default communication channels and distribution lists to ensure the right internal teams, executives, and external partners are notified automatically. Read how to manage your stakeholders

What happens after you set up ICC?

When responders open an incident in your service project, they will, by default, see the Incident Command Center, organized into five primary tabs:

  • Overview: Live incident state, responders, and affected services.

  • Investigation: Aggregated deployment diffs, log anomalies, and suggested hypotheses.

  • Mitigation: Recommended recovery actions and runbooks.

  • Communications: Drafts for internal and external status updates.

  • Post-incident review (PIR): Automatically compiled timeline and exportable post-incident review draft.

Manage access to ICC

Once the Incident Command Center for a service space is set up, your team can view the AI-first incident view based on the following permissions:

  • Viewing incident details and AI outputs: Anyone with access to the incidents can view the overview, investigation findings, mitigation plans, and communication history.

  • Manage investigations: Anyone with the assignee, responder, or Incident Manager permissions can trigger, stop, and run follow-up investigations.

  • Manage mitigation plans: Anyone with the assignee, responder, or Incident Manager permissions can create and update mitigation plans.

  • Sending stakeholder updates: Anyone with access to the incidents can create and send updates to the stakeholders.

Best practices to improve recommendations

The Incident Command Center uses the context available for an incident to generate summaries, investigations, recommendations, and drafts. To maximize suggestion quality

  • Map incidents to the services they accurately affected in your service catalog.

  • Associate linked alerts and error traces directly with the incident.

  • Keep runbooks and troubleshooting guides up to date in the linked Confluence spaces or other tools.

  • Maintain relevant knowledge base articles and historical incident records.

さらにヘルプが必要ですか?

アトラシアン コミュニティをご利用ください。