Investigate incidents with Rovo

Incident Command Center is currently available through an early access program (EAP). Features, interfaces, and availability may change as we continue development.

Note: The Incident Command Center is available to customers on the Jira Service Management Premium and Enterprise plans.

When an incident occurs, responders must quickly assess the impact, coordinate investigation and mitigation efforts, and keep stakeholders informed. Incident Command Center (ICC) centralizes critical incident data, context, and response workflows in Jira Service Management.

What is Incident Command Center?

Incident Command Center is an AI-first incident view in Jira Service Management designed to accelerate incident resolution. By using Rovo to synthesize incident activity, affected services, alerts, recent deployments, and historical data, ICC helps responders:

  • Get up to speed instantly with consolidated timeline and chat summaries.

  • Trigger AI-driven investigations to diagnose root causes and assess impact.

  • Generate guided mitigation plans to quickly stabilize affected services.

  • Keep stakeholders informed with contextual communication drafts.

  • Seamlessly transition incident learnings into post-incident reviews (PIR).

Key capabilities

Overview

View the incident summary, current status, affected services, active responders, and key timeline events in one place.

Responders can get up to speed quickly with an AI-generated summary that synthesizes context across comments, alerts, and connected collaboration tools such as Slack.

Example: If you join an incident after it has started, use Overview to see what happened, which services are affected, who is responding, and what actions have already been taken.

Investigation

Trigger an investigation to analyze potential causes, correlate signals, and uncover the root cause so your team can move directly to mitigation.

Example: If an incident starts shortly after a service change or alert spike, use Investigation to review related activity and identify which systems or changes to check first.

Mitigation

Generate and review recommended mitigation steps once an investigation identifies the probable cause, allowing responders to stabilize services quickly while adhering to standard change management procedures.

Example: If customers are experiencing elevated errors, use Mitigation to consider actions such as rolling back a recent change, scaling capacity, or routing traffic away from an affected component.

Communications

Prepare stakeholder or customer updates using the latest incident context.

Teams can keep people informed with clear, consistent updates while reducing the time spent drafting messages from scratch.

Example: After confirming the customer impact, use Communications to draft an update explaining what is affected, what the team is doing, and when the next update will be shared.

Post-incident review

Use incident activity, timeline events, decisions, and actions taken as a starting point for a post-incident review (PIR).

Teams can create a more complete review faster and focus the discussion on learnings, follow-up actions, and prevention.

Example: After the incident is resolved, use Post-incident review to start a PIR draft that captures the incident timeline, mitigation steps, communications, and open follow-up items.

What information does ICC use?

ICC uses the information available in and connected to your incidents. Depending on your configuration, this can include:

  • Incident details, description, activity, and status

  • Affected services and service relationships

  • Linked alerts

  • Similar past incidents

  • Recent changes and deployments associated with affected services

  • Data from connected observability tools

  • Content from connected knowledge bases

The quality and depth of AI-generated results depend on the context available to ICC. Connecting relevant services, alerts, development tools, observability tools, and knowledge sources can help provide more useful suggestions for investigation and mitigation.

Use ICC with your incident process

Incident Command Center is designed to enhance and streamline your existing incident process. It empowers responders by quickly collecting context, identifying next steps, and preparing updates, which frees your team to focus its expertise on escalation paths and communication standards.

During an incident, rely on ICC to quickly understand the current state. You can review the summary, affected services, active responders, and timeline events all in one place. By surfacing potential causes and mitigation actions, ICC gives your subject matter experts a valuable head start in validating solutions against your monitoring tools and service runbooks.

Note: Use ICC outputs to accelerate your response. Treating the generated summaries, suggested actions, and drafted updates as a strong starting point saves valuable time. Your team can then focus its expertise on reviewing and fine-tuning these details to ensure they are accurate, clear, and perfectly aligned with your incident process before taking action.

Who can use Incident Command Center?

Once the Incident Command Center for a service space is set up, your team can view the AI-first incident view based on the following permissions:

  • Viewing incident details and AI outputs: Anyone with access to the incidents can view the overview, investigation findings, mitigation plans, and communication history.

  • Manage investigations: Anyone with the assignee, responder, or Incident Manager permissions can trigger, stop, and run follow-up investigations.

  • Manage mitigation plans: Anyone with the assignee, responder, or Incident Manager permissions can create and update mitigation plans.

  • Sending stakeholder updates: Anyone with access to the incidents can create and send updates to the stakeholders.

Read how to set up Incident Command Center

Still need help?

The Atlassian Community is here for you.