Real-time incident detection monitors your incoming support conversations and automatically surfaces emerging incidents before they escalate. Use this article to understand how detection works, configure Slack, email, and webhook alerts, triage detected issues in the incidents feed, and respond to affected customers — all without leaving your Fin workspace.
Note: Real-time incident detection is available on the Pro add-on only.
What real-time incident detection does
Real-time incident detection continuously monitors incoming support conversations to identify emerging incidents as they happen.
There's nothing to configure and no metrics or thresholds to set. The AI recognizes when something unusual is happening across your incoming conversations and tells you what's driving it.
It moves teams from a reactive model, where incidents are discovered after they escalate, to a proactive one, where incidents are identified while they are still forming.
How it works
Real-time incident detection works in four phases — from spotting a problem in your conversations, to alerting your team, to helping you understand and respond to it.
Detection
As conversations come into your Fin inbox, the AI automatically categorizes each one into a topic and continuously monitors volume across each topic. No setup or predefined conditions are required. Detection works in six steps: 1. Categorization — each incoming conversation is automatically assigned to a topic. 2. Volume monitoring — every few minutes, the system checks how many conversations have arrived for each topic over the last 5, 10, 15, and 30 minutes, and compares that against the historical baseline for the same time of day — so it's always comparing like for like. 3. Spike confirmation — when a topic shows a meaningful spike, a statistical check confirms it's genuinely unusual and not just normal variation. 4. Root cause analysis — the conversations driving the spike are analyzed and compared against typical conversations for that topic, to identify what's actually different about them. 5. Incident creation — if the spike represents a real incident, an Incident is created with an AI-generated summary of what customers are experiencing. 6. Tagging — all related conversations, both past and future, are automatically tagged as Affected Conversations.
Alerting
The moment an Incident is detected, your team is notified via Slack, email, or webhook so you can respond immediately, even outside working hours. You can filter alerts by topic to route incidents to the right team. Alerts include a plain-language summary of the incident, the number of affected conversations, the impacted topic, and a direct link to investigate in Fin.
Triaging
The Incidents page (Analyze > Incidents) gives your team a full record of everything detected, ordered by detection date. Click into any Incident to open the detail panel, where you'll find an AI-generated summary of what's happening, the affected conversation count, a chart showing how the spike developed over time, and the full list of affected conversations so you can see exactly what customers are saying.
Response
When you open an Incident, Operator (your AI assistant) opens alongside it — already loaded with the full context of the incident. From there you can ask questions about the incident, send a bulk message to all affected customers, close impacted conversations once the incident is resolved, or create a Fin snippet so Fin can respond accurately to any new customers who contact you about it while the incident is still active.
What you can do from the incidents view
Go to Analyze > Incidents to get started.
When you open an Incident, Operator opens alongside it — already loaded with the full context of the incident. You can:
Ask questions about the incident — ask Operator which customers are affected, what the common thread is across conversations, or how the incident has developed over time.
Respond to customers in bulk — have Operator draft a message and send it to all affected customers at once, without going through conversations one by one.
Close impacted conversations — once the incident is resolved, Operator can close all affected conversations in one action.
Create a Fin snippet — give Fin information about the incident so it can respond accurately to any new customers who contact you while the incident is still active.
Incidents conversation attribute — every conversation affected by an incident is automatically tagged with the incident name as a conversation attribute, making it easy to filter, report on, and track across your workspace.
How to set up alerts
Go to Analyze > Incidents and click the bell icon in the top right of the Incidents page to configure alerts.
You can receive notifications via Slack, email, webhook, or any combination — alerts fire the moment an incident is detected, including outside working hours.
The trigger is set to New incident detected by default. You can also add a topic filter to route alerts for specific topics to the right team, and combine multiple actions — for example, sending a Slack message to your support channel and an email to your engineering lead.
Every alert includes an AI-generated summary of the incident, how many more conversations than usual are affected and over what period, when the incident started (not just when it was detected), the impacted topic, and a direct link to investigate in Fin.
Slack alert
Click the bell icon in the top right of the Incidents page, then click + New.
Select Send Slack alert. Optionally, add a topic filter to route this alert to the right team. Click Add channels. If Slack isn't already connected, you'll be prompted to connect your workspace.
Click + Add channels, select your channels — they'll show as Connected — then click Save. Your alert is now live.
Email alert
Click the bell icon in the top right of the Incidents page, then click + New.
Select Send email alert. Optionally, add a topic filter to route this alert to the right team.
Search for and add the teammates you want to notify. Anyone with a Fin account on your workspace can be added. Click Save. Your alert is now live.
Webhook alert
Webhook alerts send incident details to an external system or workflow the moment an incident is detected. Use them to be notified about incidents being created or updated in any external system.
Open Developer Hub (Settings → Developer Hub), create or open an app, set its API version to Preview, and add your endpoint under Webhooks.
Subscribe to the incident.created and incident.updated topics.
See the incident notification object for full payload details.
To manage existing alerts, click the bell icon and use the ••• menu next to any alert to edit, test, or delete it.
Report on an incident
Click the report icon on any incident to generate a report over all affected conversations. The report includes:
Total impacted conversations — the full count of affected conversations and the channels they came in on.
Response times — median first response time and total handling time for affected conversations.
Fin resolution — how many conversations Fin resolved, and the split between Fin-handled and teammate-handled conversations.
CX Score and customer remarks — satisfaction scores and qualitative feedback from affected customers.
How to triage detected incidents
Go to Analyze > Incidents. The Incidents feed lists all detected incidents, ordered by detection date. Each row shows the incident title, AI-generated summary, impacted topic, affected conversation count, detection time, and a mini volume chart. Active incidents are shown with a red border; closed incidents are greyed out.
Status — filter by Active (ongoing) or Closed (resolved).
Note: Incidents close automatically 8 hours after the last affected conversation is detected. Review and respond to active incidents within this window.
Click any incident to open the detail panel, which includes:
Title and summary — an AI-generated description of what customers are experiencing and what's driving the incident.
Conversation count — the number of conversations tagged to this incident.
Conversation chart — shows how the volume of affected conversations developed over time. Toggle Show topic volume to see the spike against the normal baseline.
Affected conversations — the full list of conversations tagged to this incident, so you can read exactly what customers are saying before taking action.
Topics — the topic or topics affected by the incident. An incident can span more than one topic.
Note: Conversations are tagged as Affected Conversations automatically — both past and future conversations matching the incident pattern. This is expected behavior.
FAQs
How quickly will an incident be detected?
How quickly will an incident be detected?
Typically within 5–30 minutes of the first affected conversations arriving. Detection speed depends on how many customers reach out about the issue in a given time period.
Do I need to set anything up for detection to work?
Do I need to set anything up for detection to work?
No — detection runs automatically with nothing to configure. Alerts are the only optional setup.
How is this different from Monitors?
How is this different from Monitors?
Monitors track conditions you define in advance — specific metrics, thresholds, or criteria you set up and maintain. Real-time incident detection surfaces issues you weren't looking for, with no predefined conditions required.
I am an existing customer and have just signed up for Pro. When can I start seeing incidents?
I am an existing customer and have just signed up for Pro. When can I start seeing incidents?
If you have been a Fin customer for more than 28 days, you can start seeing incidents from 7 days after activating Pro. This gives the system enough time to learn your conversation topics and establish a baseline for normal conversation volume.
I am a new customer and have just signed up for a Fin plan with Pro. When can I start seeing incidents?
I am a new customer and have just signed up for a Fin plan with Pro. When can I start seeing incidents?
If you are completely new to Fin, you can start seeing incidents after 28 days. This gives the system enough time to learn your conversation topics and establish a baseline for normal conversation volume.
I previously had a Pro trial. When can I start seeing incidents?
I previously had a Pro trial. When can I start seeing incidents?
Time spent on your Pro trial counts toward the required learning period. You can start seeing incidents immediately after upgrading if you have used Fin for at least 28 days and your Pro trial began at least 7 days ago.
When does an incident close automatically?
When does an incident close automatically?
An incident closes automatically 8 hours after the last affected conversation is detected.
Need more help? Get support from our Community Forum
Find answers and get help from Intercom Support and Community Experts

