ChangeTrace
Incidents

What is an incident?

The two kinds of incident ChangeTrace opens, how they differ, and what severity means.

An incident is ChangeTrace saying: something measurably went wrong, here is when, and here is what changed around it.

There are exactly two kinds, and they behave very differently.

Sales incidents

Opened when revenue or orders fall well below your own recent normal. Detected once a day, at 1:00 AM UTC, by comparing the last complete day against your trailing 7-day average.

  • Title looks like "Revenue dropped 62% vs 7-day average"
  • Needs about a week of history before it can fire at all
  • Each metric is watched separately, so a single bad day can open more than one

How the detection works →

Outage incidents

Opened when ChangeTrace cannot load your site from outside your hosting. Checked every five minutes, and opened after two consecutive failures — roughly ten minutes of genuine downtime.

  • Always critical
  • Closes itself as soon as the site responds again, recording how long it was down
  • Records how it failed — a WordPress crash and a DNS failure are very different problems

How outages work →

The differences that matter

Sales incidentOutage incident
DetectedOnce a day, 1:00 AM UTCEvery 5 minutes
DelayUp to ~24 hours~10 minutes
Needs historyYes, ~7 daysNo, works immediately
SeverityWarning or criticalAlways critical
Closes itselfNoYes, on recovery
Gets ranked causesAlwaysOnly for some failure types

Severity

SeverityMeaningEmails you?
CriticalA 70%+ drop, or your site is downYes, by default
WarningA 40–69% dropNo, by default

A warning-severity incident is a real incident — it appears on your dashboard, gets ranked causes, and shows in the list. It just does not email anyone unless you lower the threshold. Email alerts →

Status

StatusMeaning
DraftJust detected; causes not yet ranked
OpenActive
InvestigatingBeing looked at by ChangeTrace support
ResolvedClosed

Incidents start as drafts, and ranked causes arrive within half an hour. Outage incidents resolve themselves. Sales incidents do not auto-close — see Incident lifecycle.

Where incidents show up

  • Overview — the current active incident, or an all-clear card
  • Incidents — the full list, filterable by status and severity
  • Email — for critical incidents, to organization owners
  • Sidebar badge — a count, red when any of them is critical

On this page