What is an incident?
The two kinds of incident ChangeTrace opens, how they differ, and what severity means.
An incident is ChangeTrace saying: something measurably went wrong, here is when, and here is what changed around it.
There are exactly two kinds, and they behave very differently.
Sales incidents
Opened when revenue or orders fall well below your own recent normal. Detected once a day, at 1:00 AM UTC, by comparing the last complete day against your trailing 7-day average.
- Title looks like "Revenue dropped 62% vs 7-day average"
- Needs about a week of history before it can fire at all
- Each metric is watched separately, so a single bad day can open more than one
Outage incidents
Opened when ChangeTrace cannot load your site from outside your hosting. Checked every five minutes, and opened after two consecutive failures — roughly ten minutes of genuine downtime.
- Always critical
- Closes itself as soon as the site responds again, recording how long it was down
- Records how it failed — a WordPress crash and a DNS failure are very different problems
The differences that matter
| Sales incident | Outage incident | |
|---|---|---|
| Detected | Once a day, 1:00 AM UTC | Every 5 minutes |
| Delay | Up to ~24 hours | ~10 minutes |
| Needs history | Yes, ~7 days | No, works immediately |
| Severity | Warning or critical | Always critical |
| Closes itself | No | Yes, on recovery |
| Gets ranked causes | Always | Only for some failure types |
Severity
| Severity | Meaning | Emails you? |
|---|---|---|
| Critical | A 70%+ drop, or your site is down | Yes, by default |
| Warning | A 40–69% drop | No, by default |
A warning-severity incident is a real incident — it appears on your dashboard, gets ranked causes, and shows in the list. It just does not email anyone unless you lower the threshold. Email alerts →
Status
| Status | Meaning |
|---|---|
| Draft | Just detected; causes not yet ranked |
| Open | Active |
| Investigating | Being looked at by ChangeTrace support |
| Resolved | Closed |
Incidents start as drafts, and ranked causes arrive within half an hour. Outage incidents resolve themselves. Sales incidents do not auto-close — see Incident lifecycle.
Where incidents show up
- Overview — the current active incident, or an all-clear card
- Incidents — the full list, filterable by status and severity
- Email — for critical incidents, to organization owners
- Sidebar badge — a count, red when any of them is critical

