Integration · Incident response
PagerDuty + OrchestrAI
Catalog exported 2026-09-02 · PagerDuty website
Handle PagerDuty from chat: check who is on call, open incidents, acknowledge, escalate, and resolve them.
OrchestrAI exposes 6 PagerDuty operations: 4 are low-risk (read-only or low-impact), and 2 create or modify resources and run only after you confirm the plan.
What teams use it for
During an outage the responder asks who is on call for the payments-api escalation policy, acknowledges the page so it stops re-notifying, and escalates if the first person does not pick up. When a problem is spotted before monitoring catches it, the same person opens an incident against the right service from the chat thread and resolves it once the fix is verified. Creating a PagerDuty service for a newly deployed component is also covered. There is no way to list or search existing incidents, read their timeline, or add notes, so a responder still needs the incident ID or the PagerDuty app for context.
Every PagerDuty operation, with its risk level
| Operation | What it does | Risk | Step-level approval |
|---|---|---|---|
Acknowledge PagerDuty Incident |
Acknowledge incident | Low risk | No |
Create PagerDuty Service |
Create a PagerDuty service for incident management | Low risk | No |
List PagerDuty On-Call |
List on-call users | Low risk | No |
Resolve PagerDuty Incident |
Resolve incident | Low risk | No |
Create PagerDuty Incident |
Create incident | Creates resources | No |
Escalate PagerDuty Incident |
Escalate incident | Creates resources | No |
Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.
What you connect
A PagerDuty credential (stored as pagerduty).
Connected-service tokens are envelope-encrypted with a per-record key wrapped by a cloud KMS.
Prompts that work
- Who is on call right now for the checkout-service escalation policy?
- Acknowledge incident Q1ABC2DEF and escalate it to level 2, nobody has responded in ten minutes
- Open a PagerDuty incident on the search-api service titled 'Elasticsearch cluster yellow, queries timing out'
Before anything runs
Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.
Frequently asked questions
- Can OrchestrAI resolve a PagerDuty incident from Slack?
- Yes, pagerduty_resolve closes an incident by ID and is rated low risk, as is acknowledging. Creating and escalating incidents are medium risk because they page people.
- Can OrchestrAI show me open PagerDuty incidents?
- Not yet, The available operations act on an incident you name, list on-call users, and create services or incidents. Browsing or searching the incident list is not covered, so pull the ID from the PagerDuty notification.
- How does OrchestrAI authenticate to PagerDuty?
- You add a PagerDuty credential once in the connections screen. It is envelope-encrypted with a per-record key wrapped by a cloud KMS and is only decrypted inside the run that needs it.
Related integrations
Try it on your own account
Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.
Unused credits refunded in your first 14 days.