Incident Types
Streamline and customize incident management with distinct Incident Types
Within an organization, there are often many different types of incidents that require a unique response process. A major incident typically follows a different process than a security incident or compliance incident. Incident Types allow organizations to create custom types that determine the set of Custom Fields available on an incident, tailored to diverse response processes. By categorizing incidents, teams reduce confusion and ensure they engage the right processes and responders for each incident type, leading to quicker resolution and minimized business impact.
AvailabilityContact the Sales Team to expand your account's Incident Types functionality.
| Pricing Plan | Base and Major Incident Types | Security Incident Type | Custom Incident Types |
|---|---|---|---|
| Legacy Plans | ✓ | — | — |
| Free (current) | ✓ | ✓ | — |
| Professional (current) | ✓ | ✓ | — |
| Business (current) | ✓ | ✓ | Three |
| Enterprise (current) | ✓ | ✓ | 100 with up to three levels of nesting |
Required User Permissions
- All users except Limited Stakeholders can view Incident Types.
- Any user with permission to create an incident can select an Incident Type at incident creation.
- Users with Responder permissions on an incident can update its type.
- Admins and the Account Owner can create and edit Incident Types.
- Admins and the Account Owner can set the Default Incident Type.
Incident Type Foundational Concepts
Inheritance
Incident Types use an inheritance model. When you add a new custom field to a type, that field is also added to all of that type's children. This model provides the flexibility to add custom fields to all incidents in an account, or to concentrate them to a specific incident type.
When creating a new incident type, you specify a Parent Type, which defines where in the hierarchy the new type lives. An account can have at most three levels of inheritance.

Example Incident Type inheritance configurations
Select the Display Inherited Fields checkbox while configuring an Incident Type to view which fields are inherited:

Display inherited fields
Out-of-the-Box Incident Types
All pricing plans have access to the Base Incident and Major Incident types out of the box. Customers on current Free, Professional, Business, and Enterprise plans also have access to the Security Incident type.
-
Base Incident — All incidents created by default are a Base Incident. The Base Incident is always at the top of the inheritance hierarchy. Use the Base Incident to add fields that apply globally to all incidents in PagerDuty. To have new incidents automatically use a specific type instead of Base Incident, refer to Set the Default Incident Type.
-
Major Incident — Used for configuring your major incident response process. Use this type for tasks such as triggering a major incident workflow and creating custom fields specific to major incidents.
-
Security Incident — An incident caused by a potential security threat that requires specialized investigation and response.
These incident types are configured to work out of the box. Some accounts may need to enable them before creating incidents of that type. Refer to Disable or Enable Incident Types for more information.
Configure Incident Types
Create an Incident Type
-
Navigate to Incidents Incident Types.
-
In the left pane, click New Incident Type.
-
Enter the following information:
Field Instructions Parent Type Select an Incident Type to inherit from. Display Name Enter a user-friendly name to display for this incident type — for example, "Security Incident", "Legal Incident", or "Billing Incident". API Name Enter a unique name for use with the REST API. This field can only contain lowercase letters, numbers, and underscores. You cannot change this value after initial creation. Description Enter a description for the Incident Type. Enable Type Select Enable or Disable. -
Click Create.
Add Custom Fields
After creating an Incident Type, you can add custom fields to that type. Refer to Configure Custom Fields for more information.
Edit Incident Types
- Navigate to Incidents Incident Types.
- Select your preferred Incident Type.
- Make your desired changes to fields or Settings.
- Click Save.
Set the Default Incident Type
If your team marks confirmed or triaged incidents with a specific Incident Type — often to trigger Incident Workflows such as creating a Jira issue or opening a dedicated Slack channel — you can set that type as the account default. Responders then do not have to change the Incident Type by hand on every declaration for those workflows to run.
When a Default Incident Type is set, the Incident Type field is pre-filled with that type wherever an incident is declared: the web app, mobile app, and Slack. The responder can still change the type before creating the incident. Setting a default does not lock the Incident Type, and it does not change the type of any existing incidents. If no default is set, new incidents are created as a Base Incident, as they are today.
Only Admins and the Account Owner can set the Default Incident Type.
To set the Default Incident Type:
- Navigate to User Icon Account Settings Incident Settings.
- Under Default Incident, select the default Incident Type from the dropdown.
- Click Save.
Disable or Enable Incident Types
Deleting Incident TypesDeleting Incident Types is not supported. Disable an incident type to make it unavailable to responders when selecting a type on an incident.
- Navigate to Incidents Incident Types.
- Select any child of the Base Incident type.
- Click the Settings tab.
- Select Disable in the Enable Incident Type dropdown.
- Click Save.
Set Incident Type on an Incident
By default, new incidents are created as a Base Incident at the top of the inheritance hierarchy. If your account has a Default Incident Type configured, the Incident Type field is instead pre-filled with that type when you declare an incident, and you can change it before the incident is created.
Set or Change an Incident Type
Set or Change an Incident Type in the Web App
1. Navigate to Incidents.
2. Select the incident you want to modify.
3. Above the incident title, select an Incident Type from the dropdown. A confirmation modal appears prompting you to confirm whether fields should be added or removed from the incident.

Select an Incident Type
4. Click Change Incident Type to confirm.
Set or Change an Incident Type in the Mobile App
1. Navigate to Incidents.
2. Select the incident you want to modify.
3. In the carousel menu under the Triage tab, tap Set Type.
4. Select the Incident Type.
5. Tap Change Type to confirm.
Set or Change an Incident Type Using Slack
1. In a dedicated incident channel, enter the /pd type command, or click More Actions on an incident notification and select Change Type.
2. Select the Incident Type.
3. Click Save to confirm.
Set or Change an Incident Type Using Microsoft Teams
1. On a PagerDuty incident's card, click and select Change Type.
2. Select the Incident Type.
3. Click Save.
Set or Change an Incident Type Using ServiceNow
You can change the incident's type from the incident actions menu in ServiceNow after enabling this feature in the integration. Refer to Sync Incident Types with ServiceNow for more information.
Set or Change an Incident Type Using the API
Use the Update Incident API endpoint to update an incident's type.
Set or Change an Incident Type Using Incident Workflows
Use Incident Workflows with the Update Incident Type action to update an incident's type.
View Incident Types on Incidents
View Incident Types in the Web App
Incident Types are viewable on:
- The Incidents page under the Type column.
- The incident details page directly above the incident title.

Incident Type on the Web App Incidents page

Incident Type on the Web App incident details page
View Incident Types in the Mobile App
Incident Types are viewable on:
- The Incidents page directly above the incident status (for example, above "Triggered" or "Acknowledged").
- The incident details page directly above the incident status.

Incident Type on the Mobile Incidents page

Incident Type on the Mobile incident details page
View Incident Types Using Slack
Incident Types are viewable on incident notifications under the Type heading.

Incident Type on Slack incident notification
View Incident Types Using Microsoft Teams
Incident Types are viewable on incident notifications under the Type heading.

Incident Type on Microsoft Teams incident notification
View Incident Types Using ServiceNow
Incident Types are viewable on the ServiceNow incident after enabling this feature in the integration. Refer to Advanced ServiceNow Configuration for enablement and configuration steps.

Incident Type on ServiceNow incident record
FAQ
When is a good time to use Incident Types?
Use Incident Types whenever there is a unique incident process to follow. Your organization's process for major incidents — including required metadata to capture and remediation steps — is likely very different from the process for lower-severity incidents. Incident Types guide responders through these differences and capture variations in response processes.
There are two main categories where different processes are relevant:
- Organizational structure: Within scaled companies, organizational structure frequently defines where one process ends and another begins. Different parts of the organization may follow different processes, making it useful to define an Incident Type aligned with each business unit's process.
- Business impact: A common example is a security incident. Unlike organizational structure scenarios, security incidents may follow a consistent process across the organization, but that process differs from other incident types such as a major incident.
Can I trigger Incident Workflows conditionally based on Incident Type?
Yes. From Incident Workflows, use the Conditional Trigger to trigger a workflow for specific Incident Types. For example, you can trigger a Major Incident Workflow whenever a Major Incident triggers.
Updated 4 days ago
