A failing check becomes an incident the moment it trips your rule — debounced against flapping, grouped with related failures, assigned, acknowledged and resolved with a full audit trail, and mirrored to PagerDuty, Opsgenie, incident.io or Rootly if that's where your process lives.
Incident rules decide what deserves one: downtime after N failures from M regions, an anomaly of a given severity, a change of a given severity. Related failures collapse into one incident instead of ten; maintenance windows mute the monitors you're working on so planned work never pages the on-call; reminders repeat while it stays open.
Every incident carries its own timeline — the checks that opened it, the intelligence events detected around it, who acknowledged it and when, what resolved it — so the post-mortem writes itself.