Get started Dashboard
Datadog Sentry Cloudflare Better Stack

Audit the alert rules you inherited

Scores every alert in Datadog, Sentry, Cloudflare and Better Stack by how often it fires against how often it mattered.

I want to do this: Go through our alert rules: which ones fire the most, and which were ever real?

## Setup (skip if Polylane is already set up)

Read and follow https://polylane.com/auth.md for non-interactive signup and setup. Start by checking whether I am already signed in; reuse my account and workspace.

If the CLI is missing, bootstrap it without starting the interactive wizard:

curl -fsSL 'https://polylane.com/setup?ref=prompts' | bash -s -- --install-only

Then follow the guide through email verification, workspace selection, source connections, and MCP authentication. Ask me for an email code or OAuth consent only when needed. Verify each step; report pending setup instead of claiming success from installation alone.

## How to work

Over MCP: searchTools lists what this workspace exposes, with each tool's schema; call it first. runTool runs one tool, runCode chains several in one call and returns just the answer. search and execute cover the full Polylane REST API: threads, issues, investigations, autofixes, memories.
From the terminal: the polylane CLI wraps the same API, with structured output and non-interactive flags everywhere.
Reads always work. Write tools appear only if I have opted in, and every write is screened.

## Task: Audit the alert rules you inherited

Steps:
1. List the alert rules and monitors across connected providers
2. Pull each one's firing history for the window
3. Cross-reference firings against the issues that turned out real
4. Score each rule: signal rate, duplicate rate, last true positive
5. Deliver the audit with delete, tune, and keep recommendations

Ground every claim in data you actually pulled: the query, the log line, the change record. If the data is inconclusive, say so. Ask me before anything that writes.

Every alert was somebody's good idea.

Rules accumulate: the 2023 migration, the incident that never recurred, the threshold set in a panic. Deleting one feels dangerous, so the noise compounds instead.

  • Rules nobody remembers writing, firing weekly
  • Real alerts buried under ceremonial ones
  • "Just mute it" as alert management

One prompt, this much work. Every step on your real data.

  1. 1 List the alert rules and monitors across connected providers Datadog Better Stack
  2. 2 Pull each one's firing history for the window Sentry Cloudflare
  3. 3 Cross-reference firings against the issues that turned out real
  4. 4 Score each rule: signal rate, duplicate rate, last true positive
  5. 5 Deliver the audit with delete, tune, and keep recommendations

Delete with confidence

Every rule scored against what actually happened, so pruning stops being guesswork. The pager gets quieter without getting blinder.

More prompts for Incident response

Stop doing this by hand. Paste it, and your agent does the rest.