Get started Dashboard
Datadog Sentry Better Stack Slack Cloudflare

Triage everything that fired overnight

Sorts the overnight alerts from Datadog, Sentry and Better Stack into three lists (real, noise, still open), each with the query behind it.

I want to do this: Triage everything that fired overnight: what was real, what was noise, and what's still open?

## Setup (skip if Polylane is already set up)

Read and follow https://polylane.com/auth.md for non-interactive signup and setup. Start by checking whether I am already signed in; reuse my account and workspace.

If the CLI is missing, bootstrap it without starting the interactive wizard:

curl -fsSL 'https://polylane.com/setup?ref=prompts' | bash -s -- --install-only

Then follow the guide through email verification, workspace selection, source connections, and MCP authentication. Ask me for an email code or OAuth consent only when needed. Verify each step; report pending setup instead of claiming success from installation alone.

## How to work

Over MCP: searchTools lists what this workspace exposes, with each tool's schema; call it first. runTool runs one tool, runCode chains several in one call and returns just the answer. search and execute cover the full Polylane REST API: threads, issues, investigations, autofixes, memories.
From the terminal: the polylane CLI wraps the same API, with structured output and non-interactive flags everywhere.
Reads always work. Write tools appear only if I have opted in, and every write is screened.

## Task: Triage everything that fired overnight

Steps:
1. Pull every issue and alert that fired in the window
2. Group duplicates and storm re-fires into their underlying issues
3. For each issue, read the metric or log series behind it and judge it against normal
4. Split the pile: confirmed incidents, noise with the reasoning, still-open questions
5. Deliver the triage with links to each issue and the queries behind each verdict

Ground every claim in data you actually pulled: the query, the log line, the change record. If the data is inconclusive, say so. Ask me before anything that writes.

Forty alerts, four tabs, first coffee.

The overnight pile mixes one real incident with thirty-nine echoes of it. Sorting them means opening each alert, finding its query, and reading the graph, forty times.

  • Reading the same alert storm one page at a time
  • The real issue buried under its own duplicates
  • "Is this still happening?" checked by hand, per alert

One prompt, this much work. Every step on your real data.

  1. 1 Pull every issue and alert that fired in the window Datadog Sentry
  2. 2 Group duplicates and storm re-fires into their underlying issues
  3. 3 For each issue, read the metric or log series behind it and judge it against normal Datadog Better Stack
  4. 4 Split the pile: confirmed incidents, noise with the reasoning, still-open questions
  5. 5 Deliver the triage with links to each issue and the queries behind each verdict

The pile becomes three short lists

Real, noise, and needs-a-human, each with the query behind it. The first hour of the day goes to the one issue that deserves it.

More prompts for Incident response

Stop doing this by hand. Paste it, and your agent does the rest.