Skip to main content
Most AI controls live in Settings → AI governance. The rest sit with the feature they control.

Every AI control

Who can change these settings

  • The Manage security settings permission covers incident channel message storage, alongside your organization name and your SAML and SCIM configuration. By default, only account owners have this permission.
  • The Manage organization settings permission covers everything else. Admin and Owner hold it by default.
You can grant either to a custom role. See user roles and permissions. To unlock AI data redaction or turn off transcript viewing, email help@incident.io. Every change is recorded in your audit log.

Message storage

AI features use the incident channel conversation as key context, so this must be enabled to use most AI features. This includes the @incident agent in Slack, the web dashboard and mobile app, as well as Investigations. Your data, including messages, is never used to train models.

Private incidents and alerts

Even with private access allowed, a private incident never surfaces in search results or in suggestions for a different incident. The Slack agent is unaffected by this setting: it can be used anywhere in Slack, and never surfaces private incident or alert information.

AI data redaction

AI data redaction strips credit card numbers, US Social Security numbers and phone numbers from incident channel messages, the attachments AI reads and Scribe transcripts before they reach a model. Other content, including alert payloads, custom fields and code, is sent as written.

Subprocessors

Your organization consents to OpenAI, Anthropic, Google Vertex, Recall.ai and ElevenLabs at sign-up, so all of them are allowed. Settings → AI governance lists their status once you’ve opted out of any. You can opt out of any of them: talk to your account manager, or email help@incident.io. AI features route across whichever LLM providers you allow. Opting out of Google Vertex turns off code analysis. Opting out of ElevenLabs moves Scribe to your meeting provider’s captions, and voicemail transcription to Twilio.

FAQs

No. We hold zero data retention agreements with the LLM providers behind our AI features, OpenAI, Anthropic and Google Vertex, so what we send them is not stored by them and is never used to train or fine-tune a model. The audio providers behind Scribe and voicemail don’t retain your data either. See AI data handling.
Not currently. Our AI features use a combination of models across providers, chosen for accuracy, so there is no bring-your-own-model or bring-your-own-key option.
Our Trust Center holds the current subprocessor list, the data processing addendum, and our SOC 2 Type II report.

AI data handling

Which providers we use, and how your data is handled.

Managing sensitive data

Prevent, erase and redact sensitive information.