# Incident Types

Streamline and customize incident management with distinct Incident Types

Within an organization, there are often many different types of incidents that require a unique response process. For example, a major incident typically follows a different process than a security incident or compliance incident. The Incident Types feature allows organizations to create custom types that determine the set of [Custom Fields](/incident-management/incidents/custom-fields-on-incidents) available on an incident, tailored to their diverse response processes. By categorizing incidents, teams can reduce confusion and ensure that they engage the right processes and responders for each incident type, leading to quicker resolution and minimized business impact.

> **Availability:** | Pricing Plan               | Base and Major Incident Types | Security Incident Type | Custom Incident Types                  |
> | :------------------------- | :---------------------------- | :--------------------- | :------------------------------------- |
> | **Legacy Plans**           | ✓                             | —                      | —                                      |
> | **Free** (current)         | ✓                             | ✓                      | —                                      |
> | **Professional** (current) | ✓                             | ✓                      | —                                      |
> | **Business** (current)     | ✓                             | ✓                      | Three                                  |
> | **Enterprise** (current)   | ✓                             | ✓                      | 100 with up to three levels of nesting |
> | **PD Reliability Platform Essential** | ✓                   | ✓                      | Three                                  |
> | **PD Reliability Platform Plus/Ultimate** | ✓               | ✓                      | 100 with up to three levels of nesting |
>
> Contact the [Sales Team](https://www.pagerduty.com/contact-us/#contact-sales) to expand your account's Incident Types functionality.

> **Required User Permissions:** - All users, except for Limited Stakeholders, can **view** Incident Types.
> - Any user with permission to create an incident can **select** an Incident Type at incident creation.
> - Users with Responder permissions on an incident can **update** its type.
> - Admins and the Account Owner can **create** and **edit** Incident Types.
> - Admins and the Account Owner can **set** the Default Incident Type.

## Incident Type Foundational Concepts

### Inheritance

Incident Types use an inheritance model. When you add a new custom field to a type, that field is also added to all of the type's children. This model provides the flexibility to add custom fields to all incidents in an account, or to concentrate them to a specific incident type.

While creating a new incident type, you will specify a **Parent Type**, which defines where in the hierarchy the new type will live. You can have at most three levels of inheritance on your account.

![Example Incident Type inheritance configurations](/images/kb/74e715c548fd574844df597535b47955ab15290a66a59ccd8a5ed2f95f440f61-incident-types-inheritance.webp)

Click the **Display Inherited Fields** checkbox while [configuring an Incident Type](#configure-incident-types) to view which fields are inherited:

![Display inherited fields](/images/kb/b9b83676efe18f7dc289b62d9c7cc0ddde2579a4ef2febeb9ebdd6baa52c7f03-incident-types-display-inherited-fields.webp)

### Out-of-the-Box Incident Types

All pricing plans, including legacy plans, have access to the Base Incident and Major Incident default types. In addition, customers on current Free, Professional, Business, and Enterprise pricing plans have access to Security Incidents, a third default type. These are described below:

- **Base Incident** - By default, all incidents created are a “Base Incident”. The Base Incident is also always at the top of the inheritance hierarchy. You can use the Base Incident to add fields that should apply globally to all incidents within PagerDuty. To have new incidents automatically use a specific type instead of Base Incident, refer to [Set the Default Incident Type](#set-the-default-incident-type).
- **Major Incident** - The Major Incident is used for configuring your major incident response process. You can use this default incident type for tasks such as triggering a major incident workflow, creating custom fields specific to major incidents, and more.
- **Security Incident** - An incident caused by a potential security threat that requires specialized investigation and response.

Typically, these default incident types are configured to work out of the box. However, some customers may need to enable them to start creating incidents of that type. Refer to [Enable an Incident Type](#disable-or-enable-incident-types) for more information.

## Configure Incident Types

### Create an Incident Type

To create an Incident Type in the PagerDuty web app:

1. Navigate to **Incidents**  →  **Incident Types**.
2. In the left pane, click **New Incident Type**.
3. Enter the following information:

| Field | Instructions |
| --- | --- |
| **Parent Type** | Select an Incident Type to inherit from. |
| **Display Name** | Enter a user-friendly name to display for this incident type — for example, "Security Incident", "Legal Incident", or "Billing Incident". |
| **API Name** | Enter a unique name for use with the REST API. This field can only contain lowercase letters, numbers, and underscores. You cannot change this value after initial creation. |
| **Description** | Enter a description for the Incident Type. |
| **Enable Type** | Select **Enable** or **Disable**. |

4. Click **Create**.

### Add Custom Fields

After creating an Incident Type, you can add custom fields to that type. Refer to the [Configure Custom Fields](/incident-management/incidents/custom-fields-on-incidents#configure-custom-fields) article for more information.

### Edit Incident Types

1. Navigate to **Incidents**  →  **Incident Types**.
2. Select your preferred Incident Type.
3. Make your desired changes (e.g., [Add Custom Fields](#add-custom-fields) _or_ adjust **Settings**).
4. Click **Save**.

### Set the Default Incident Type

If your team marks confirmed or triaged incidents with a specific Incident Type — often to trigger [Incident Workflows](/ai-automation/automation/incident-workflows) such as creating a Jira issue or opening a dedicated Slack channel — you can set that type as the account default. Responders then do not have to change the Incident Type by hand on every declaration for those workflows to run.

When a Default Incident Type is set, the **Incident Type** field is pre-filled with that type wherever an incident is declared: the web app, mobile app, and Slack. The responder can still change the type before creating the incident. Setting a default does not lock the Incident Type, and it does not change the type of any existing incidents. If no default is set, new incidents are created as a Base Incident, as they are today.

Only Admins and the Account Owner can set the Default Incident Type.

To set the Default Incident Type:

1. Navigate to **User Icon**  →  **Account Settings**  →  **Incident Settings**.
2. Under **Default Incident**, select the default Incident Type from the dropdown.
3. Click **Save**.

### Disable or Enable Incident Types

> **Delete Incident Types:** Deleting Incident Types is not supported. You can disable an incident type to make it unavailable to responders when selecting a type on an incident.

Perform the following steps to disable or enable incident types:

1. Navigate to **Incidents**  →  **Incident Types**. 
2. Select any child of the **Base Incident** type.
3. Click the **Settings** tab. 
4. Select **Disable** in the **Enable Incident Type** dropdown.
5. Click **Save**.

**Note**: To disable an Incident Type, you must also disable any child types.

## Set Incident Type on an Incident

By default, new incidents are created as a Base Incident at the top of the inheritance hierarchy. If your account has a [Default Incident Type](#set-the-default-incident-type) configured, the **Incident Type** field is instead pre-filled with that type when you declare an incident, and you can change it before the incident is created.

### Set or Change an Incident Type

**Set or Change an Incident Type in the Web App**

1. Navigate to **Incidents**. 
2. Select the incident you want to modify.
3. Above the incident title, select an **Incident Type** from the dropdown. A confirmation modal appears, prompting you to confirm whether the field should be added or removed from the incident.

![A screenshot of the PagerDuty web app showing where to select an Incident Type on an existing incident](/images/kb/cce7cde05a197f50305e0547b51065840b751ea000a70a39a4bd44eb09141962-select_incident_type.webp)
*Select an Incident Type*

3. Click **Change Incident Type** to confirm.

**Set or Change an Incident Type in the Mobile App**

1. Navigate to **Incidents**. 
2. Select the incident you want to modify.
3. In the carousel menu under the **Triage** tab, tap **Set Type**.
4. Select the **Incident Type**. 
5. Tap **Change Type** to confirm.

**Set or Change an Incident Type Using Slack**

1. In a dedicated incident channel, enter the `/pd type` command, or click **More Actions** on an incident notification and select **Change Type**.
2. Select the **Incident Type**. 
3. Click **Save** to confirm.

**Set or Change an Incident Type Using Microsoft Teams**

1. On a PagerDuty incident's card, click  and select **Change Type**.
2. Select the **Incident Type**.
3. Click **Save**.

**Set or Change an Incident Type Using ServiceNow**

You can change the incident’s type from the incident actions menu in ServiceNow after enabling this feature in the integration. Refer to the [Sync Incident Types with Service](/integrations/servicenow-integration-guide/advanced-servicenow-configuration/sync-incident-types-with-servicenow#update-an-incidents-type) article for more information.

**Set or Change an Incident Type Using the API**

You can update an incident’s type using the [Update Incident API](/developer/api/reference/rest/incidents/update-incident) endpoint.

**Set or Change an Incident Type Using Incident Workflows**

You can update an incident's type using [Incident Workflows](/ai-automation/automation/incident-workflows) with the [Update Incident Type](/workflow-actions/pagerduty-incident-management/update-incident-type) action.

## View Incident Types on Incidents

You can view Incident Types in multiple ways:

**View Incident Types in the Web App**

Incident Types are viewable on:

- The **Incidents** page under the **Type** column.
- The incident details page directly above the incident title.

![Incident Type on Web App Incidents Page](/images/kb/f756b85d1cfd8b07eb5aa8e69d924fe6a57f4300f6bf2420d0184aa752e194dd-incident-type-incidents-page.webp)
*Incident Type on the Web App Incidents page*

![Incident Type on Web App Incident Details](/images/kb/cc87768859f209dac837c273396d5fe393db449c5c3b6f98d277dcb0e8ea6ec5-incident-type-incident-details.webp)
*Incident Type on the Web App incident details page*

**View Incident Types in the Mobile App**

Incident Types are viewable on:

- The **Incidents** page directly above the incident status (e.g., above “Triggered” or “Acknowledged”).
- The incident details page directly above the incident status.

![Incident Type on Mobile Incidents Page](/images/kb/cbad9911ede2254a9f6f11c2e91a5abd287ecc6b21e1f403b3e5c86914140f6b-incident-type-mobile-incidents-page.webp)
*Incident Type on the Mobile Incidents page*

![Incident Type on Mobile Incident Details](/images/kb/7895965d7c2511cbf06dcfe2698762073b54f5f87d14ebfa01b9f7af4a3fda7b-incident-type-mobile-incident-details-page.webp)
*Incident Type on the Mobile incident details page*

**View Incident Types Using Slack**

Incident Types are viewable on incident notifications under the **Type** heading.

![A screenshot of the Slack UI showing a PagerDuty incident's type](/images/kb/c2e5eaae3cc977df23e4dc1a05802e7c7f90f583f0363e03a365191f4abcc568-slack_incident_type.webp)
*Incident Type on Slack incident notification*

**View Incident Types Using Microsoft Teams**

Incident Types are viewable on an incident notification under the **Type** heading.

![Incident Type in Microsoft Teams](/images/kb/ad1261a02d9d3e7381c7aa360485d30d6c831e57b98b0d80b14b877b25d19655-ms_teams_incident_type.webp)
*Incident Type on Microsoft Teams incident notification*

**View Incident Types Using ServiceNow**

Incident Types are viewable on the ServiceNow incident after enabling this feature in the integration. Refer to [Advanced ServiceNow Configuration](/integrations/servicenow-integration-guide/advanced-servicenow-configuration#incident-types-and-custom-field-mappings) for enablement and configuration steps.

![Incident Type on ServiceNow Incident Record](/images/kb/6c504f54e33c3f6d58e93e61417cda4202e78125821cb31b196a1b19e1a71620-incident-types-view-servicenow.webp)
*Incident Type on ServiceNow incident record*

## FAQ

**When is a good time to use Incident Types?**

A good time to use Incident Types is whenever there is a unique incident process to follow. Your organization's process for major incidents, including required metadata to capture and remediation steps, is likely very different from the one for lower-severity incidents. Incident Types are ideal for guiding responders through these differences and capturing variations in response processes.

There are two main categories for when different processes (i.e., Incident Types) are relevant:

- **Organizational structure**: Within scaled companies, organizational structure frequently defines where one process ends and another begins. Within these businesses, one part of the organization may look to follow a different process than other areas of the company. In these scenarios, it often makes sense to define an Incident Type that aligns with each business unit's processes.
- **Business impact**: Another common use case for an Incident Type is a security incident. Unlike in the organizational structure example above, security incidents may follow a consistent process across all parts of the organization. However, their process may differ from other incidents, such as a major incident.

**Can I trigger Incident Workflows conditionally based on Incident Type?**

Yes. From [Incident Workflows](/ai-automation/automation/incident-workflows#create-an-incident-workflow-from-scratch), you can use the [Conditional Trigger](/ai-automation/automation/incident-workflows#conditional-triggers) to trigger a workflow for specific Incident Types. For example, you could trigger a Major Incident Workflow whenever a Major Incident triggers.

**Does setting a Default Incident Type change existing incidents?**

No. A Default Incident Type applies only to incidents created after you set it. Existing incidents keep their current type.

**Can a responder change the pre-filled Incident Type when declaring an incident?**

Yes. The Default Incident Type pre-fills the **Incident Type** field, but the responder can select a different type before creating the incident.
