Datadog Alert Triage Agent with Codex

One run per alert routed into the trigger, and each one is a handful of reads and a short Slack message. Cost therefore tracks how often you are paged, which is a number you already want to be small. Codex keeps those runs quick, and the metric and log queries are the sort of API work it is strong on.

Loading preview…
Free to start · guided setup

Watch it work before it's live

Run a staged conversation — no account needed. The agent handles it for real while a simulated world answers its tool calls; nothing touches real accounts, and nothing is actually sent.

[Triggered] api-gateway 5xx ratio above 2%

Triggered

Error ratio 7.4% over the last 5 minutes against a 2% threshold, evaluated across 34 of 36 gateway pods. Triggered 14:07 UTC. Tags env:prod, region:eu-west-1, version:2026.8.4.

Set up in minutes

Using this template drops you into a guided setup. It asks exactly this, nothing else:

  1. Connect Datadog

    One sign-in. The agent acts through your account, scoped to what this template uses.

  2. Connect Slack

    One sign-in. The agent acts through your account, scoped to what this template uses.

  3. Severity rules

    Which monitors are worth waking someone for - what each severity level means on your services, what counts as fleet wide, your quiet hours, and the monitors you would rather never see in the channel.

  4. Runs on Codex

    Preselected for this page — connect your Codex account during setup, or switch to NoClick's built-in models with one click.

  5. Watch it handle a test run

    A staged conversation against a simulated world — then it’s live.

Why Codex for this agent

Priced per page, not per monitor

Monitors that never fire cost nothing, so a quiet week is a quiet bill. A bad night costs more, and that is the night you most want the evidence gathered anyway.

Query, count, format

The scope count and the metric pull are mechanical. A fast harness gets the note into the channel while the graphs are still moving.

Before you fork

Can I change harness without redoing the Datadog setup?

Yes. Changing it means editing one dropdown on the agent node. Your severity rules, the API and application keys and the Slack channel all stay untouched. The next alert is triaged by the new harness. Changing it mid incident is a bad idea, so make the switch on a quiet afternoon and watch a few alerts pass through it.

Run it with a different agent

Put Datadog Alert Triage Agent to work on Codex

Free to start. Guided setup, a test run against staged conversations, and it's live.