Datadog Alert Triage Agent with OpenCode

Alert triage here is a fixed pipeline: read the event, fetch the monitor, count what is actually alerting, pull the metric around the window, check for open incidents, write five labelled lines. That is a narrow pipeline with a hard word limit at the end of it, and OpenCode is easy to point at something this contained. Which model does the thinking is left to you.

Loading preview…
Free to start · guided setup

Watch it work before it's live

Run a staged conversation — no account needed. The agent handles it for real while a simulated world answers its tool calls; nothing touches real accounts, and nothing is actually sent.

[Triggered] api-gateway 5xx ratio above 2%

Triggered

Error ratio 7.4% over the last 5 minutes against a 2% threshold, evaluated across 34 of 36 gateway pods. Triggered 14:07 UTC. Tags env:prod, region:eu-west-1, version:2026.8.4.

Set up in minutes

Using this template drops you into a guided setup. It asks exactly this, nothing else:

  1. Connect Datadog

    One sign-in. The agent acts through your account, scoped to what this template uses.

  2. Connect Slack

    One sign-in. The agent acts through your account, scoped to what this template uses.

  3. Severity rules

    Which monitors are worth waking someone for - what each severity level means on your services, what counts as fleet wide, your quiet hours, and the monitors you would rather never see in the channel.

  4. Runs on OpenCode

    Preselected for this page — connect your OpenCode account during setup, or switch to NoClick's built-in models with one click.

  5. Watch it handle a test run

    A staged conversation against a simulated world — then it’s live.

Why OpenCode for this agent

Same five lines every time

Fired, scope, evidence, already open, first check. A predictable shape is what makes a note readable at three in the morning by somebody who has just woken up.

Page rate sets the model

A team paged twice a week and one paged twenty times a night have very different economics. Model choice is the dial, and your severity rules do not change when you move it.

Before you fork

We already have alert fatigue. Does this add to it?

It can, if you route everything into it. Your severity rules decide what earns a channel post, and a monitor the rules do not cover gets a short note saying so rather than a verdict. Point one noisy service at it for a day and read what it would have said. If the notes are not changing what you do, the monitor is the problem rather than the triage.

Run it with a different agent

Put Datadog Alert Triage Agent to work on OpenCode

Free to start. Guided setup, a test run against staged conversations, and it's live.