Skip to content

Firefight registers two identical slash commands, /firefight and its short alias /ff. These docs use /ff. Most commands act on the incident whose channel you run them in, so unless noted otherwise, run them inside an incident channel.

Most of what these commands do can also be done from the incident’s page in the dashboard, using the same dialogs. See Running an incident from the dashboard.

CommandWhat it does
/ff newDeclare a new incident. Opens the declare dialog, then creates the incident channel.
/ff listList the incidents that are currently live.
/ff homeOpen the Firefight home dialog, an overview with quick actions for common tasks.
CommandWhat it does
/ff leadAssign the incident lead.
/ff rolesAssign every incident role in one dialog, one person each.
/ff statusChange the incident’s status.
/ff severityChange the incident’s severity.
/ff updatePost an incident update. One dialog covers status, severity, a written summary of where things stand, and when the next update is due.
/ff summaryEdit the incident’s summary.
/ff inviteInvite teammates into the incident channel.
/ff escalateUrgently notify people and request an acknowledgement, so you know help is coming.
CommandWhat it does
/ff actionCreate an action item, something to do now as part of the response.
/ff actionsList the incident’s action items and their status.
/ff followupCreate a follow-up, something to do after the incident is over.
/ff followupsList the incident’s follow-ups.
/ff runbookAttach a runbook to this incident, picking from the ones not already on it.
/ff timelineShow the incident’s timeline of key events.
/ff catchupGet an AI-written summary of the incident so far, useful when joining late.

Every action item and follow-up is posted in the channel with its own controls. I can take this assigns it to you, Mark as done closes it out, and the person picker beside them hands it to someone else at any point before it is done. Handing one over posts it again naming the new holder, so they can work it where they were told about it. The same controls sit on every row in /ff actions and /ff followups, so you can work the whole list from one screen.

Completing anything posts a short line saying what was finished and who finished it, linking back to where it came from. Work spread across an incident is easy to miss otherwise, because a finished item only strikes itself through in place and Slack does not announce an edit.

CommandWhat it does
/ff linkLink this incident to another one.
/ff relateMark another incident as related to this one.
/ff duplicateMark this incident as a duplicate of another.
CommandWhat it does
/ff closeClose the incident. /ff resolve does the same thing.
/ff cancelCancel an incident that turned out not to be one.
/ff reopenReopen a resolved or canceled incident with the same channel and history. /ff open does the same thing.
/ff postmortemGenerate an AI-drafted postmortem from the incident’s timeline and discussion, ready to edit in the dashboard.
/ff shoutoutRecognize a teammate who came through during the incident.

Inside an incident channel, reacting to any message turns it into a record. No command needed.

ReactionWhat it does
💥 :boom:Turn the message into an action item.
▶️ :arrow_forward:Turn the message into a follow-up.
❤️‍🔥 :heart_on_fire:Give the message’s author a shoutout.

In an incident channel, mention @Firefight in a message to ask questions about the incident. It answers from the incident’s own timeline and discussion.