Declare an incident in one tap from a scenario tile, or open one by hand, then work it through a protocol checklist while every action is logged to an immutable timeline.
Declare Emergency
The fastest way to start is the red Declare Emergency button at the top of the Security Operations menu. It opens a grid of scenario tiles — Fire — Main Office, Lockdown, Bomb threat — and tapping one derives the whole response: the incident's title and severity, the checklist it loads, the alert message, which rooms are alarmed, which SMS recipient lists are texted, and any webhooks that fire.
One hold-to-confirm then declares the incident and sounds the alarm on every emergency room at once, and drops you straight onto the live incident. Holding — rather than clicking — is deliberate: this is the one button in the product that makes hundreds of phones sound at once.
A scenario tile — Declares the incident and sounds the alarm together.
Monitor / assess — Declares an incident with no alarm, for a developing situation you want logged and staffed before you commit to alerting anyone.
Adjust… — Hands off to the full alert wizard, pre-filled from the scenario, when you need fine control over one room: a subset of recipients, a reworded message, different lists.
The tiles are your scenarios, not a fixed list — they're managed in Settings → Scenarios, so Fire — Main Office and Fire — Warehouse can be two separate tiles with different rooms, recipient lists and checklists. Every organisation starts with ten built-in scenarios, so the grid is never empty.
Starting an Incident by Hand
An incident is the container for a single event — real or rehearsed. Opening one gives you a checklist to work, a place to broadcast from, a map of your people, and a timeline that records everything that follows. When no scenario fits, open one directly:
Go to Active Incident and choose New incident.
Give it a title and pick a severity.
Optionally link a protocol to load its checklist.
Tick drill if this is a rehearsal rather than the real thing.
Severity
Low — Minor, contained, no wider response needed.
Medium — Warrants attention and tracking.
High — Serious; pulls in the wider team.
Critical — Life-safety or major disruption; all hands.
Protocols & Checklists
A protocol is a reusable, ordered checklist you write before you need it — your lockdown procedure, your fire muster, your bomb-threat steps. Link one to an incident and its steps become that incident's checklist. Each step is one of three kinds:
Manual — A thing a responder does and then ticks off.
Voice broadcast — Plays a pre-recorded announcement to a room or set of rooms.
Note — A reminder or instruction to read, with nothing to action.
Build and reorder protocols under Protocols. You can still add ad-hoc steps mid-incident when reality doesn't match the plan.
Working the Incident
Checklist — Move each step from pending to in-progress to complete (or skip it), with optional notes.
Broadcast — Send a pre-recorded announcement to all rooms or a chosen subset.
Notes — Keep a running narrative of what's happening.
Timeline — A read-only, time-stamped log of every action taken.
Announcements
Announcements are pre-recorded voice messages — you type the words, whoot. speaks them — kept in a library so they're ready the instant you need them. "This is a fire evacuation. Leave by the nearest exit." is far better written and voiced in advance than improvised under pressure. Steps and broadcasts pull from this library.
Setting Up Beforehand
Settings is where the pre-incident decisions live, and it's worth an hour of a quiet afternoon:
Scenarios — The tiles in Declare Emergency, and everything one tap on each of them does.
General — Whether alert texts carry a response link, which domain that link uses, how long to wait for a tap before falling back to SMS questions, whether people who join a recipient list mid-incident get alerted, and how long movement trails are kept.
Response page — The questions and branding a recipient sees, with a live preview of the real page.
Resolving an Incident
When it's over, resolve the incident (or escalate it if it's outgrowing your response). You'll be asked how well the protocol held up — a quick rating and notes — which feeds straight into the after-action review.
Every action — steps, broadcasts, notes, status changes, alerts, updates and map messages — is written to the incident's timeline, which can't be edited after the fact. That immutable record is what makes the whole thing auditable.