Official agent skill

Oncall Irm

by grafana in grafana/skills

Route alerts, run on-call rotations, and drive incidents in Grafana IRM / OnCall — integrations (Alertmanager / Grafana Alerting / generic webhook / PagerDuty), Jinja2 routing + grouping templates…

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Oncall Irm

skills CLI
$ npx skills add grafana/skills --skill oncall-irm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install grafana/skills oncall-irm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/grafana-cloud/oncall-irm .claude/skills/oncall-irm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
oncall-irm
GitHub stars
282
Token cost
~1.4k tokens
SKILL.md length
218 words
Files
3 (incl. references)
Skills in repo
51
Repo updated
First seen
Licence
Apache-2.0

At a glance

Route alerts, run on-call rotations, and drive incidents in Grafana IRM / OnCall — integrations (Alertmanager / Grafana Alerting / generic webhook / PagerDuty), Jinja2 routing + grouping templates…

  • Works in 3 steps: Wire Alertmanager → IRM and verify routing → Build an escalation chain + verify → Create a schedule from iCal + verify…
  • Wiring Alertmanager to OnCall
  • SKILL.md covers Prerequisites, Core concepts, Common Workflows and Best practices, plus 1 more section
  • Calls curl and jq

What it does

Oncall Irm is an agent skill from grafana/skills, published by the product's own GitHub organization. Route alerts, run on-call rotations, and drive incidents in Grafana IRM / OnCall — integrations (Alertmanager / Grafana Alerting / generic webhook / PagerDuty), Jinja2 routing + grouping templates, escalation chains (wait → notify schedule → notify team → webhook → auto-resolve), schedules (web + iCal + Terraform grafanaoncallschedule), Slack chatops with Acknowledge/Resolve/Silence, and the P1-P4 incident lifecycle. Use when wiring Alertmanager to OnCall, deciding which team gets paged, building rotations from a…

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/integrations.md` and `references/templates-schedules.md`).

It sits in DevOps & Cloud, covering Monitoring and alerting and Incident response. It works with Grafana, Prometheus, Slack and Terraform. The licence is Apache-2.0.

When your agent uses it

  • Wiring Alertmanager to OnCall
  • Deciding which team gets paged
  • Building rotations from a Google Calendar / iCal
  • Hooking up Slack notifications

Example prompts

  • “page the platform team on critical alerts”
  • “send Prometheus alerts to Slack”
  • “set up our on-call rota”
  • “/oncall-irm”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Wire Alertmanager → IRM and verify routing
  2. Build an escalation chain + verify
  3. Create a schedule from iCal + verify "who is on-call right now"

What it can do on your machine

Read from SKILL.md and the folder at commit 1ccacf2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • grafana.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Oncall Irm loads about 1.4k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 239 tokens; SKILL.md has 218 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~239
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from grafana/skills at commit 1ccacf2, republished under its Apache-2.0 licence (© grafana). 218 words, ~1,380 tokens.

Download SKILL.mdSave it as .claude/skills/oncall-irm/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
oncall-irm
description
Route alerts, run on-call rotations, and drive incidents in Grafana IRM / OnCall — integrations (Alertmanager / Grafana Alerting / generic webhook / PagerDuty), Jinja2 routing + grouping templates, escalation chains (wait → notify schedule → notify team → webhook → auto-resolve), schedules (web + iCal + Terraform `grafana_oncall_schedule`), Slack chatops with Acknowledge/Resolve/Silence, and the P1-P4 incident lifecycle. Use when wiring Alertmanager to OnCall, deciding which team gets paged, building rotations from a Google Calendar / iCal, hooking up Slack notifications, or declaring an incident from an alert — even when the user says "page the platform team on critical alerts", "send Prometheus alerts to Slack", "set up our on-call rota", "escalation policy", or "auto-resolve when the alert clears" without naming OnCall / IRM. Heads up — OnCall OSS is in maintenance mode (archived March 2026); Grafana Cloud users should use IRM.
license
Apache-2.0

Grafana OnCall & IRM

OnCall docs: https://grafana.com/docs/oncall/latest/ IRM docs: https://grafana.com/docs/grafana-cloud/alerting-and-irm/

Grafana OnCall OSS is in maintenance mode (archived March 2026). Cloud users → IRM. Concepts (chains, schedules, integrations) are identical.

Prerequisites

  • Grafana Cloud stack with IRM/OnCall enabled
  • API token (Authorization: <token>)
  • Slack workspace + admin to install the OnCall app (for ChatOps)

Core concepts

ConceptDescription
IntegrationWebhook URL accepting alerts; one per source
RouteJinja2 condition that maps to an escalation chain (first True wins)
Escalation ChainWait / notify schedule / notify team / webhook / auto-resolve steps
ScheduleCalendar-based rotation (web / iCal / Terraform)
Alert GroupRelated alerts collapsed by a Grouping ID template
Notification PolicyPer-user channels — Slack, mobile push, SMS, phone, email

Flow: alert → integration → routing template → escalation chain → notifications → ack / resolve.

Common Workflows

1. Wire Alertmanager → IRM and verify routing
yaml
# 1. In IRM: New integration → Alertmanager. Copy the webhook URL.
# 2. alertmanager.yml (see references/integrations.md for full block):
receivers:
  - name: grafana-oncall
    webhook_configs:
      - url: https://<stack>.grafana.net/integrations/v1/alertmanager/<id>/
        send_resolved: true
        max_alerts: 100
bash
# 3. Test the routing template BEFORE going live (UI: Integration → Route → "Preview")
#    Paste a sample payload (use a real Alertmanager test webhook). Expect:
#      Routing result: True
#      Escalation chain selected: <expected chain>
#    If False — your Jinja expression is wrong; fix and re-preview.

# 4. End-to-end test — fire amtool (or any test webhook) at the URL
amtool alert add foo severity=critical team=platform --alertmanager.url http://localhost:9093

# 5. Verify in IRM → Alert Groups (should appear within ~5s) — confirm:
#    - Correct route fired
#    - Correct schedule/user notified
#    - Slack message appeared in the configured channel

Routing template syntax + Jinja helpers: references/templates-schedules.md. Other integrations (Grafana Alerting, generic webhook, Slack): references/integrations.md.

2. Build an escalation chain + verify
1. Notify "Primary On-Call" (Important Notifications)
2. Wait 5 min
3. Notify "Primary On-Call" (Default Notifications)
4. Wait 10 min
5. Notify team "Platform"
6. Trigger outgoing webhook (PagerDuty / ticket)
bash
# Verify: create a test alert (UI → Integration → "Send demo alert"),
# then watch the alert-group timeline tick through steps 1 → 6.
# Use IRM → Escalation Chains → "Test" if available, otherwise the demo alert is the canonical check.
3. Create a schedule from iCal + verify "who is on-call right now"
bash
# 1. Create the schedule
curl -X POST https://<stack>.grafana.net/api/v1/schedules/ \
  -H "Authorization: <token>" -H "Content-Type: application/json" \
  -d '{"name":"Platform On-Call",
       "ical_url_primary":"https://calendar.example.com/platform.ics",
       "slack":{"channel_id":"C123456ABC","user_group_id":"S123456ABC"}}'

# 2. Verify the schedule was created
curl -s https://<stack>.grafana.net/api/v1/schedules/ \
  -H "Authorization: <token>" | jq '.results[] | select(.name=="Platform On-Call")'

# 3. Verify who is on-call right now
curl -s https://<stack>.grafana.net/api/v1/schedules/<schedule_id>/next_shifts/ \
  -H "Authorization: <token>" | jq '.results[0]'
# Expect a shift starting now (or recently) with the right user_id.

Terraform variant + shift block: references/templates-schedules.md.

Best practices

  • Keep chains ≤4 levels with a definitive final step (webhook to PagerDuty or auto-resolve)
  • Always set send_resolved: true in Alertmanager so OnCall auto-resolves
  • Use max_alerts: 100 in Alertmanager webhook config
  • Combine Slack + mobile push for delivery reliability
  • Assign integrations/schedules to teams for RBAC

Resources

© grafana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/grafana-cloud/oncall-irm of grafana/skills.

  • SKILL.md
  • references/integrations.md
  • references/templates-schedules.md

Open the folder on GitHubat commit 1ccacf2

Compare with similar skills

Oncall Irm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Oncall Irm compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Oncall Irm this skillgrafana/skills282—~1.4kAutomated safety check: PassApache-2.0
Alerting OncallBagelHole/DevOps-Security-Agent-Skills1.2k—~3kAutomated safety check: PassMIT
Expert OpsReJeCtAll/ExpertTeam-Codex113—~625Automated safety check: PassMIT
Grafana Observabilityautomateyournetwork/netclaw676—~2.7kAutomated safety check: NotesApache-2.0
Sentry Alert TunerLeoYeAI/openclaw-master-skills2.2k—~7.3kAutomated safety check: PassMIT
Grafanamagnus919/agent-skills115—~2.4kAutomated safety check: PassMIT

Similar skills

  • Alerting Oncall

    BagelHole/DevOps-Security-Agent-Skills

    Set up alerting rules, configure on-call rotations, and manage incident response workflows.

    1.2k GitHub stars~3k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Expert Ops

    ReJeCtAll/ExpertTeam-Codex

    基础设施运维专家入口。用于 Codex CLI 的 $expert-ops 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.

    113 GitHub stars~625 tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Grafana Observability

    automateyournetwork/netclaw

    Grafana observability platform — dashboards, Prometheus PromQL, Loki LogQL, alerting, incidents, OnCall schedules, annotations, datasource queries, panel rendering (75+ tools).

    676 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Sentry Alert Tuner

    LeoYeAI/openclaw-master-skills

    Reduce Sentry alert fatigue by surgically tuning issue grouping, fingerprint rules, severity mapping, sample rates, before-send filters, sourcemap pipelines, and release-health gates.

    2.2k GitHub stars~7.3k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Grafana

    magnus919/agent-skills

    Operate, configure, provision, secure, and troubleshoot Grafana OSS, Enterprise, and Cloud, including dashboards, folders, data sources, annotations, alert rules, contact points, notification…

    115 GitHub stars~2.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Kibana Connectors

    aspectrr/deer

    Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform.

    405 GitHub stars~2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed

More from grafana/skills

All 51 skills in this repo
  • K6 Docs

    grafana/skills

    Official

    Write or review k6 documentation across the three k6 repositories - k6-DefinitelyTyped (TypeScript types), k6-docs (user documentation), and k6 (release notes / changelog).

    282 GitHub stars~678 tokensUpdated 2 days ago
    Auto-check passed
  • Alerting Irm

    grafana/skills

    Official

    Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…

    282 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Dashboarding

    grafana/skills

    Official

    Build, modify, and ship Grafana dashboards as JSON via the HTTP API — panel types (timeseries / stat / gauge / table / heatmap / logs / traces / node-graph), gridPos 24-column layout, units…

    282 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • K6 Perf Test Website

    grafana/skills

    Official

    A skill your agent uses when the user wants to performance-test, load-test, or stress-test a public website end-to-end with k6.

    282 GitHub stars~3.3k tokensUpdated 2 days ago
    Auto-check passed
  • Promql

    grafana/skills

    Official

    Write, validate, and optimize PromQL for Prometheus / Grafana Mimir / Grafana Cloud Metrics.

    282 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Adaptive Metrics

    grafana/skills

    Official

    Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config…

    282 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Oncall Irm

What does Oncall Irm do?

Route alerts, run on-call rotations, and drive incidents in Grafana IRM / OnCall — integrations (Alertmanager / Grafana Alerting / generic webhook / PagerDuty), Jinja2 routing + grouping templates…. Oncall Irm is an agent skill from grafana/skills, published by the product's own GitHub organization. Route alerts, run on-call rotations, and drive incidents in Grafana IRM / OnCall — integrations (Alertmanager / Grafana Alerting / generic webhook / PagerDuty), Jinja2 routing + grouping templates, escalation chains (wait → notify schedule → notify team → webhook → auto-resolve), schedules (web + iCal + Terraform grafanaoncallschedule), Slack chatops with Acknowledge/Resolve/Silence, and the P1-P4 incident lifecycle.

When should I use Oncall Irm?

Oncall Irm fits situations like: wiring Alertmanager to OnCall; deciding which team gets paged; building rotations from a Google Calendar / iCal; hooking up Slack notifications.

How do I install Oncall Irm in Claude Code?

Run `npx skills add grafana/skills --skill oncall-irm -a claude-code`. Or copy the skill folder (skills/grafana-cloud/oncall-irm in grafana/skills) into .claude/skills/oncall-irm in your project. Claude Code loads it when a task matches its description.

How do I install Oncall Irm in Codex?

Run `npx skills add grafana/skills --skill oncall-irm -a codex`. Or copy the skill folder (skills/grafana-cloud/oncall-irm in grafana/skills) into .agents/skills/oncall-irm in your project. Codex loads it when a task matches its description.

Can I use Oncall Irm in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grafana/skills --skill oncall-irm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oncall-irm, .gemini/skills/oncall-irm, .github/skills/oncall-irm and .opencode/skills/oncall-irm in your project.

What does Oncall Irm need to run?

Going by SKILL.md and its folder, Oncall Irm needs the command-line tools its instructions call (curl and jq).

Does Oncall Irm access the network?

SKILL.md names 1 domain. As links in the text: grafana.com. This is read from the text; nothing was executed.

Is Oncall Irm safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Oncall Irm use?

Oncall Irm is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Oncall Irm use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Oncall Irm?

Skills that share tags, products or a category with Oncall Irm: Alerting Oncall (BagelHole/DevOps-Security-Agent-Skills, 1.2k stars), Expert Ops (ReJeCtAll/ExpertTeam-Codex, 113 stars), Grafana Observability (automateyournetwork/netclaw, 676 stars) and Sentry Alert Tuner (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Oncall Irm?

grafana (a GitHub organization, an official publisher) maintains it in grafana/skills, which has 282 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 8, 2026.

Source: grafana/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.