Rootly MCP server
Drive Rootly incidents, alerts, and on-call schedules from your AI agents.
About
Connect Tracecat to Rootly to manage incidents, alerts, and on-call schedules for SOC analysts and SRE responders. You can open a Rootly incident from a SIEM alert and pull historically similar incidents to ground the agent's first response. From there, page the right rotation, suggest a remediation playbook, and write the post-incident follow-up with confidence.
Setup
- 1
Create an API key
The Rootly MCP server authenticates with a Rootly API token passed as a bearer credential. Rootly issues three token types, global, team-scoped, or personal, so you can match the credential to the agent's blast radius.
- 2
Select the
Rootlytile in the Tracecat MCP catalogOpen the
MCP catalogin your workspace, select theRootlytile, and paste your API key. - 3
Enable
Rootlyin your agentIn your
ai.agentaction orAgents→toolstab, selectRootlyfrom theMCP integrationsdropdown.
Tools
list_incidentsList Rootly incidents with filters for status, severity, time range, and team.
getIncidentFetch a single incident with its timeline, roles, and linked alerts.
createIncidentOpen a new incident with severity, summary, and affected services.
find_related_incidentsSuggest historically similar incidents for a given description or alert.
suggest_solutionsSurface suggested remediation steps based on past incidents and playbooks.
get_oncall_shift_metricsReturn on-call workload metrics for a user or schedule over a time window.
check_oncall_health_riskFlag rotations at risk of burnout based on alert load and shift patterns.
list_alertsList alerts ingested from connected monitoring sources.
list_schedulesList on-call schedules with rotations and current responders.