---
title: "Run incident response in your FedRAMP High environment"
description: "Run paging, incident coordination, and response automation for sensitive federal workloads with Datadog Incident Response."
author: "Daljeet Sandu"
date: 2026-10-08
tags: ["incident management", "on-call", "workflow automation", "certification", "fedramp", "govcloud"]
blog_type_id: the-monitor
locale: en
---

Earlier this year, [Datadog for Government achieved FedRAMP® High certification](https://www.datadoghq.com/blog/datadog-achieves-fedramp-high-certification.md), extending our GovCloud environment (US1-FED) to the federal government's most sensitive civilian workloads. That certification now covers [Datadog Incident Response](https://docs.datadoghq.com/incident_response.md), bringing paging, incident coordination, automation, and postmortem workflows into US1-FED.

When a government system goes down, responders need to reach the right people, coordinate a fix, and keep stakeholders informed. The response can also generate sensitive operational data that needs to remain in an appropriate environment.

With Datadog Incident Response in US1-FED, teams can run that response in a FedRAMP High–certified environment while keeping their existing monitoring and investigation tools. At the time of this blog post’s publication, it is the only incident response platform with FedRAMP High certification.

In this post, we'll explain how you can:

- [Keep incident data within your FedRAMP High–certified environment](#keep-incident-data-within-your-fedramp-high-certified-environment)
- [Coordinate incident response in Datadog](#coordinate-incident-response-in-datadog)
- [Route alerts from your existing monitoring systems](#route-alerts-from-your-existing-monitoring-systems)
- [Investigate incidents with Datadog telemetry data](#investigate-incidents-with-datadog-telemetry-data)
- [Reduce the infrastructure you operate during an outage](#reduce-the-infrastructure-you-operate-during-an-outage)

## Keep incident data within your FedRAMP High–certified environment

FedRAMP High applies to systems where a loss of confidentiality, integrity, or availability could severely affect government operations or public trust. Incident response tooling belongs in that category: Incident data often includes alert payloads, logs, screenshots, architecture details, and responder notes about what is broken and why.

![Datadog incident timeline showing an incident declaration, an On-Call page, a Slack message, and an incident commander assignment.](https://web-assets.dd-static.net/42588/1791487111-1-fedramp-high-incident-response-timeline.png)

When your incident response platform sits outside your certified environment, teams may need to limit what incident context can follow the incident. That can mean keeping sensitive details elsewhere, leaving gaps in the incident timeline. Datadog Incident Response runs within the certified boundary, so the information needed to coordinate a response can stay with the response itself.

## Coordinate incident response in Datadog

Datadog Incident Response brings paging, incident coordination, automation, and postmortem workflows together while working alongside the tools already in your stack. During an incident, you can use these capabilities to:

- **Automatically page the team that owns the failing service**: [Datadog On-Call](https://docs.datadoghq.com/incident_response/on-call.md) supports layered schedules for complex rotations, escalation policies for unanswered pages, and overrides. It also supports individual quiet hours to accommodate leave and time zones without requiring teams to rebuild the underlying rotation. Responders choose how they are reached (e.g., push, SMS, or voice call) and can acknowledge, escalate, or declare an incident from their phone.
- **Coordinate where your team already works**: When you declare an incident, Datadog opens the channel, pages additional responders, and starts the bridge in one step. Assign roles, record severity and impact, and post updates from the incident workspace or directly from Slack or Microsoft Teams.
- **Keep stakeholders informed during incidents**: Notification rules push severity changes and status updates to the leadership, program, and partner groups that need them, on the schedule you define. This keeps stakeholder updates within the incident workflow, rather than requiring responders to manage a separate communication process.
- **Maintain a detailed incident timeline**: Datadog records incident activity as the response unfolds. Datadog adds status changes, chat activity, bridge transcripts, and signals from connected systems to the incident timeline. This gives teams a more complete record for post-incident reviews and audits without requiring them to reconstruct events from memory and screenshots.
- **Automate repeatable response steps**: [Datadog Workflow Automation](https://docs.datadoghq.com/actions/workflows.md) lets teams automate repeatable response steps. You can use it to gather incident context, run approved remediation procedures, create or update tickets, and notify stakeholders across connected systems. These automated workflows reduce the manual coordination required during an incident, giving responders more time to investigate and remediate the underlying issue.
- **Document incidents and track follow-up work**: Datadog populates postmortems with data from the incident record and lets teams export follow-up work to systems such as Jira. On-Call and incident analytics give you visibility into response metrics and recurring patterns across incidents.

![Datadog On-Call schedule showing weekday and weekend rotations, assigned responders, and an override.](https://web-assets.dd-static.net/42588/1791487161-2-fedramp-high-on-call-rotation-schedule.png)

## Route alerts from your existing monitoring systems

Datadog Incident Response can work with the monitoring, security, and service management systems your teams already use. Depending on the systems in your environment, you can:

- Route alerts from existing monitoring tools into On-Call escalation
- Declare incidents from monitoring or security platforms
- Attach investigation data to the incident
- Sync follow-up work to your work management system

This lets teams incorporate Incident Response into their existing processes without replacing the systems that generate alerts and investigation data. You can also manage service ownership in [Catalog](https://docs.datadoghq.com/internal_developer_portal/catalog.md) or connect existing ownership data, helping keep escalation logic up to date as teams and services change.

## Investigate incidents with Datadog telemetry data

For agencies already using Datadog in US1-FED, responders can investigate incidents alongside the metrics, traces, and logs that provide context for the response. A page can link responders to the relevant Datadog data and dashboards, reducing the need to recreate investigation context in another platform.

[Datadog Synthetic Monitoring](https://docs.datadoghq.com/synthetics.md) can help responders verify whether critical user journeys have recovered, while security signals can provide context about suspicious activity associated with the degradation. In the postmortem, Incident Response automatically includes the telemetry data used during the investigation.

Teams already using [Datadog for Government](https://www.datadoghq.com/solutions/government/) can use the same dashboards, monitors, access controls, and investigation workflows when responding to incidents in US1-FED. This reduces the need to establish a separate response process for FedRAMP High workloads.

## Reduce the infrastructure you operate during an outage

Self-hosted response tooling gives you control, but it also creates another production system to run. It needs patching, backups, monitoring, access management, high availability, and audit evidence. The response system also needs to remain available when other systems are degraded or unavailable.

Datadog Incident Response is fully managed within the FedRAMP High–certified US1-FED environment. [NIST SP 800-61 Rev. 3](https://csrc.nist.gov/pubs/sp/800/61/r3/final) recommends documenting incident response activities, coordinating responder roles and actions, and protecting incident response information. Datadog Incident Response can help teams support these practices by tracking incident activity, assigning responders, coordinating response workflows, and maintaining incident records within US1-FED.

## Run incident response in US1-FED

Datadog Incident Response gives public sector teams a managed way to page responders, coordinate incidents, automate response steps, and maintain incident records within the FedRAMP High–certified US1-FED environment. Teams can connect their existing monitoring and response systems while keeping incident response within the same certified environment.

To learn more, read the [Datadog Incident Response documentation](https://docs.datadoghq.com/incident_response.md), review [Datadog for Government's FedRAMP High certification](https://www.datadoghq.com/blog/datadog-achieves-fedramp-high-certification.md), and visit [Datadog for Government's FedRAMP Marketplace listing](https://www.fedramp.gov/marketplace/products/FR2023864279A/). To get started with Datadog Incident Response for your FedRAMP High environment, [request a Datadog for Government demo with our public sector experts](https://www.datadoghq.com/public-sector-demo) or [start a Datadog Incident Response free trial](https://www.datadoghq.com/dg/incident-response/?utm_source=google&utm_medium=paid-search&utm_campaign=dg-incidentresponse-na&utm_keyword=incident%20management%20service&utm_matchtype=p&igaag=199195148080&igacm=23861362230&igacr=809474790156&igakw=incident%20management%20service&igamt=p&igant=g&utm_campaignid=23861362230&utm_adgroupid=199195148080).


If you’re not yet a Datadog customer, <!-- Sign-up trigger (sign up for a 14-day free trial) omitted -->.