Overview
IncidentFox provides 50+ built-in tools across multiple categories. Each tool can be:- Enabled/disabled per team
- Configured with credentials and settings
- Customized with team-specific defaults
Tool Categories
Configuration Structure
Tools are configured under thetools key:
Common Configuration Options
All Tools
Credentials
Always use vault references for secrets:Tool-Specific Configuration
Kubernetes
AWS
Coralogix
Snowflake
Datadog
Grafana
GitHub
Disabling Dangerous Tools
For security, you may want to disable certain tools:Tool Loading Priority
When an agent needs a tool, the system checks:- Is the integration installed? (package availability)
- Are credentials configured? (tool config + vault)
- Is it enabled for this team? (team config)
- Is it allowed for this agent? (agent config)
Monitoring Tool Usage
View tool usage metrics in the Web UI under Team Console > Agent Runs. Each investigation shows:- Which tools were invoked
- Execution time per tool
- Success/failure status
- Tool output (redacted as needed)
Next Steps
Data Sources
Detailed setup for each data source
Custom MCP Tools
Add custom tools via MCP

