# FireHydrant vs Grafana IRM: An Incident Management comparison for 2026

On March 24, 2026, Grafana Labs archived the open-source Grafana OnCall repository. The code is still on GitHub, read-only, but the cloud connection that delivered mobile push, SMS, and phone notifications to self-hosted installs was switched off. Teams that had run a free pager on their own servers for years were left with a decision they had not budgeted for: move to Grafana Cloud IRM, pay for a self-managed Enterprise deployment, or leave Grafana for incident response altogether.

FireHydrant is one of the tools those teams now find on their shortlist. Its free plan covers up to 10 responders, it has its own on-call product, and its Signals Migrator can import schedules and escalation policies, though it is advertised for PagerDuty and Opsgenie rather than Grafana OnCall.

[ad-uptime]

The two products could hardly be more different underneath. **Grafana IRM is the incident layer of an observability platform**, combining the former Grafana OnCall and Grafana Incident inside Grafana Cloud, next to your metrics, logs, and traces. FireHydrant holds none of your telemetry. **FireHydrant is a process tool for running incidents the same way every time**, with condition-triggered runbooks, a service catalog, change tracking, status pages, and retrospectives, and it now belongs to Freshworks.

This comparison covers the choice facing former OnCall users, on-call, declaring and running incidents, AI and MCP, status pages and retrospectives, and the telemetry question, which for once has a clear winner, then prices both for a 25-person team.

## Quick comparison

The table covers what teams usually ask first. Several rows reverse the pattern you may expect from other incident tool comparisons.

| Category | FireHydrant | Grafana IRM |
|---|---|---|
| **What it is** | Standalone incident response platform | On-call and incident layer of Grafana Cloud |
| **Owner** | Freshworks | Grafana Labs |
| **Holds your telemetry** | ✘ | ✔, Mimir, Loki, and Tempo |
| **Automation** | Runbooks triggered by incident conditions | Escalation chains and integrations |
| **Declare from a dashboard** | ✘ | ✔, from any panel |
| **Service catalog** | ✔, Pro | Service context from Grafana |
| **On-call** | Signals, included on Pro and metered by alerts | Included in active-user price |
| **Schedules as code** | API and Terraform | ✔, Terraform and iCal |
| **AI** | Summaries, transcripts, and retros on Enterprise | Sift and Grafana Assistant on native data |
| **MCP server** | ✔, open source | ✔, open-source Grafana MCP server |
| **Status pages** | ✔, unlimited public on Pro | ✘, not part of IRM |
| **Retrospectives** | ✔, timeline-based with templates | ✔, generated from the timeline |
| **Free plan** | Up to 10 responders | Up to 3 active IRM users |
| **Paid pricing** | $25 per responder per month | $20 per active user per month plus $19 platform fee |
| **Self-hosted** | ✘ | Enterprise only, OSS OnCall archived |
| **Compliance highlights** | SOC 2 | SOC 2 Type II, GDPR, FedRAMP, PCI DSS |

## If you were running Grafana OnCall OSS

This section is for the teams the archive affected most. If you never self-hosted OnCall, skip ahead.

Your options now fall into three groups. The first is Grafana Cloud IRM, the managed successor where all development now happens. Its free tier covers up to 3 active IRM users, and the Pro plan bills $20 per active user per month plus a $19 platform fee. You get the same on-call model you know, plus Grafana Incident, Sift, and Grafana Assistant. If your metrics and logs already live in a self-hosted Grafana stack, you are also deciding whether to move them to Grafana Cloud, since IRM's advantage is strongest when the telemetry sits beside it.

The second is self-managed Grafana Enterprise, which keeps IRM on your own infrastructure. That path starts at a $25,000 annual minimum, which puts it out of reach for most teams that chose the open-source pager to save money.

The third is a different vendor. FireHydrant's free plan covers 10 responders, with 2 runbooks, 1 public status page, and 3 integrations, which is enough for a small team to replace a self-hosted pager without a contract. Beyond 10 responders, Pro costs $25 per responder per month. You lose the in-Grafana workflow, but your Grafana dashboards and alerting keep working, and Grafana alerts can feed FireHydrant through a webhook.

| Replacing OnCall OSS | FireHydrant | Grafana Cloud IRM | Grafana Enterprise |
|---|---|---|---|
| **Free tier** | Up to 10 responders | Up to 3 active users | ✘ |
| **Entry paid price** | $25 per responder per month | $20 per active user plus $19 fee | $25,000 per year minimum |
| **Hosting** | FireHydrant SaaS | Grafana Cloud | Your infrastructure |
| **Keeps the Grafana workflow** | ✘, alerts arrive by webhook | ✔ | ✔ |
| **Schedule import** | Signals Migrator, PagerDuty and Opsgenie | Native continuity | Native continuity |

[summary]
### Bring your data with you when you move

<iframe class="aspect-video h-auto" width="100%" height="315" src="https://www.youtube.com/embed/fD3pHdwRz3U" title="Importing Data | Better Stack" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>

Leaving self-hosted OnCall means choosing between Grafana Cloud's several components and a standalone tool like FireHydrant that holds no telemetry at all. Better Stack imports your existing telemetry and runs on-call, incidents, and status pages on the same platform, so replacing the pager is also a chance to retire the servers that ran it.

**If the pager has to move anyway, move the evidence it depends on at the same time.** [See how importing works](https://betterstack.com).
[/summary]

## Platform or process

Before comparing features, consider what each product is built around, because it shapes every section that follows.

Grafana IRM is built around data. Alerts from Grafana Alerting and dozens of other sources route through escalation chains to on-call responders, incidents carry timelines and roles, and every graph and log query sits one click away. The trade-off is commitment: IRM pays off when you standardize on Grafana Cloud.

![Screenshot of Grafana IRM incident and on-call homepage](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/420fc4fd-f837-4b15-342b-7065f9c8f500/public =1200x630)

FireHydrant is built around process. It does not care where alerts come from, and it puts its effort into making each incident follow the steps your team agreed on, using runbooks, a service catalog, and a detailed timeline that turns into a retrospective. Since January 2026 it has belonged to Freshworks, which is integrating it with Freshservice tickets.

![Screenshot of FireHydrant platform overview](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/1cd0af3c-d852-4728-e2d9-929b64a52300/public =1920x1008)

| Design | FireHydrant | Grafana IRM |
|---|---|---|
| **Center of gravity** | The response process | The observability data |
| **Works with any monitoring** | ✔ | ✔, best with Grafana Cloud |
| **Biggest commitment** | Configuring runbooks and catalog | Adopting Grafana Cloud |
| **Parent's wider product** | Freshservice ITSM | Grafana Cloud observability |

## On-call and escalation

Both can replace a standalone pager, and Grafana's on-call has the longer history.

### Grafana IRM: the OnCall model, now in the cloud

Grafana IRM schedules support rotations, planned overrides, automated shift-swap requests, Google Calendar integration, and time zones, and you can define them in Terraform or import them from iCal. Escalation chains run multiple steps, and notifications go out through the iOS and Android apps, Slack, Teams, Telegram, SMS, phone, and email, with do-not-disturb override for critical alerts.

![Screenshot of Grafana IRM on-call schedule and rotations](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/5b418729-077e-4241-a4f6-9675856f7300/public =956x512)

On-call is part of the active-user price, and someone only counts as active in a month when they are on a schedule or escalation chain or take an IRM action.

### FireHydrant Signals: on-call metered by volume

Signals comes with FireHydrant Pro and covers schedules, unlimited escalation policies, and notifications by push, Slack, Teams, and email. SMS and voice are sold separately, Signals is charged by the number of alerts sent, and live call routing and alert grouping are Enterprise features.

![Screenshot of FireHydrant on-call schedule](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/907e5f36-95f0-451c-667d-34afd9ced900/public =1876x706)

For a team used to OnCall, Grafana IRM will feel familiar and costs nothing extra for phone alerts. FireHydrant's on-call is capable, but its pricing needs more careful reading. If you are also weighing PagerDuty, our [PagerDuty vs Grafana IRM comparison](https://betterstack.com/community/comparisons/pagerduty-vs-grafana-irm/) covers that matchup.

| On-call | FireHydrant | Grafana IRM |
|---|---|---|
| **Rotations and overrides** | ✔ | ✔, plus automated shift swaps |
| **Schedules as code** | API and Terraform | ✔, Terraform and iCal |
| **Notification channels** | Push, Slack, Teams, email | Adds SMS, phone, Telegram, and Google Calendar |
| **SMS and voice** | Sold separately | Included |
| **Live call routing** | Enterprise | ✘ |
| **Billing** | Per responder plus alert volume | Per active user per month |

## Declaring and running the incident

The two tools start incidents from different places, and they guide responders in different ways.

### Grafana IRM: start from the graph

In Grafana IRM, you can declare an incident from any dashboard panel, and the incident opens with that visualization attached. The responder investigates in the same product, pulling logs from Loki or traces from Tempo without changing tools, while the incident view records each action on a timeline that becomes the post-incident review. Slack, Teams, Jira, ServiceNow, and GitHub integrations cover the coordination around it.

![Screenshot of Grafana IRM incident timeline and declaration](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/b024ed80-99fe-48d7-ecb4-c0d1268d0000/md1x =2411x1209)

What Grafana IRM offers less of is structure. Workflow automation is lighter, and there is less prompting for the incident lead about what to do next.

### FireHydrant: start the process

FireHydrant's runbooks fill that gap. When an incident matches conditions such as severity, service, or environment, a runbook opens a Slack or Teams channel, starts a video bridge, pages the owning team, assigns roles, creates a ticket, and posts a status update.

![Screenshot of FireHydrant runbook builder and automated workflow](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/05dc0cbd-3638-4d4d-e6a4-1afec7591500/lg2x =2304x1296)

The service catalog tells each incident who owns the affected service and what it depends on, and FireHydrant ingests deploy and infrastructure change events so responders can see what shipped before the failure. Pro caps runbooks at 5.

![Screenshot of FireHydrant service catalog view](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/ef0c7bfe-0461-4452-5c41-897d25cbd900/lg2x =2000x784)

| Running the incident | FireHydrant | Grafana IRM |
|---|---|---|
| **Declare from a dashboard** | ✘ | ✔ |
| **Process automation** | ✔, runbooks | Lighter |
| **Incident channel and bridge** | ✔, automatic | ✔, via Slack integration |
| **Service ownership** | ✔, catalog | Grafana teams and service context |
| **Change tracking** | ✔, deploy and infrastructure events | ✔, via Sift and integrations |
| **Evidence in the same tool** | ✘ | ✔ |

## AI and MCP

Both now have AI. The difference is what that AI can reach.

### Grafana IRM: Sift and Grafana Assistant

Sift runs checks against your metrics, logs, and traces during an incident and surfaces likely causes, such as error spikes, noisy neighbors, and recent changes. Grafana Assistant handles agentic tasks, writes queries, and builds dashboards. Because both run on Grafana's own data, they can look at raw telemetry rather than a summary passed across an integration.

![Screenshot of Grafana Assistant overview](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/76a7f830-3a72-45b7-1b76-6774e5693600/lg2x =2832x2186)

Grafana's open-source MCP server exposes dashboards, queries, alerting, IRM data, and Sift investigations to assistants like Claude.

### FireHydrant: documentation AI on Enterprise

FireHydrant AI writes incident summaries, transcribes calls, helps triage, drafts retrospectives, and suggests follow-ups, all on the Enterprise plan. It works on the incident record rather than on telemetry. FireHydrant's open-source MCP server runs locally with an API key and lets assistants read and act on incidents.

![Screenshot of FireHydrant AI summary in the incident timeline](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/9b3b8c6a-939b-4c07-3856-0bc63008ab00/md1x =1392x1334)

If AI investigation matters to you, Grafana is the stronger choice here, provided your telemetry lives in Grafana Cloud. Our [incident.io vs Grafana IRM comparison](https://betterstack.com/community/comparisons/incident-io-vs-grafana-irm/) shows how Sift compares with an AI SRE that works through integrations instead.

| AI and MCP | FireHydrant | Grafana IRM |
|---|---|---|
| **Root-cause investigation** | ✘ | ✔, Sift |
| **Works on raw telemetry** | ✘ | ✔ |
| **Incident summaries** | Enterprise | ✔, Grafana Assistant |
| **Call transcription** | Enterprise | ✘ |
| **AI retrospective drafts** | Enterprise | ✔, via Grafana Assistant |
| **MCP server** | ✔, open source, local | ✔, open source |

[summary]
### An AI SRE on one store of data

<iframe class="aspect-video h-auto" width="100%" height="315" src="https://www.youtube.com/embed/n6TtDk8ITgc" title="AI SRE Demo | Better Stack" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>

Grafana's Sift reads telemetry spread across Mimir, Loki, and Tempo, and FireHydrant's AI reads only the incident record. Better Stack's AI SRE works on logs, metrics, and traces stored together in one warehouse, so when an incident opens it can follow a failing request from trace to log line and return a likely cause with the evidence attached.

**An AI investigation moves faster when every signal lives in the same place.** [See Better Stack AI SRE](https://betterstack.com/ai-sre).
[/summary]

## Status pages and retrospectives

This section swings back to FireHydrant.

FireHydrant's Free plan includes 1 public status page, and Pro includes unlimited public pages updated by runbooks. Private pages are Enterprise-only. Grafana IRM does not include customer-facing status pages, so Grafana teams usually add a separate product.

![Screenshot of FireHydrant status page builder](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/f5fec99f-d37e-4a08-e95b-701974661600/public =1486x654)

Both produce retrospectives from the incident timeline. Grafana IRM generates a structured post-incident review from its timeline, with Grafana Assistant available to help draft it. FireHydrant includes one retrospective template on Pro, unlimited templates and AI drafts on Enterprise, and follow-up tracking through ticket integrations.

![Screenshot of FireHydrant retrospective draft with AI suggestions](https://imagedelivery.net/xZXo0QFi-1_4Zimer-T0XQ/1a69903c-9807-42d0-4d9a-2f2226127000/md1x =1148x728)

| Status pages and retros | FireHydrant | Grafana IRM |
|---|---|---|
| **Public status pages** | 1 on Free, unlimited on Pro | ✘ |
| **Private status pages** | Enterprise | ✘ |
| **Retrospectives** | ✔, templates | ✔, generated from the timeline |
| **AI retrospective drafts** | Enterprise | ✔, Grafana Assistant |

[summary]
### Status pages without a second vendor

<iframe class="aspect-video h-auto" width="100%" height="315" src="https://www.youtube.com/embed/v7veE29LdyI" title="Status Pages Overview | Better Stack" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>

Grafana IRM has no status pages, so Grafana teams add another product to tell customers about an outage. Better Stack includes status pages with custom domains, private pages, and subscriber notifications, updated from the same incidents and monitors that detected the problem, next to the logs, metrics, and traces.

**The tool that knows something is down should be the one that tells your customers.** [See Better Stack status pages](https://betterstack.com/status-page).
[/summary]

## The telemetry question

In most comparisons in this series, this section ends with neither tool holding your data. Here Grafana IRM wins outright.

Grafana Cloud is a full observability platform with metrics in Mimir, logs in Loki, traces in Tempo, plus profiling, synthetic monitoring, real user monitoring, and Kubernetes observability, and Grafana Labs was named a Leader in Gartner's 2026 Magic Quadrant for Observability Platforms. Choosing IRM puts incidents and telemetry in one product.

FireHydrant holds none of it. Choosing FireHydrant means paying for and integrating a separate monitoring platform, often Grafana itself, and switching to it during most investigations. Our [Better Stack vs FireHydrant comparison](https://betterstack.com/community/comparisons/better-stack-vs-firehydrant/) covers that gap from the other side.

The caveat on Grafana is complexity. Each signal lives in its own backend with its own query language, LogQL, PromQL, and TraceQL, and each has its own pricing dimension. If you are reconsidering Grafana as a whole rather than just its incident layer, our roundup of [Grafana alternatives](https://betterstack.com/community/comparisons/grafana-alternatives/) covers the other options.

| Observability | FireHydrant | Grafana IRM |
|---|---|---|
| **Metrics** | ✘ | ✔, Mimir |
| **Logs** | ✘ | ✔, Loki |
| **Traces** | ✘ | ✔, Tempo |
| **Profiling, RUM, synthetics** | ✘ | ✔ |
| **Query languages** | Not applicable | PromQL, LogQL, TraceQL |
| **Same product as incidents** | ✘ | ✔ |

[summary]
### One query language across every signal

<iframe class="aspect-video h-auto" width="100%" height="315" src="https://www.youtube.com/embed/kf97nwgL88M" title="Building charts with SQL | Better Stack" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>

Grafana keeps the data next to the incident but splits it across backends with three query languages, and FireHydrant keeps none of it. Better Stack stores logs, metrics, and traces in one warehouse you query with SQL, so a responder can move from an error rate to the log lines behind it without switching stores or syntax.

**Holding the telemetry matters most when you can query all of it the same way.** [Explore Better Stack dashboards](https://betterstack.com/dashboards).
[/summary]

## Pricing

The billing units differ, and both reward teams whose responders are a small share of headcount.

### FireHydrant

1. **Free:** up to 10 responders, 2 runbooks, the Slack and Teams chatbot, 1 public status page, and 3 integrations.
2. **Pro:** $25 per responder per month, billed annually, with 5 runbooks, unlimited public status pages, the service catalog, 5 integrations, Signals on-call, and SSO. Signals is charged by alert volume, and SMS and voice cost extra.
3. **Enterprise:** custom, adding FireHydrant AI, unlimited runbooks and integrations, alert grouping, live call routing, private incidents and status pages, analytics, SCIM, audit logs, and viewer licenses.

### Grafana IRM

1. **Free:** up to 3 active IRM users, with access to all IRM features.
2. **Pro:** $20 per active IRM user per month plus a $19 monthly platform fee, with automatic volume discounts.
3. **Enterprise:** custom, with a $25,000 annual minimum and options for self-managed, federal cloud, and bring-your-own-cloud deployment.

Observability data in Grafana Cloud is billed separately by usage.

### What a 25-person team pays

Assume 25 engineers, 10 of whom carry the pager. Monitoring is excluded for both, though a Grafana team is probably paying for Grafana Cloud already.

| Cost component | FireHydrant Pro | Grafana IRM Pro |
|---|---|---|
| **If all 25 are active responders** | 25 at $25, so $625 per month | 25 at $20 plus $19, so $519 per month |
| **If only the 10 on call are active** | 10 at $25, so $250 per month | 10 at $20 plus $19, so $219 per month |
| **SMS and voice** | Extra | Included |
| **Status pages** | Included | Separate product |
| **Runbooks and catalog** | Included | ✘ |
| **AI investigation** | Not offered | Sift included, Assistant may add cost |
| **Free tier** | Up to 10 responders | Up to 3 active users |

At list price, Grafana IRM is slightly cheaper at both team shapes and includes phone alerts, while FireHydrant includes status pages and its runbook-driven process. The bigger difference is outside this table. A Grafana Cloud customer adds IRM to a bill it already pays. A FireHydrant customer pays for monitoring somewhere else.

## Which one fits your team

Choose Grafana IRM if your telemetry lives in Grafana Cloud, or if you were running OnCall OSS and want the most familiar path forward. It suits teams that investigate from dashboards, teams with many occasional responders who benefit from active-user billing, and public-sector or payments teams that need FedRAMP or PCI DSS. Plan to add a status page product and accept a lighter incident process.

Choose FireHydrant if your monitoring spans several vendors, or your problem is that incidents unfold differently every time. Its runbooks, service catalog, change tracking, status pages, and retrospectives give each response a repeatable shape, and its free plan covers small teams leaving a self-hosted pager. Budget for phone alerts, and for Enterprise if you want its AI.

## Final thoughts

These tools answer different questions. **Grafana IRM asks where the evidence is and puts the incident next to it**, while FireHydrant asks what should happen next and makes sure it does.

If you were a self-hosted OnCall user, the archive already made part of this choice for you, because staying with Grafana now means staying in Grafana Cloud. Run the numbers on moving your telemetry there before you renew anything. **If you would not move your data to Grafana Cloud for its own sake, do not move your pager there either.**

[summary]
### One MCP endpoint for incidents and telemetry

<iframe class="aspect-video h-auto" width="100%" height="315" src="https://www.youtube.com/embed/ddfuZrT7RCg" title="MCP Server | Better Stack" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>

FireHydrant's MCP server exposes incidents but no telemetry, and Grafana's MCP server spans several separate backends. Better Stack's MCP server sits over one platform, so Claude or Cursor can query your logs with SQL, check who is on call, acknowledge an incident, and build a dashboard chart in one conversation.

**With incidents and telemetry behind one MCP endpoint, your assistant can investigate and respond without switching tools.** [Try Better Stack](https://betterstack.com).
[/summary]

