Noots.ai alpha is live. Expect some bugs while we polish, and tell us when you meet one.Report a bug

A warning before the breach, not a red badge after it.

Most SLA tools tell you a target was missed. This one pages somebody while there is still time to make it: a live countdown on the card that only runs during your business hours, a warning at three quarters of the target that reaches the tray, the ticket's own channel and an inbox, and an escalation chain that pages the people you named and whoever is actually carrying the pager right now. Beside it, timers on the task that resolve a rate and become an invoice, and monitoring webhooks from PagerDuty, Datadog, Alertmanager, Zabbix or UptimeRobot that open the ticket, attach its SLA and page whoever is on the rota. Choose IT & Managed Services at setup and all of it is queued for you.

10 apps queued at setup - untick any of them before you finish
A new project in this workspace

Default project tabs

OverviewBoardToolsBacklogFilesMeetingsCalendarMembersCapacityBudgetKeys

Backlog replaces List and Timeline - a service desk plans in days, not quarters - Keys holds each client's credentials, and Tools books the shared consoles and seats devs share.

Projects created on day one

  • Service Desk
  • Client Projects
  • Internal IT
A day on the tools

What changes, in the hours it actually changes.

Three moments from an ordinary week. Every one of them is a thing the product does, not a thing it could be configured to do one day.

1

07:40

an alert fires before anyone is at a desk

PagerDuty, Datadog, Zabbix, Alertmanager, UptimeRobot or any JSON webhook posts to a Noots endpoint. The vendor adapter turns the payload into a task on the right board with the right fields, attaches an SLA, opens an incident channel and pages the person the rota says is carrying it this week. A repeat of the same alert updates the ticket it already made instead of opening a second one. The client's admin console password is in the project's Keys tab, behind a code, so nobody is texting it at seven in the morning.

2

11:15

the queue is triaged, and the clock stops at six

A client emails about a printer, another asks for a new starter by Monday: both go into Intake with a category and a priority, and get triaged to a named engineer. Four severity tiers each carry their own response and resolution target, and every card shows a live countdown to whichever is next. The clock runs only inside your working window, so a Friday-evening Sev 3 does not burn its target over the weekend. Set those hours explicitly, or let Noots take the median of what your team say their own hours are: the median rather than the union, because one night-shift hire should not quietly convert every client's eight-by-five into twenty-four-by-seven. Sort or filter the whole board by SLA state, and group the Timeline by it.

3

15:05

the warning arrives while there is still an hour in it

At three quarters of the target, the warning goes to the assignee's tray, to the ticket's own channel - the incident channel where the alert opened one - and to an inbox, rather than to a badge nobody is looking at. If nothing moves, the escalation chain pages the next step: the people you named, plus whoever the on-call rota says is holding it at that moment. When two rotas are both live and none is named for that tier, it refuses to guess: it pages the named people instead and writes the reason into the post and the trail. A target that passes anyway is recorded against the ticket, and the attainment report reads those closed promises back.

Made for IT & Managed Services

The three that do the heavy lifting.

Choose this industry during setup and its tools are queued for you. Review the list, drop anything you don't want, and the workspace initialises with the rest already working - or install any one of them on its own, later, from the marketplace.

Queued at setup

SLA Timers

Four severity tiers with their own response and resolution targets, counted on a business-hours clock, with a warning before the target passes rather than a badge after it.

  • Live countdown on the card, the detail panel and the board filter
  • Business-hours clocks, per severity tier
  • A pre-breach warning to the tray, the ticket's channel and an inbox
  • Escalation chains that page the named people and the on-call rota
  • Attainment measured over closed promises, not over events
Queued at setup

Time Tracking & Billing

Start a timer inside the task, or add the entry afterwards. Rates resolve per user, per project or per org, and the Billing tab turns unbilled hours into an invoice.

  • Task timers and manual entries
  • Per-user, per-project and per-org rates
  • A Billing tab that produces invoices
  • CSV export of every line item
Queued at setup

Monitoring & RMM Webhooks

Five vendor adapters - PagerDuty, Datadog, Prometheus Alertmanager, Zabbix and UptimeRobot - plus a custom mapping screen for anything else that speaks JSON. None of them needs an API key.

  • A per-endpoint inbound URL, no API key required
  • Vendor field and severity maps, or your own
  • An alert opens a task with its SLA attached
  • A repeat updates the ticket; a recovery closes it and stops the clock
The shape of the work

How IT & Managed Services actually runs.

Each of these is a project in Noots - its own board, tab strip, meetings, calendar and members. They are not pre-built modules and we will not pretend they are: what the industry gives you is the right defaults around them.

01Ticket intake & triage
02Incident response
03SLA management
04Change & patch windows
05Client onboarding
06Asset & licence tracking
07Project delivery
08Renewals & reviews
And everything else

These sit on top of the whole product.

  • The SLA state is everywhere the work is: a countdown chip on the board card, a panel in the task's own detail view, a sort and a filter across the board, and a band on the Timeline that groups the project by how close each promise is
  • Attainment is measured when a clock stops, over closed promises rather than over events, so a single ticket that missed both its targets counts once and not twice
  • When a monitoring alert is serious enough, the home screen stops being a dashboard and becomes the incident: what broke, where it came from, which project it belongs to, the severity, the clock, who is carrying the pager, and one press to acknowledge or escalate. Who may declare one and who may stand it down is set per workspace, and enforced on the server rather than in the button
  • Time Tracking & Billing keeps the hour on the ticket it is billed against - a timer started from the task or an entry added afterwards, a rate that resolves per user, per project or per org, and a Billing tab that turns the week's unbilled hours into an invoice with CSV line items
  • On-call runs the rotation: who is carrying the pager right now, the handover, and the incident tracked from page to write-up beside the work that fixes it
  • Intake is the front door every client request comes through - a category, a priority and a named owner - so nobody's inbox is the ticketing system
  • The Keys tab on every project holds that client's credentials behind a code, with a timed unlock and a reminder before a secret expires; the Tools tab books the shared consoles, lab boxes and licence seats so two engineers are never on one
  • The Ledger is the register of every laptop, monitor, licence and piece of kit per client: who holds it, where it lives, when it was bought
  • Checklists & SOPs run the client onboarding and the monthly maintenance pass the same way every time, ticked step by step with a name on each; Codex holds the runbooks
  • The built-in CRM keeps accounts, opportunities and renewals next to the work, and client calls join automatically and become the tasks that were agreed
  • Offered at setup, one tick each: Recurring Tasks for the patch windows, the Risk Register for the incident write-up after the pager stops, Customer Health for the accounts drifting towards churn - with every licence and contract that has a date on it on the account's Renewals tab - and a Vendor & Client Register
  • Autopilot plans the migration and reassigns when someone is over capacity; the recorder offers a steer for a client call, an incident review, a change window and a handover, and a date somebody said out loud becomes a real start and due date on the card
  • Chat channels are created per project and per team, with calls that survive navigation; GitHub is a marketplace app, so a merged fix can close its ticket on the teams that want it
See the full platform
What we don't claim

The honest edges.

  • An SLA clock pauses when a person presses pause, and the banked time is counted in business minutes. There is no rule that stops the clock on its own because a ticket moved into a column called Waiting on customer.
  • A severity tier is one promise per workspace rather than one per project, deliberately: a contract-level target that quietly differs between two boards is not a target. What varies per ticket is which tier it is on.
  • SLA state reaches the board card, the task detail, the board's sort and filter, the Timeline's grouping and, when a clock is close enough on a severe enough ticket, the Emergency Response takeover on the home screen. What there is not is a quiet at-risk WIDGET you can add to your dashboard to watch the near misses that never become an emergency.
  • Noots does not replace your RMM or your PSA - it receives their alerts and runs the work that follows.
  • Six RMM vendors were deliberately left on the generic mapping rather than guessed at: a wrong field path maps nothing, which is indistinguishable from a broken integration.
  • Invoices are produced and exported by Noots; sending and collecting them stays in your accounting system.
  • A client emails you, and you file it: Intake is a queue people type into, not a mailbox that opens tickets on its own. Contract entitlements - block hours, per-seat agreements, what a retainer includes - are not modelled either; a renewal on the account's Renewals tab holds the date and the cost, and the hours are priced by the rate you set.
Questions

The ones buyers ask first.

Do the SLA clocks stop outside business hours?
Yes. Each severity tier carries its own response and resolution target and its own working window, so time outside it is not counted against the target. You can set that window explicitly, and where you have not, Noots takes the median of the hours your own members have declared rather than the union of them - the union is how one night-shift hire silently turns every client's eight-by-five into twenty-four-by-seven.
What happens BEFORE an SLA breaches?
At three quarters of the target by default, a warning goes out - to the assignee's notification tray, to the ticket's own channel, which is the incident channel when an alert opened one, and to an inbox on the chain's own channel. That is the part most tools skip: a red badge after the fact tells you what you already know. If nothing moves, the escalation chain pages the next step, and a target that passes anyway is recorded against the ticket rather than quietly dropped.
Who does an escalation actually page?
Three sources, added together: the people named on that step, whoever the on-call rota says is holding it at the moment the step fires, and the project's own members as a last resort so a step never pages nobody. When two rotas are live and none is named for that tier, it refuses to guess a rota: it pages the named people and writes the reason into the chat post and the event trail, because paging the wrong engineer at two in the morning is worse than saying you could not tell.
Can we report on SLA attainment?
Yes, in the admin section beside the policies. The unit is a closed promise rather than an event, so a ticket that missed both its response and its resolution target counts once. It reads the events the engine has been writing all along, which nothing used to read back.
How do the hours become an invoice?
An engineer starts a timer from the task, or adds the entry by hand afterwards. The rate resolves per user, per project or per org, and the Billing tab turns the week's unbilled hours into an invoice with every line item exportable as CSV, so nobody reconciles a spreadsheet on the last day of the month. Sending and collecting it stays in your accounting system.
Which monitoring tools can post alerts into Noots?
PagerDuty, Datadog, Prometheus Alertmanager, Zabbix and UptimeRobot each have a built adapter with its own field map, severity map, dedupe key and recovery signal - and none of them needs an API key, because they are inbound webhooks. Anything else that can POST JSON uses the custom mapping screen, where you decide which field of the payload becomes which field of the task.
Does a flapping alert open a ticket every minute?
No. Each alert carries a dedupe key, so a repeat updates the ticket it already opened rather than creating another. When the alert clears, the recovery closes the ticket and stops the SLA clock through the same code path the manual button uses.
Where do a client's passwords and API keys live?
In that client's project, on the Keys tab: a vault behind a code, resolved on the server on every read and write, with a timed unlock rather than a permanent one and a reminder before a secret expires. The reminder only reaches people who can open the vault, because a secret's name and expiry date are themselves a disclosure. Keys is on by default for this industry only - an engineering firm would open an empty vault, which invites the first secret somewhere else.

Open a workspace that already knows IT & Managed Services.

Answer what your organisation does, review what gets installed, and start with the boards, meetings, chat and calendar already in the right shape.

Free to start · No credit card required