Firebird (Sep/Oct 2026) Release Overview

firebird-release-image.png

Rising in a flash of light, the Firebird release is here to bring new energy to incident response! Like the legendary bird whose glow helps guide the way, this release helps teams capture critical conversations, strengthen access, turn incident updates into action, and build cleaner, more dependable incident data. Let’s take flight and see what’s new:

  • Capture important incident conversations with the Scribe Agent for Microsoft Teams incident meetings, which can join meetings, transcribe the discussion, preview transcription progress from the Incident Console, and make previous transcription sessions available to view or export later.
  • Strengthen native xMatters login with email multi-factor authentication, adding an authentication step for users who sign in with native credentials and helping protect emergency or break-glass accounts that need to remain available.
  • Turn incident notes into action with the new Incident Notes trigger, allowing flows to start as soon as a note is added so important findings, decisions, status updates, and next steps can be shared with teams, channels, or other systems.
  • Create more consistent incident data with list and multi-select list incident type properties, giving responders predefined choices that can be used in automation, Playbook conditions, incident filtering, CSV exports, reporting, and API updates.

And so much more! Read on to learn more about what we've been working on...

Availability

Before you scroll down to see all the improvements included in this release, here are some important dates:

  • Non-production environment access: Tuesday, September 22
  • Production environment access: Tuesday, October 20 (enabled between 10:00-10:30am Pacific)

Though we aim to include as many features in each release as we can, it's possible that not everything in the release will be available at the same time. If that's the case for a specific feature, we'll include a note about availability in its write-up below. If nothing is noted, it is scheduled to be available at the production release.

Sneak peek

As a special bonus, we're also giving you a sneak peek at a feature we're working on for a future release:

  • Workflow Promotion APIs: Move tested workflow configurations between xMatters environments through your own source control, review, approval, and CI/CD processes.

Incident response & service intelligence

When incidents unfold, teams need reliable ways to capture what happened, structure key details, and move updates to the right places. In Firebird, we’re introducing Microsoft Teams meeting transcription with the xMatters Scribe Agent, new list and multi-select list incident type properties, and a trigger that can start workflows when notes are added to an incident.

Scribe Agent for Microsoft Teams incident meetings

To help preserve important conversations during incident response without requiring someone on the call to take notes manually, the xMatters Scribe Agent can now join Microsoft Teams meetings associated with an incident and transcribe the meeting audio. Users can invite the Scribe Agent when creating a new incident meeting or add it to an existing meeting, then view the agent’s current status and preview the transcription from the Incident Console while the meeting is in progress.

Scribe Agent for Microsoft Teams Incident Meetings (4).png

Teams can also review previous transcription sessions and export them for later reference, making it easier to revisit decisions, prepare incident reports, conduct post-incident reviews, or share context with people who were not able to attend the meeting.

Scribe Agent for Microsoft Teams Incident Meetings (5).png

Incident type properties: list and multi-select list

Administrators can now add list and multi-select list properties to incident types, giving responders predefined choices instead of requiring free-text entry. Responders can select these values when initiating an incident from the flow trigger form, Microsoft Teams, or Slack, and update them later from the Incident Console.

Once selected, these values become part of the xMatters incident data. Teams can use them in flow automation and playbook conditions, display and filter by them in the incident list, include them in CSV exports, and read or update them through the API.

For example, an administrator can create a 'Customer Impact' property with options such as 'No Customer Impact', 'Potential Customer Impact', and 'Confirmed Customer Impact'. When responders select one of these values, it can trigger specific response steps, notify relevant teams, launch stakeholder communication processes, or escalate the incident based on customer impact.

Incident Notes trigger

Flow Designer now includes the Incident Notes trigger which initiates a flow whenever a note is added to an incident. The trigger can use the note and relevant incident context to update collaboration channels, notify teams and stakeholders, or pass information into other systems without requiring responders to take manual action. 

Incident notes often capture key findings, decisions, status updates, and next steps during a response. By turning those notes into actionable signals, teams can move important information through the response faster while responders continue documenting updates in the incident record. For example, when a responder adds a note identifying a suspected root cause, the initiated flow can automatically share that update with the incident’s collaboration channel so the response team can start further investigation into the issue.

Automation & integrations

When tools are easier to connect and maintain, teams can spend less time manually managing the mechanics of their response processes. In Firebird, we’re adding new Microsoft Teams capabilities, expanding ServiceNow Data Sync configuration, introducing a Jira Cloud template workflow, and improving scheduled flows and workflow list visibility.

New Microsoft Teams app and device management

Availability: Production release (pending Microsoft certification)

This release introduces a new app for Microsoft Teams: xMatters Incident Resolution. This app allows users to select their xMatters instance when logging in, add notes to xMatters incidents directly from Microsoft Teams, search for groups and services, view on-call information, invite groups or service owners into Teams channels, and initiate xMatters incidents from Microsoft Teams.

Administrators also gain more control over Microsoft Teams deployments. They can manage which xMatters instances users are allowed to connect to, and Teams can now be configured and managed as a notification device directly from xMatters. Teams device provisioning also no longer depends on users logging into the Teams app to create the device, making it easier to support user administration, imports, and synchronization processes.

New MS Teams app and Device Management.png
New MS Teams app and Device Management (2).png

For organizations that use Microsoft Teams as a primary collaboration platform, these updates make it easier to manage Teams access, support Teams as a notification channel, and let responders interact with incidents from the workspace they already use.

Microsoft Teams group chat steps

Flow Designer now includes Microsoft Teams steps for working with group chats. Users can create a new group chat, add members to an existing group chat, and post messages to a group chat as part of an automated flow.

This gives teams more flexibility to automate collaboration in the format they already use. For example, when a high-priority event occurs, a flow can create a group chat, add the appropriate responders, and post the initial event details. As the workflow progresses, additional updates can be posted to the same chat without requiring custom integration logic.

Microsoft Teams - Group Chat Steps (combined).png

ServiceNow Data Sync - OAuth 2.0 client credentials

ServiceNow Data Sync now supports OAuth 2.0 using the Client Credentials grant type, allowing administrators to authenticate to ServiceNow with a client ID and client secret instead of a user-based authentication method. This gives organizations a better fit for automated, machine-to-machine synchronization because the connection is associated with an application rather than an individual user.

For teams who require automated integrations to use dedicated application credentials, administrators can configure the ServiceNow Data Sync to authenticate as an application and continue synchronizing data without depending on a specific employee account. This simplifies credential management and helps teams align with their preferred integration security practices.

ServiceNow Data Sync - OAuth 2.0 Client Credentials.png

ServiceNow Data Sync - map group admin

The ServiceNow Data Sync can now map a ServiceNow group manager to the corresponding xMatters group as a group admin, keeping group ownership aligned across both systems. Administrators can choose whether to always assign configured default xMatters group admins, use them only when the mapped ServiceNow manager is invalid, or assign both the default admins and the mapped manager.

ServiceNow Data Sync - Map Group Admin.png

This gives organizations more flexibility to automate group administration while maintaining the safeguards they need. For example, a team can use ServiceNow managers as xMatters group admins and rely on default admins as a fallback when a manager is missing or does not map to a valid xMatters user.

ServiceNow Data Sync - user reconciliation

When users are removed from ServiceNow or no longer meet the configured sync criteria, the ServiceNow Data Sync can now apply a defined action to the corresponding xMatters users. Administrators can choose whether those users remain unchanged, are disabled, or get deleted from xMatters. This helps organizations that use ServiceNow as the source for synchronized users to reduce manual cleanup as access changes. For example, if an employee leaves the organization and no longer appears in the sync results, the ServiceNow Data Sync can disable the xMatters account during reconciliation, preventing it from remaining active while preserving the user record for reference.

Jira Cloud integration template workflow

xMatters now includes a Jira  Cloud integration template workflow to help teams quickly get started with common Jira automation use cases. The workflow receives events from Jira, determines what type of event occurred, and uses the latest Jira Flow Designer steps to take the appropriate action.

Jira Integration Template Workflow.png

For example, when a high-priority Jira work item is assigned to a user or group, the workflow can send an xMatters notification with the work item details. A responder can then take ownership from the notification, and the workflow will update Jira with the new assignee and work item status so resolution work can progress without switching between systems.

Flow Designer Scheduled trigger: sub-hour intervals

The Scheduled trigger in Flow Designer now supports intervals under one hour, allowing scheduled flows to run anywhere from every 15 minutes up to once per hour. This gives teams more control over how frequently automated processes run without relying on external scheduling tools or workarounds. For example, an operations team that checks an external system for new critical events can configure a flow to run every 20 or 30 minutes, or as often as every 15 minutes, so new events can be identified and acted on sooner.

Flow Designer Scheduled Trigger Sub-Hour Intervals.png

Workflow creation details and sorting

To make it easier to find recently created workflows or review older automation that may need attention, the workflow list now shows when each workflow was created and who created it. Users can also sort by creation date to show the newest or oldest workflows first, and that sorting works with existing filters and search criteria.

workflows-created-date.png

Sneak peek: workflow promotion APIs

Workflow promotion APIs give teams an API-driven way to move workflows and related configuration between xMatters environments. Teams can develop and test changes in non-production, retrieve configuration as JSON or YAML, store it in their own source-control system, and use existing Git review, approval, and CI/CD processes to apply approved changes to another xMatters environment. The initial experience is API-driven, with no new promotion UI, xMatters-hosted Git repository, or xMatters-managed CI/CD pipeline included

On-call management & user experience

As teams grow and communication channels become more complex, it becomes even more crucial to help resolvers review information clearly and catch potential issues before they happen. In Firebird, we’re making large shifts easier to review, adding safeguards for messages sent to very large audiences, improving dynamic group terminology, strengthening native login with email MFA, and giving users more control over notification and subscription behavior.

Visibility and usability improvements for large shifts

Large shifts are now easier to review directly from the xMatters web UI. When a shift includes many members, the first 20 are shown, along with an indicator displaying the number of remaining members. Users can click 'Show More' to load additional members in batches of 100, or collapse the list back to the first 20 with 'Show Less' once the full list has been loaded.

Visibility and Usability Improvements for Large Shifts.png

Safeguard against sending messages to very large audiences

To help prevent accidental messages to unexpectedly large audiences, xMatters now warns senders when selected users and groups add up to 10,000 or more recipients. The warning appears while the message is being composed, before Send is selected, giving the sender a chance to review the intended audience.

Safeguard Against Sending Messages to Very Large Audiences (1).png

If the sender continues, xMatters shows a second confirmation before the message is sent. This safeguard does not block legitimate large-scale communications, but it gives users an extra check before notifying thousands of people.

Safeguard Against Sending Messages to Very Large Audiences (2).png

Improved terminology for dynamic group criteria panel

Dynamic group criteria are now easier to understand when adding or editing a group in the xMatters web UI. The criteria panel uses 'AND' and 'OR' instead of 'All' and 'Any', making the relationship between criteria clearer: 'AND' means users must match all criteria, while 'OR' means users must match at least one criterion.

This is a terminology update only and does not change how dynamic group criteria are evaluated. Existing dynamic groups automatically display the new terminology when viewed or edited, with no migration or user action required.

Improved Terminology for Dynamic Group Criteria Panel (rename AllAny to ANDOR).png

Email MFA for native xMatters login

Organizations can now enable multi-factor authentication for users who sign in to xMatters with native credentials. After entering their username and password, users complete an additional authentication step using a verification code delivered by email.

Email MFA for Native xMatters Login.png

This gives customers a way to strengthen security for native xMatters accounts without relying on an external identity provider. It also helps protect emergency or break-glass administrator accounts for organizations that use SSO day to day but keep native accounts available in case their identity provider is unavailable.

"Email device deactivated" notifications

When xMatters automatically deactivates an email device because of a detected delivery failure, the affected user and their supervisors will now be notified. Administrators can also subscribe to these events using subscription forms when they need broader visibility into email-device deactivations across the organization. This brings attention to a failed notification path before it causes someone to miss an important alert. For example, if an on-call engineer’s old corporate email address starts failing and xMatters deactivates the device, the engineer and their supervisor can update the contact information before the next on-call shift. This notification applies only to email devices automatically deactivated after a delivery failure, not devices deactivated manually.

Subscription criteria: exclusions

Subscription criteria now support exclusion operators for List, Combo Box, and Hierarchy properties. Subscribers can define the values they want to exclude (for example, all High Priority alerts except those tied to a specific support group) while continuing to use existing inclusion operators when they want to match specific values.

For teams that only need to exclude a small set of values, exclusions are easier to maintain than a long list of every acceptable option. An operations manager could subscribe to High Priority alerts across the organization, exclude unsupported business applications, and still receive alerts for new applications as they are added.

Reporting & analytics

Clear audit details help teams investigate activity, confirm changes, and support compliance work with less manual effort. In Firebird, we’re adding scenario change history to the System Audit Report, introducing a new Synchronization Audit Report, and making Security, System, and Web Service Audit data available through public APIs.

Scenario audits in the Systems Audit report

Administrators can now trace changes to scenarios directly from the Systems Audit report, making it easier to investigate unexpected notification behavior, verify approved updates, and support compliance reviews. Scenario audit records capture details such as what changed, when it changed, who made the change, and the previous and new values where available. Scenario audits appear alongside existing form and workflow audits, with search, filtering, and export capabilities. Because scenarios can define important incident defaults such as recipients, devices, priority, and other form values, this adds a more complete record of configuration changes across xMatters.

New Synchronization Audit report

The new Synchronization Audit Report gives administrators a clearer way to investigate Data Sync results and pinpoint where problems occurred. Users can select a date range, review job status and processing details, then drill into table-level results and specific field or row-level warnings and errors. When enabled, the report replaces the existing synchronization report in xMatters navigation while retaining the same permissions and data-retention rules. Each level can be filtered and exported to CSV, with exports reflecting the filters applied. Administrators can use details such as row keys, field names, field values, and audit messages to correct source data or share relevant information with support and other stakeholders.

Public APIs for Security, System, and Web Service Audits

You can now retrieve Security, System, and Web Service Audit data programmatically through authenticated, permission-controlled public REST APIs. Instead of manually opening reports, applying filters, and exporting spreadsheets, authorized systems can pull audit records directly into SIEM, GRC, data lake, or reporting platforms.

Security Audit data covers login attempts and authentication context, System Audit data covers changes to users, devices, groups, subscriptions, and workflows, and the Web Service Audit covers legacy REAPI and SOAP request data. Because the results are returned in a machine-readable format, teams can automate recurring collection, correlate xMatters activity with other enterprise data, and support investigations, access reviews, and compliance reporting with less manual effort.

Mobile updates

When users are working with xMatters on the go, the experience should feel as clear and easy as it does at their desk. In Firebird, we’re adding support for IdP-managed passkey authentication on mobile, while giving users a better view of mid-shift rotations, absences, and replacements in their calendars.

Support IdP-managed passkey authentication

Organizations using passkeys with their SAML identity provider can now extend that authentication experience to the iOS and Android xMatters mobile app. When users sign in with SSO, authentication opens through an embedded system browser in the xMatters app. If the customer’s IdP requires or offers a passkey, the IdP presents its passkey experience, such as device biometrics, a device PIN, security keys, or another supported method.

Passkey enrollment, enforcement, recovery, revocation, and fallback methods remain managed by the customer’s IdP. xMatters continues to use the existing SAML SSO configuration and does not create, store, manage, or validate passkeys. Organizations can use the same central identity policies across web and mobile login while maintaining control through providers such as Microsoft Entra ID, Okta, Ping Identity, or Google Cloud Identity/Google Workspace.

Display mid-shift rotations in user calendars

Availability: In an upcoming release of the mobile apps

The xMatters mobile app now shows mid-shift rotations in the My Schedule 'List' and 'Day' views on iOS and Android, giving users a clearer view of when their primary or secondary on-call responsibilities change during a shift. Affected shifts are divided into before-and-after segments, with a dotted line marking the rotation boundary and shift details showing each segment with its own escalation information.

For example, on a weekend shift that runs from Friday evening to Monday morning, a user who is secondary before a midnight rotation and primary afterward can now see that change directly in their mobile calendar. Longer shifts with multiple rotations display each segment in sequence, while the 'Month' view continues to show the escalation in effect at the beginning of the shift.

Display absences and replacements in list view calendars

Availability: In an upcoming release of the mobile apps

Mobile users can now turn on 'Show Absences' in My Schedule 'List' view to see the scheduled shifts affected by their absences. Instead of removing absent portions from the schedule, the list marks those periods as 'Absent' and shows the relevant group, shift, date, time, and replacement details when available.

The view helps users distinguish between time they are working, time they were originally scheduled but are absent, and time they were not scheduled. A responder taking a weekend absence can see those hours in the list, confirm who is covering the shift, and share any handoff details before stepping away.

Early Access Program & feature delivery update

The goal of our current delivery model is to balance feature delivery with customer change management processes. This means providing visibility into upcoming changes for customers that want it, while allowing other customers to have a more standard non-production environment that matches production.

If you aren't familiar with the current model, we release features only visible to admins/developers at a faster pace than the quarterly release process. These features should not impact end users until a customer provisions them into their workflow. Customers can opt their non-production environments into the Early Access Program to see features and functionality enhancements that impact end users before they're released on a quarterly basis. All customer non-production environments are updated four weeks prior to an official quarterly production release to allow for testing and training on new features.

We regularly reevaluate and improve our deployment processes to ensure they reflect industry best practices and customer feedback. For more information about our deployment process, see our xMatters Deployment and Early Access article. We'll update that document whenever we make a change, and let you know about the change through other appropriate channels.

Learn more

These are the main features for this release but, as always, there are several other small changes and enhancements we're delivering to keep xMatters forging ahead. As always, detailed information and instructions for using these new features will be available in our online documentation.

We hope you enjoy everything we've packed into the Firebird release, and we're looking forward to seeing you again soon for Griffin...

 

 

 

 


The information in this article is the intellectual property of xMatters, an Everbridge Company, and is intended only for use with xMatters products by xMatters customers and their employees. Further, this intellectual property is proprietary and must not be reused or resold.

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Article is closed for comments.