> ## Documentation Index
> Fetch the complete documentation index at: https://devlookout.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Promote Alert evidence

> For the complete documentation index, see https://devlookout.com/llms.txt. Explicitly promotes selected Alert evidence into an Incident and records the actor and reason.



## OpenAPI

````yaml /openapi.yaml post /api/v1/incidents/promote
openapi: 3.1.0
info:
  title: Lookout HTTP API
  version: 1.0.0
  description: >-
    Versioned interface for querying Lookout security state, ingesting evidence,
    managing Alerts, and promoting Incidents. The deployed Lookout instance is
    authoritative and raw evidence remains local unless export is explicitly
    enabled.
servers:
  - url: https://lookout.example.com
    description: Replace with the private URL of your Lookout deployment
security:
  - bearerAuth: []
tags:
  - name: System
  - name: Security graph
  - name: Rules
  - name: Events
  - name: Collectors
  - name: Alerts
  - name: Incidents
paths:
  /api/v1/incidents/promote:
    post:
      tags:
        - Incidents
      summary: Promote Alert evidence
      description: >-
        For the complete documentation index, see
        https://devlookout.com/llms.txt. Explicitly promotes selected Alert
        evidence into an Incident and records the actor and reason.
      operationId: promoteIncident
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              additionalProperties: false
              required:
                - alertIds
                - reason
              properties:
                alertIds:
                  type: array
                  minItems: 1
                  uniqueItems: true
                  items:
                    type: string
                reason:
                  type: string
                  minLength: 1
            example:
              alertIds:
                - alert-example-1
                - alert-example-2
              reason: Related evidence confirmed during investigation
      responses:
        '201':
          description: Promoted Incident
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Incident'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
components:
  schemas:
    Incident:
      type: object
      required:
        - id
      properties:
        id:
          type: string
      additionalProperties: true
    ErrorResponse:
      type: object
      required:
        - error
      properties:
        error:
          type: string
        issues:
          type: array
          items:
            type: string
  responses:
    BadRequest:
      description: Invalid request
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Unauthorized:
      description: Missing or invalid credentials
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Forbidden:
      description: The principal lacks the required permission
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: opaque
      description: A 256-bit token generated by the Lookout CLI.

````