Section 02 · Four comparison axes
Where we're different, plain-spoken.
Each row below names one decision a team has to make. The PagerDuty column is described honestly — when PagerDuty is the right buy, section 04 names it.
axis band · 4 rows · side-by-sidemendhelm vs pagerduty
01 · axis
Who actually closes the 3 AM incident?
row · closureMendhelm
Agent closes the loop. Detects drift, drafts the dry-run envelope, promotes within your policy window, posts a PR with corrected intent, and rolls the incident up into the Monday digest. The on-call only sees what escalated past the agent’s signed-off scope.
PagerDuty
Pages the rotation. A human acks the alert, reads the runbook or the routing rules, types the resolve, and closes the ticket. PagerDuty owns who got paged, when they acked, and where the incident timeline lives — none of which is the fix.
Mendhelm runs the closed loop — detect, dry-run, promote, audit — without waking the on-call. PagerDuty pages the rotation and a human types the ack/resolve pair; the fix is a human's problem.
02 · axis
Per-engineer on-call burden and alert fatigue.
row · on-call taxMendhelm
Closed loop absorbs the flap. The same drift class that wakes the rotation twice in a week collapses into one audit row on Monday, and the rotation eventually shrinks from 24/7 to one week a quarter. Ack-tier drift classes — where the wrong fix is worse than no fix — still page a human, deliberately, with a signed scope-manifest diff in hand.
PagerDuty
PagerDuty is the rotation's source of truth. Schedules, escalation policies, ack timers, schedules layered on schedules — every new pager path adds a row the team owns, and the per-engineer wake-up count climbs with the workload. The team stays alert-fatigued because the burden is theirs by design.
Mendhelm collapses the recurring flap into one signed scope-manifest row on Monday. PagerDuty ownership is the rotation itself — 24/7 humans, ack timers, escalation policies — and the alert-fatigue ceiling rises with the workload.
03 · axis
What happens after the ack?
row · remediationMendhelm
Reaches the intended state. Mendhelm detects the drift, drafts the dry-run envelope, attaches the audit record, and either auto-promotes inside your policy window (60 seconds on Auto, 15 minutes on Window) or pages a human with the signed scope-manifest diff in hand. The flap closes before stand-up.
PagerDuty
Stops at the ack. The pager stack triages the alert, escalates if the ack timer expires, and writes the incident timeline — that’s the contract. The fix is the human’s job: triage, write the patch, run the deploy, manually close. The ack is the dashboard; the work is downstream.
Mendhelm applies the fix in dry-run by default, promotes inside the policy window, and posts the PR. PagerDuty stops at the ack — the fix is the human’s job.
04 · axis
Layered permissions and immutable audit trail.
row · auditMendhelm
Native. Per action we record the prompt, the exact scope (principal, role, ARN / namespace), the intended diff, the actual diff, the dry-run boolean, and the outcome with reason codes. Wildcard scopes — iam:*, secretsmanager:*, cluster-admin — require a second reviewer before the agent will operate under them. Nobody, including Mendhelm, holds a delete scope on the trail.
PagerDuty
Incident-response-shaped. PagerDuty logs who got paged, when they acked, when they escalated, what notes they attached — the incident timeline plus responder list. The change record lives elsewhere (CloudTrail, GCP Audit Logs, Azure Activity, K8s audit log) and reviewer-policy governance is org-side — PagerDuty is not the system of record for what changed in production.
Mendhelm writes an audit row per action — prompt, scope, intended diff, actual diff, dry-run yes/no, reviewer-policy tier — with layered read-only roles and no vendor delete scope. PagerDuty owns the incident timeline and the responder list, not the change record; reviewer-policy governance is org-side / runbook-side.