
The investigation details page shows the status card, the summary, the root cause and the recommendations for a completed investigation.
Start an investigation
1
Open the alert
Go to Alerts and click the alert. Scroll to the Investigation section. If earlier runs
exist, a View existing investigation(s) link lists them.
2
Pick a provider and model
Choose the AI Provider and, when the provider offers a choice, the Model. If a warning
says no provider is configured, follow its Configure a provider link first. A second warning
appears when no data source is connected, because the agent then has no metrics or logs to read
and its results are shallow.
3
Choose how deep to go
Tick Deep investigation to run parallel metrics, logs, changes and traces scouts. It finds
more and uses more tokens.
4
Start it
Click Start Investigation. You land on the investigation page and watch it run.
/sre-investigate <alert-id> or by reacting to the alert message with the :rotating_light: emoji.
Read the result
While the run is active the page shows the current step (out of a maximum of 30), how many unique queries ran and how many findings are recorded. A Stop button ends the run early. When it finishes, read the page from the top:
Each finding lists the evidence it cites. Open in Explore on an evidence row re-runs that query live in the Explorer, which needs the Business plan (see Explore logs, metrics and traces). The live result can differ from the excerpt stored with the finding, because your provider’s data changes.
The agent reads metrics, logs, traces, alert history, similar alerts, service dependencies and matching runbooks from what you connected. It works through your metrics first, then utilization and recent changes, then correlations and history, and ends by testing hypotheses about the cause.
A status of partial means the AI provider failed part way. The results shown are real but
incomplete. Check your provider settings and use Retry.
Follow up
The buttons at the top of a finished investigation:- Expand starts a follow-up run that begins from what this one found.
- Retry opens Retry Investigation, where you pick a provider and optionally a model, then click Start Investigation. It is available after a run fails, finishes, is partial or is cancelled.
- Report offers a Technical Report, a Management Report or a Customer Report.
- Publish to status page opens a customer-facing incident pre-filled from the investigation, if you manage your status page.
- Fix with Claude hands a frozen fix brief to your own local agent session.
- View Alert and Explore logs, metrics and traces take you back to the alert or into the Explorer for the same service and window.
Create a ticket from an investigation
1
Click Create ticket
The button sits in the header of a finished investigation. If a ticket was already filed for the
alert, the page shows it and a Create another button.
2
Review the draft
The title and description are drafted from the alert and its last completed investigations. An
AI-drafted badge appears when the refinement arrives, and anything you edit is kept. Pick a
Repository if the card is about a specific one.
3
Choose where it goes
The card always opens on your ops board. If a Jira, Zoho Sprints or GitHub integration is
connected, tick Also file it in to mirror it there. To also open a fix pull request, tick
Also open a fix pull request for this ticket.
4
Create it
Click Create ticket. The confirmation names the card and gives a View ticket link.
From Slack
When an investigation completes, the result posts in the alert’s thread with View Full Investigation, Acknowledge Alert, Resolve Alert and Create Ticket buttons.Related
- Triage alerts: where investigations start.
- Request a fix as a pull request: turn a root cause into a pull request.
- Fix with Claude: hand the problem to your own machine.
- Connect your data: the data an investigation can query.

