Documentation menu

Investigations

Open Ask → Investigations in the application and environment you want to review.

  1. Review the schedule and error thresholds. Scheduled checks start paused.
  2. Run a reviewed scan, or enable an hourly, six-hour or daily schedule.
  3. Open a finding to compare evidence, inspect its source and accept or dismiss the proposed work.
  4. Prepare a follow-up question opens an editable draft in Ask. Submit it yourself to use your configured AI provider.

These are rule-based checks, not a diagnosis. They compare consecutive one-hour error windows and identify open warning/critical threshold or SLO incidents in the selected environment. Proposed steps are a manual checklist. Reviewing a finding does not execute code, change services, acknowledge incidents or resolve issues.

Assistant, Errors and Metrics must be enabled. Reading requires all three module read permissions; managing schedules and reviews additionally requires application write access and a passkey verified within ten minutes. Background scans recheck the approving member's current access, including Google Workspace entitlement. Lost authority pauses the schedule until another authorized operator reviews it.

Each scan considers up to 10,000 retained error events and 50 active incidents, returning at most 25 matching issues and 25 incidents. Exceeding input bounds produces a limited scan with no conclusions. Error growth must meet the minimum count and growth factor; a zero baseline still requires the minimum count. A complete scan means these bounded rules ran, not that the service is healthy. There are at most 24 scans per rolling day and 2,000 retained findings per environment.

Evidence contains source identifiers, counts, observation windows, severity and static proposals. Raw messages, stacks, identity fields and provider secrets are not copied. One snapshot per source per UTC day preserves the original evidence and human decision; subsequent scans increase its observation count. Follow source links for the current state.

Findings and scan history expire after seven days or the application's shorter retention. Shortened retention applies immediately to reads and review actions, with hourly fair cleanup. Deleting the original issue or incident removes its findings. The append-only audit retains settings, scan and review receipts. Coding-agent handoff and automatic fixes are outside this initial capability.