Concepts / Investigations

Ask operational questions without losing the evidence.

Tracey makes conversational investigation useful by keeping tool activity, grounding status, sources, limitations, and investigation history attached to the answer.

Start from a real signal

Open an investigation from an alert, failed run, incident, trace, conversation, or natural-language question. The starting context becomes part of the durable timeline.

  • Why did this run fail?
  • Which tool or dependency contributed the most latency?
  • What changed before the error rate increased?
  • Did the workload recover after the approved change?

Evidence gathering

The investigator chooses bounded read tools across connected systems. It correlates agent spans with SigNoz logs and metrics, Kubernetes workloads and events, recent rollouts, and prior recovery history.

Investigation
├── question and scope
├── queries executed
├── evidence references
├── observed facts
├── deterministic calculations
├── hypotheses
└── limitations

A grounded answer

A useful answer names what was observed, how the conclusion was calculated, what remains uncertain, and which source or trace supports each important claim.

If a connector is unavailable or telemetry is incomplete, Tracey reports the limitation and narrows the conclusion.

From investigation to plan

An investigation can produce a typed remediation plan, but the plan is not an execution. It must pass deterministic policy evaluation and, where required, administrator approval before an executor can act.