Prerequisites
- Complete the Quickstart or use an existing Incident.
- Connect and verify the evidence sources relevant to the alert.
- Confirm the model provider is configured and
/readyzsucceeds.
Start the Investigation
- Open the Incident created by an alert.
- Select Investigate.
- Ask a focused question, such as “Did a deployment precede the checkout latency alert?”
- Watch progress move from
queuedtoinvestigatingwhile OpenCluster reads the connected sources.
Understand the result
A finished result separates the summary, impact, Findings, hypotheses, Action Proposals, limitations, and numbered Tool Run citations.- A Finding is trustworthy only to the extent supported by its cited Tool Runs.
- A supported hypothesis is not a verified cause. Check its mechanism and competing explanations.
- An Action Proposal is advice, not an executed change. Review its risk, reversibility, approval requirement, citations, and verification procedure.
- A limitation names evidence OpenCluster could not obtain or a conclusion it could not defend.
unresolved, and propose a
human-approved rollback with a latency verification check. If either source is
unavailable, the result must state that limitation instead of claiming a cause.
Verify the outcome
Open each citation and confirm that its source, time window, and summary support the Finding. Review contradictions and truncated Tool Runs. A completed Investigation ends asconcluded, partial, needs_input, cancelled, or failed:
Select Cancel investigation when the question is no longer useful. Cancellation is
best effort: in-flight reads may stop, the terminal status becomes
cancelled, and no
later activity is accepted for that Investigation.
If an expected source is missing, return to its Integration, run verification, and check
its permissions. Do not reinterpret an inconclusive result as a cause.
Next, read Investigations and results.