Skip to main content
Use at least one alert source to create Incidents and add only the evidence sources your on-call team is permitted to read. A connected source is queried only when it is relevant to the Investigation and its verified access allows the Tool. Creating, changing, verifying, disabling, or removing an Integration requires the Role stated by its generated API operation; the console requires an Admin for setup. Each provider guide gives the least-privilege permissions, exact procedure, verification, limitations, rotation, and removal behavior. Verification records what the current credential and provider installation make available. It does not prove that a future Investigation will contain enough evidence to establish a cause. Provider content remains untrusted, and read-only access still requires the deployment owner to review retention, network, and credential policy. Start with Connect your tools, then run an Investigation.