Investigation flow
- Orient. OpenCluster starts with the incident question, alert labels and annotations, timing, source links, and a current Kubernetes workload inventory when available.
- Select useful sources. Verified integrations expose only the reads their granted access supports. OpenCluster chooses among them based on the incident; it does not query every integration by default.
- Follow the results. Each result informs the next read. The path is adaptive, not a fixed checklist.
- Conclude. OpenCluster records supported findings, unresolved leads, and practical next steps. Each finding cites the reads behind it.