Skip to main content
When Rootly AI SRE finishes an investigation, the AI SRE tab on the alert or incident shows what it concluded, the evidence behind that conclusion, and every check it ran. Use this page to read each part of the result, ask follow-up questions, and record how accurate it was.
Rerun investigation, the Investigations page and Slack delivery of results may not be enabled for every team. Your Rootly account team turns them on. To start an investigation, see Running an Investigation.

While the Investigation Runs

While a run is going, the tab shows a Live investigation box; see What You See While It Runs. Some investigations also show a Verdict so far block while checks continue. Its status reads Preliminary, Confirmed or Revised, followed by · still being checked. Treat it as a working answer until the verdict card appears.

The Verdict Card

When the investigation ends, a verdict card replaces the progress box. It carries:
  • The outcome label, which says what the investigation concluded. See Outcome Labels.
  • A one-line summary under the label. For Root cause identified, this line names the root cause.
  • A confidence tier, shown only for Root cause identified. See Confidence.
  • Suspected area, when no root cause was confirmed and AI SRE has a leading possible cause. It’s marked Suspected, not confirmed, so treat it as a lead to check rather than a conclusion.
  • Elapsed time, and a count of checks and tool calls such as 8 checks · 23 tool calls.
  • Rerun investigation, where enabled. See Rerun an Investigation.
  • How accurate was this investigation?, the accuracy rating. See Rate the Accuracy.

Outcome Labels

Every finished investigation ends with one of these labels on the AI SRE tab.
Contributing factor identified and Blocked appear only for teams that Rootly has set to the six-stage flow described in Hypothesis Testing. On the default flow, a run that didn’t confirm a cause shows Inconclusive — needs human, and the card can name the leading possible cause under Suspected area. There, the tab shows Could not investigate only when the run made no checks at all. A run that made checks but gathered no usable evidence shows Inconclusive — needs human on the tab and Could not investigate on the Investigations page and in Slack.
The Investigations page and Slack use a shorter set of labels: Root cause identified, Best effort, Inconclusive, Blocked and Could not investigate, plus Failed in Slack. Best effort there matches Contributing factor identified on the tab. On the default flow, a run the tab shows as Inconclusive — needs human can also appear as Best effort on those surfaces. On the Investigations page, a failed or cancelled run shows in the Status column.

Confidence

A Root cause identified result carries one of three confidence tiers: High confidence, Medium confidence or Low confidence. The tier can be followed by a count of the decisive evidence behind it, such as 2 decisive signals. It reflects how strongly the evidence supports the root cause. Hypothesis Testing explains how AI SRE reaches it. Other outcomes show no tier, and the tab never shows confidence as a number. The Investigations page and Slack differ. The Confidence column on the Investigations page shows a percentage for any run that has a confidence value, whatever its outcome. Slack messages show no confidence. Read a percentage alongside the Outcome column: a percentage on an Inconclusive run doesn’t mean a root cause was found.

The Report

Below the verdict card, the report sets out the reasoning. Only sections with content appear.

What Happened

What happened opens with a narrative of the problem as AI SRE reconstructed it. Below the narrative, a causal chain lists each link between the trigger and the symptom, in time order. Each link can carry a UTC clock time, the evidence behind it, and a status of Confirmed, Likely or Refuted. Investigations on the six-stage flow present What happened as questions instead: What failed?, What set it off? and What has been ruled out or remains open? These can include a chart of the alerting signal and an Alternatives weighed list of the explanations AI SRE compared. When the trigger wasn’t found, What set it off? starts with Unknown. and says how many candidates were measured.
When a root cause sounds plausible but you doubt the mechanism, read the causal chain one link at a time. Links marked Likely are suspected rather than established, so start there.

Evidence

Evidence lists what AI SRE found, one card per item. Each card shows what was observed, the source with its vendor logo, and a View link that opens the item in the source tool when a link is available. Each item is weighted Decisive or Supporting. Decisive items come first. Supporting items sit under Supporting context, which starts open when there are fewer than three. The legend also lists Strong, a weight current investigations don’t assign. When the outcome isn’t Root cause identified, a line above the cards says so, for example “6 facts recorded, 1 decisive. Nothing here confirms a cause.”
To challenge a root cause, start with its Decisive evidence. If a decisive item is a misreading, the conclusion built on it usually falls too.
Recommended next steps appears when an investigation ends without a root cause or contributing factor. A Blocked run lists the fix, such as reauthorizing a connector with permission to read monitors, metrics, logs and traces, or connecting a tool that can read the alert’s data source, and then rerunning the investigation. Otherwise the section reads “No follow-up actions were recorded. This investigation has no next step to hand you.” A result with a root cause or contributing factor has no next-steps section. Ask in Chat what to check or change next, and put any change through your normal review before it touches production.

The Investigation Path

The Investigation path follows the report. It’s a collapsible trail, open by default, of the possible causes AI SRE considered and the checks it ran. On a finished run, its header counts them, such as 3 possible causes · 9 checks · 27 tool calls. Each line carries a state. Hover over a state to see its meaning. Expand a check to see each tool call it made, with the Query AI SRE sent and the Result it got back. Look here when you want to know what AI SRE ruled out and why. A possible cause left inconclusive, or a check with no evidence, can mean AI SRE had no tool that could read the signal it needed. Evidence Sources explains what an investigation can reach.

Ask Follow-Up Questions in Chat

The Chat panel lets you ask about a completed investigation: what it ruled out, what a signal means, what to check next. It opens once the investigation completes, for members with write access to the alert or incident. Chat isn’t available on a failed run. Chat is private. The panel is marked Only you can see this, and each person gets a separate conversation for each investigation, starting from its report. To answer, AI SRE can query your connected tools again. Nothing you ask in Chat changes the report or reaches your teammates. When you know something the investigation missed, such as a manual config change or a vendor outage, ask Chat to reason about it. Then rate the result, and rerun once the gap is closed.

Rerun an Investigation

Where enabled, Rerun investigation on the verdict card starts a fresh investigation of the same alert or incident. It appears once the latest investigation has finished, whether it completed, failed or was cancelled, and it needs write access to the alert or incident. Rootly asks you to confirm: “Start a fresh investigation? The current results stay available in this alert’s history.” The rerun counts as a manual run. Afterward, the tab shows the newest investigation. Earlier runs keep their rows on the Investigations page, with their outcome, confidence and your feedback. Rerun after you change something the investigation depends on:
  • Connect a missing source or fix a connector’s permissions under AI SRE → Atlas → Connectors (AI & Agents → Connectors if your sidebar doesn’t have an AI SRE item). See AI Connectors.
  • Update Instructions when every investigation should check something it missed.
  • Update the matching investigation rule when only one alert class needs different guidance.

Rate the Accuracy

Rate a finished investigation with How accurate was this investigation? Choose a score between 0 (not at all) and 5 (spot on). The follow-up question depends on the score:
  • 3 or more asks Anything that could have been better? with Too Verbose, Missed Context, Weak Evidence and Took Too Long.
  • 2 or less asks What did it get wrong? with Wrong Root Cause, Missed a Signal, Hallucinated, Wrong Service and Irrelevant.
Check any that apply, add a comment, and select Submit. Skip saves the score alone, and Undo removes your rating. Add a comment when the result missed context, relied on weak evidence or named the wrong cause, so your team has a record of what it should have found. Anyone who can read the alert or incident can rate a finished investigation, including members with read-only access. Each person has one rating per investigation, and rating again replaces it. The Feedback column on the Investigations page shows your own score. A rating doesn’t change the report. To change what the next investigation does, adjust its connectors, instructions or rules, then rerun.

Who Can See a Result

Anyone who can read an alert or incident can open its AI SRE tab and read the result. Starting an investigation, rerunning it and using Chat need write access to that alert or incident. Manage User Permissions covers who can configure AI SRE.
A completed investigation is shared with everyone who can read the alert or incident. Rootly doesn’t re-filter the report for each later viewer based on whether that viewer could run the connector or Private Agent query themselves. Treat alert and incident readers as the audience for any evidence in the report, and scope sensitive provider credentials, Private Agent access and source data to match.

The Investigations Page

Where enabled, the Investigations page lists AI SRE investigations for the selected team on alerts and incidents you can read. Select a row to open that alert’s or incident’s AI SRE tab. Open it from AI SRE in the sidebar, where Investigations is the first tab and Atlas the second. Teams that don’t have the consolidated navigation yet open Investigations as its own sidebar item. Four cards at the top summarize the investigations that match the current period, filters and search:
  • Investigations: how many ran in the period.
  • Root cause identified: the share of concluded investigations that identified a root cause.
  • Ran autonomously: the share that started automatically, with no person involved.
  • Median duration: the median time an investigation took.
Narrow the list with the Search alerts and incidents box and the Period, Status, Outcome, Trigger and Resource filters. The period defaults to the last 30 days. The table shows each run’s Resource, Alert or incident, Status, Outcome, Confidence, Feedback, Trigger, Duration and Started time, newest first. Trigger reads Autonomous for automatic runs and Manual for runs a person started. Runs started from Slack show Slack Agent.

Results in Slack

Where enabled, and when Slack is connected, AI SRE posts each investigation to Slack and edits the message in place as the run progresses:
  • For an alert, a threaded reply under each channel message that announced the alert.
  • For an incident, a top-level message in the incident channel.
While the run is going, the message reads Investigation ongoing and lists the checks under way. When it finishes, the message becomes a short summary: a caption such as Rootly AI SRE ran a 6-phase investigation in 4 min, the outcome label and summary, a What happened paragraph when there is one, a count of hypotheses tested, confirmed and ruled out, and a View Full Investigation in Web link to the AI SRE tab. The Slack summary shows no confidence, evidence or next steps. Open the tab for those. If the alert or incident is linked to a private incident, AI SRE posts only in that incident’s own channel. When that link is made while the investigation runs, messages already posted in other channels are replaced with Investigation unavailable.

Troubleshooting

AI SRE ran checks but no root cause met its evidence bar. Start with Suspected area on the verdict card, if present, as a lead. Then open the Investigation path and look for possible causes marked inconclusive or checks with no evidence. These can point to a signal AI SRE couldn’t read. Connect that source or add Instructions that point to it, then rerun where available, or have a responder gather the named evidence.
A connector was refused permission, no connected tool could read the alert’s data source, or a similar access gap stopped the run. Follow the step under Recommended next steps: reauthorize the named connector or connect a tool that can read the source under AI SRE → Atlas → Connectors (AI & Agents → Connectors if your sidebar doesn’t have an AI SRE item), then rerun the investigation.
AI SRE can trace a cause to a dependency upstream of the service that alerted, using service relationships such as those in the Knowledge Graph where it’s enabled. Check the causal chain under What happened to confirm the path from that service to your symptom. The tab has no export control, so share the alert’s or incident’s link with the AI SRE tab open, or the Slack message, with the owning team.
Chat needs write access to the alert or incident and a completed investigation, and it isn’t offered on a failed run. Rerun investigation needs write access and a finished investigation, and it may not be enabled for the selected team. Ask your Rootly account team if you have access and the button still doesn’t appear.
The two surfaces use different label sets. Best effort on the Investigations page and in Slack matches Contributing factor identified on the tab, and on the default flow also Inconclusive — needs human. See Outcome Labels.
Rate the investigation 2 or less, check Wrong Root Cause or Missed a Signal, and describe what it should have found. Ask in Chat why AI SRE reached its conclusion; the answer can show which source it lacked or misread. Fix that gap, then rerun.

Frequently Asked Questions

No. A finished report stays as written, and Chat never changes it. A rerun starts a new investigation, and the tab then shows the newest one.
AI SRE names a root cause only when the evidence confirms one. Otherwise it reports a contributing factor, Inconclusive — needs human or Blocked rather than guess. See Hypothesis Testing.
Only you. Each person’s conversation about an investigation is private, and it doesn’t change the shared report.
The tab shows a confidence tier only when the outcome is Root cause identified. Every other outcome appears without one.
The tab has no export or share control. Copy the text you need from What happened, the causal chain and the evidence cards, whose View links point back to each source, or link to the alert’s or incident’s AI SRE tab.

Rootly AI SRE

How AI SRE investigates, the outcomes it reports, and its settings.

Running an Investigation

Start investigations by hand, from Slack, or automatically with rules.

Hypothesis Testing

How AI SRE tests possible causes and settles an outcome and confidence.

Evidence Sources

What an investigation reads, and where its access stops.

Instructions

Steer what every investigation checks and how it reports.