While the Investigation Runs
While a run is going, the tab shows a Live investigation box; see What You See While It Runs. Some investigations also show a Verdict so far block while checks continue. Its status reads Preliminary, Confirmed or Revised, followed by · still being checked. Treat it as a working answer until the verdict card appears.The Verdict Card
When the investigation ends, a verdict card replaces the progress box. It carries:- The outcome label, which says what the investigation concluded. See Outcome Labels.
- A one-line summary under the label. For Root cause identified, this line names the root cause.
- A confidence tier, shown only for Root cause identified. See Confidence.
- Suspected area, when no root cause was confirmed and AI SRE has a leading possible cause. It’s marked Suspected, not confirmed, so treat it as a lead to check rather than a conclusion.
- Elapsed time, and a count of checks and tool calls such as 8 checks · 23 tool calls.
- Rerun investigation, where enabled. See Rerun an Investigation.
- How accurate was this investigation?, the accuracy rating. See Rate the Accuracy.
Outcome Labels
Every finished investigation ends with one of these labels on the AI SRE tab.Confidence
A Root cause identified result carries one of three confidence tiers: High confidence, Medium confidence or Low confidence. The tier can be followed by a count of the decisive evidence behind it, such as 2 decisive signals. It reflects how strongly the evidence supports the root cause. Hypothesis Testing explains how AI SRE reaches it. Other outcomes show no tier, and the tab never shows confidence as a number. The Investigations page and Slack differ. The Confidence column on the Investigations page shows a percentage for any run that has a confidence value, whatever its outcome. Slack messages show no confidence. Read a percentage alongside the Outcome column: a percentage on an Inconclusive run doesn’t mean a root cause was found.The Report
Below the verdict card, the report sets out the reasoning. Only sections with content appear.What Happened
What happened opens with a narrative of the problem as AI SRE reconstructed it. Below the narrative, a causal chain lists each link between the trigger and the symptom, in time order. Each link can carry a UTC clock time, the evidence behind it, and a status of Confirmed, Likely or Refuted. Investigations on the six-stage flow present What happened as questions instead: What failed?, What set it off? and What has been ruled out or remains open? These can include a chart of the alerting signal and an Alternatives weighed list of the explanations AI SRE compared. When the trigger wasn’t found, What set it off? starts with Unknown. and says how many candidates were measured.Evidence
Evidence lists what AI SRE found, one card per item. Each card shows what was observed, the source with its vendor logo, and a View link that opens the item in the source tool when a link is available. Each item is weighted Decisive or Supporting. Decisive items come first. Supporting items sit under Supporting context, which starts open when there are fewer than three. The legend also lists Strong, a weight current investigations don’t assign. When the outcome isn’t Root cause identified, a line above the cards says so, for example “6 facts recorded, 1 decisive. Nothing here confirms a cause.”Recommended Next Steps
Recommended next steps appears when an investigation ends without a root cause or contributing factor. A Blocked run lists the fix, such as reauthorizing a connector with permission to read monitors, metrics, logs and traces, or connecting a tool that can read the alert’s data source, and then rerunning the investigation. Otherwise the section reads “No follow-up actions were recorded. This investigation has no next step to hand you.” A result with a root cause or contributing factor has no next-steps section. Ask in Chat what to check or change next, and put any change through your normal review before it touches production.The Investigation Path
The Investigation path follows the report. It’s a collapsible trail, open by default, of the possible causes AI SRE considered and the checks it ran. On a finished run, its header counts them, such as 3 possible causes · 9 checks · 27 tool calls. Each line carries a state. Hover over a state to see its meaning.Ask Follow-Up Questions in Chat
The Chat panel lets you ask about a completed investigation: what it ruled out, what a signal means, what to check next. It opens once the investigation completes, for members with write access to the alert or incident. Chat isn’t available on a failed run. Chat is private. The panel is marked Only you can see this, and each person gets a separate conversation for each investigation, starting from its report. To answer, AI SRE can query your connected tools again. Nothing you ask in Chat changes the report or reaches your teammates. When you know something the investigation missed, such as a manual config change or a vendor outage, ask Chat to reason about it. Then rate the result, and rerun once the gap is closed.Rerun an Investigation
Where enabled, Rerun investigation on the verdict card starts a fresh investigation of the same alert or incident. It appears once the latest investigation has finished, whether it completed, failed or was cancelled, and it needs write access to the alert or incident. Rootly asks you to confirm: “Start a fresh investigation? The current results stay available in this alert’s history.” The rerun counts as a manual run. Afterward, the tab shows the newest investigation. Earlier runs keep their rows on the Investigations page, with their outcome, confidence and your feedback. Rerun after you change something the investigation depends on:- Connect a missing source or fix a connector’s permissions under AI SRE → Atlas → Connectors (AI & Agents → Connectors if your sidebar doesn’t have an AI SRE item). See AI Connectors.
- Update Instructions when every investigation should check something it missed.
- Update the matching investigation rule when only one alert class needs different guidance.
Rate the Accuracy
Rate a finished investigation with How accurate was this investigation? Choose a score between 0 (not at all) and 5 (spot on). The follow-up question depends on the score:- 3 or more asks Anything that could have been better? with Too Verbose, Missed Context, Weak Evidence and Took Too Long.
- 2 or less asks What did it get wrong? with Wrong Root Cause, Missed a Signal, Hallucinated, Wrong Service and Irrelevant.
Who Can See a Result
Anyone who can read an alert or incident can open its AI SRE tab and read the result. Starting an investigation, rerunning it and using Chat need write access to that alert or incident. Manage User Permissions covers who can configure AI SRE.The Investigations Page
Where enabled, the Investigations page lists AI SRE investigations for the selected team on alerts and incidents you can read. Select a row to open that alert’s or incident’s AI SRE tab. Open it from AI SRE in the sidebar, where Investigations is the first tab and Atlas the second. Teams that don’t have the consolidated navigation yet open Investigations as its own sidebar item. Four cards at the top summarize the investigations that match the current period, filters and search:- Investigations: how many ran in the period.
- Root cause identified: the share of concluded investigations that identified a root cause.
- Ran autonomously: the share that started automatically, with no person involved.
- Median duration: the median time an investigation took.
Results in Slack
Where enabled, and when Slack is connected, AI SRE posts each investigation to Slack and edits the message in place as the run progresses:- For an alert, a threaded reply under each channel message that announced the alert.
- For an incident, a top-level message in the incident channel.
Troubleshooting
The result says Inconclusive — needs human
The result says Inconclusive — needs human
The result says Blocked
The result says Blocked
The root cause names a service my team doesn't own
The root cause names a service my team doesn't own
Chat or Rerun investigation doesn't appear
Chat or Rerun investigation doesn't appear
The Investigations page shows a different outcome than the tab
The Investigations page shows a different outcome than the tab
The report contradicts what your team found
The report contradicts what your team found
A View link on an evidence card doesn't open
A View link on an evidence card doesn't open
Frequently Asked Questions
Does the report change after the incident resolves?
Does the report change after the incident resolves?
Why doesn't AI SRE always name a root cause?
Why doesn't AI SRE always name a root cause?
Who can see my Chat questions?
Who can see my Chat questions?
Why is there no confidence tier on my result?
Why is there no confidence tier on my result?
Can I copy the result into a retrospective?
Can I copy the result into a retrospective?