> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rootly.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Running an AI SRE Investigation

> Start a Rootly AI SRE investigation from an alert, an incident or Slack, run investigations automatically, and follow one while it works.

Rootly AI SRE runs an investigation on one alert or incident and writes the result to that record's **AI SRE** tab. This page covers every way an investigation starts, what each one needs, and what you see while it runs.

<Info>
  Your Rootly account team enables AI SRE for the selected team. Until it does, **AI & Agents → AI SRE** shows a waitlist page and alerts and incidents have no **AI SRE** tab. Account-level automatic investigation, **Rerun investigation**, the **Investigations** page and Slack delivery of results may not be enabled for every team either; the Rootly account team turns them on. See [Getting Started](/ai/ai-sre/getting-started) for enablement.
</Info>

## Ways to Start an Investigation

| Trigger                                       | Alerts                         | Incidents                                                              | What It Needs                                                                   |
| --------------------------------------------- | ------------------------------ | ---------------------------------------------------------------------- | ------------------------------------------------------------------------------- |
| **Start investigation** on the **AI SRE** tab | Yes                            | Yes, except scheduled maintenance                                      | Write access to the alert or incident                                           |
| An **Auto-run** investigation rule            | New alerts that match the rule | No                                                                     | A rule set to **Auto-run**                                                      |
| Account-level automatic investigation         | Every new alert                | Every new incident, except scheduled maintenance and example incidents | Turned on by your Rootly account team                                           |
| Asking Rootly in Slack                        | Yes                            | Yes, except scheduled maintenance                                      | Write access to the alert or incident                                           |
| **Rerun investigation**                       | Yes                            | Yes                                                                    | A finished investigation, write access, and Rerun enabled for the selected team |

Every trigger runs the same investigation and puts the result on the record's **AI SRE** tab. The trigger decides which investigation rule, if any, adds its instructions to the run. [Investigation Rules](/ai/ai-sre/investigation-rules) explains how that rule is chosen.

A follow-up question in the **Chat** panel doesn't start an investigation. It asks about one that has already finished, as described in [Ask Follow-Up Questions](#ask-follow-up-questions).

## Start an Investigation Manually

Run AI SRE from an alert or a non-maintenance incident.

<Steps>
  <Step title="Open the AI SRE Tab">
    Open the affected alert or incident, then select the **AI SRE** tab.
  </Step>

  <Step title="Start the Investigation">
    Select **Start investigation**. You need write access to the alert or incident.
  </Step>

  <Step title="Follow the Investigation">
    Watch the investigation stages and the possible causes AI SRE tests as they update. When it finishes, the verdict card shows the outcome, and the report below it sets out what happened and the evidence behind it.
  </Step>

  <Step title="Rate the Result">
    Use the **How accurate was this investigation?** control on the completed investigation to record whether the diagnosis matched what happened. See [Reading the Result](/ai/ai-sre/reading-the-result) for the rating and the report.
  </Step>
</Steps>

Members without write access see "You don't have permission to start an investigation. Ask a teammate with write access to run AI SRE — you'll be able to view the results here." They can read the shared result once a teammate starts the run. See [Manage User Permissions](/managing-users/user-permissions#ai-agents-and-ai-sre) for the full permissions matrix.

**Start investigation** appears only while the alert or incident has no investigation. After a run exists, the tab shows that run in place of the button, and the tab's **Start investigation** action and automatic triggers don't begin another. Use **Rerun investigation**, where available, for a fresh run from the tab. A new Slack request can start a fresh run after the earlier one finishes, as described below.

AI SRE doesn't appear on scheduled maintenance incidents because they don't represent a failure to diagnose.

<Warning>
  The completed investigation is shared with everyone who can read the alert or incident. Rootly doesn't re-filter the report for each later viewer based on whether that viewer could run the connector or Private Agent query themselves. Treat alert and incident readers as the audience for evidence included in the report, and scope sensitive provider credentials, Private Agent access and source data to match.
</Warning>

## Run Investigations Automatically

AI SRE starts on its own in two cases: an **Auto-run** investigation rule matches a new alert, or your Rootly account team has turned on account-level automatic investigation.

### With Investigation Rules

An [investigation rule](/ai/ai-sre/investigation-rules) set to **Auto-run** starts AI SRE when a new alert matches its conditions, such as title, description, urgency, source, status or a custom alert field. Rules apply to alerts only.

Rootly checks rules once, shortly after an alert is created, and skips alerts that already have an investigation or arrive during the rule's cooldown. See [Run Modes](/ai/ai-sre/investigation-rules#run-modes) for details.

Use automatic investigations for high-signal alert classes where responders benefit from evidence before they open the alert. Keep noisy or experimental alert classes in **Manual** mode until the 90-day match preview and completed reports look reliable. A rule with no conditions matches every alert, so an empty **Auto-run** rule investigates every new alert that arrives outside its cooldown.

### Account-Level Automatic Investigation

Rootly can also turn on automatic investigation for the selected team. There's no setting for it in **AI & Agents**; your Rootly account team turns it on or off. When it's on:

* Every new alert is investigated automatically, whether or not a rule matches.
* If an **Auto-run** rule matches, the run uses that rule's instructions, and while the rule's cooldown is active the alert isn't investigated automatically.
* An alert that matches only a **Manual** or **Paused** rule is still investigated, without that rule's instructions.
* Every new incident is investigated automatically, except scheduled maintenance incidents and example incidents.

## Investigate an Incident

Start an incident investigation yourself from the incident's **AI SRE** tab or by asking Rootly in Slack. Investigation rules never apply to incidents, so an incident is investigated automatically only when account-level automatic investigation is on.

Scheduled maintenance incidents have no **AI SRE** tab. Asking Rootly to investigate one in Slack gets the reply "There's nothing to root-cause on a scheduled maintenance incident."

## Ask Rootly in Slack

Mention `@Rootly` and ask it to investigate. See [Using Rootly AI in Slack](/ai/rootly-in-slack/using-rootly-in-slack) for where you can mention it. Rootly picks the target in this order:

1. An incident you name, such as `investigate INC-123`, or an alert you name by its ID.
2. The incident the channel or conversation is about.
3. The alert whose announcement thread you're asking in.

If none of these resolves, Rootly starts nothing and asks you to name an incident or alert, or to ask from its channel or thread. You need write access to the target. Rootly won't post a private incident's investigation outside that incident's own channel, and it tells you which channel to ask in.

When the run starts, Rootly replies "Starting a root-cause investigation for" followed by the alert or incident title, then "follow progress in the AI SRE tab." The run doesn't reply to your request with its findings. The result appears on the record's **AI SRE** tab and, where Slack delivery is enabled, in the Slack messages described in [What You See While It Runs](#what-you-see-while-it-runs).

Slack requests aren't limited to one investigation per alert or incident. In the same thread, Rootly reuses an investigation that's still running. Once it has finished, a new request starts a new investigation, and the **AI SRE** tab shows the most recent one.

## Rerun an Investigation

Where Rerun is enabled, a finished investigation shows **Rerun investigation**, including one that ended with **Failed**. It asks "Start a fresh investigation? The current results stay available in this alert's history." and starts a new investigation, which counts as a manual run. You need write access to the alert or incident.

A rerun matches investigation rules again against the alert as it is at that moment, so it can pick up instructions from a rule added since the first run. The **AI SRE** tab then shows the new investigation. See [Reading the Result](/ai/ai-sre/reading-the-result) for what the finished report contains.

## Ask Follow-Up Questions

After an investigation completes, members with write access get a **Chat** panel on the **AI SRE** tab. Type into **Ask a follow-up about this investigation…** to ask what the investigation ruled out, what a signal means or what to check next.

A follow-up doesn't start a new investigation and never changes the report. To answer, AI SRE can query your connected tools again. See [Ask Follow-Up Questions in Chat](/ai/ai-sre/reading-the-result#ask-follow-up-questions-in-chat).

Chat isn't available while the investigation is still running, or on an investigation that ended with **Failed**.

## What You See While It Runs

After you select **Start investigation**, the tab shows **Investigating…** until the live run takes over. A **Live investigation** box then shows:

* A stage indicator, **Preparing** and then **Stage N of M**, with a sentence describing the current stage. Stage names include **Gather facts**, **Investigate** and **Write verdict**.
* A progress bar and an elapsed-time clock.

Below it, the **Investigation path** lists each check and each possible cause as AI SRE tests it. Expand a check to see the tool calls behind it. The tab updates live, so you don't need to reload it, and the investigation keeps running in the background if you leave the page. [Hypothesis Testing](/ai/ai-sre/hypothesis-testing) explains what each stage does.

Where Slack delivery is enabled, AI SRE also posts a message that it updates as the run progresses: for an alert, a threaded reply under each channel message that announced it; for an incident, a top-level message in the incident channel. When the run finishes, the message becomes a summary with a **View Full Investigation in Web** link. [Reading the Result](/ai/ai-sre/reading-the-result) covers Slack delivery in detail.

## How an Investigation Ends

Every investigation runs within limits on model spend, tool calls and reasoning turns. When a stage reaches its limit, AI SRE stops gathering evidence for it and reports what it established. There's no control to stop an investigation early; it ends when it finishes or reaches those limits.

AI SRE is built to abstain rather than invent a cause:

* Claims must cite what a tool actually returned. Rootly drops claims that cite nothing.
* Rootly, not the model, settles the outcome from the evidence gathered.
* When the evidence doesn't confirm a root cause, the result says so, for example **Inconclusive — needs human**, instead of naming a guess.
* When AI SRE couldn't gather any evidence, the outcome is **Could not investigate**. On the default flow the tab can show **Inconclusive — needs human** for such a run; see [Outcome Labels](/ai/ai-sre/reading-the-result#outcome-labels).

Instructions guide the investigation, but they don't count as evidence. AI SRE only attributes a cause when the evidence gathered during the investigation supports it. See [Hypothesis Testing](/ai/ai-sre/hypothesis-testing) for how causes are tested and [Reading the Result](/ai/ai-sre/reading-the-result) for every outcome.

## Automatic Runs and Unattended Access

An automatic investigation is a system-triggered run, so there is no initiating responder whose personal provider permissions can be used. It uses the team's connector credentials and the tools each connector exposes to AI SRE. For Rootly's own permission checks, an automatic run acts as an owner or admin on the selected team, so it can read Rootly data that some readers of the alert can't. Everyone who can read the alert or incident sees the finished report. When AI SRE and Private Agent are enabled, it can also use registered Private Agent capabilities under the `ai-sre` system actor.

That access isn't guaranteed to be read-only:

* Some built-in connectors, for example Atlassian, Notion, Linear and AWS, pass the provider's full tool catalog to AI SRE, and a built-in connector tool can accept provider-defined commands or queries that change data when the provider account allows it.
* Custom MCP tools can be write-capable, and Rootly doesn't classify their behavior.
* Private Agent capabilities can include HTTP write requests and SQL execution against a database, and they run without an interactive approval step.

Expose only connector capabilities, provider commands, tools, local policies and credentials that are safe for unattended use. Setting a rule to **Auto-run** authorizes this unattended run for every alert the rule matches. When account-level automatic investigation is on, every new alert and incident gets this unattended run.

When you start an investigation yourself, AI SRE uses your Private Agent permissions for its private capability calls. An automatic investigation instead uses the `ai-sre` system actor. The AI connectors and private agents an investigation calls are part of [Atlas](/ai/atlas/overview), Rootly's AI layer. See [Evidence Sources](/ai/ai-sre/evidence-sources) for every access boundary, and [AI Connectors](/ai/connectors/overview) and [Private Agents](/private-agent) to set each one up.

## Troubleshooting

<AccordionGroup>
  <Accordion title="The AI SRE tab doesn't appear on an alert or incident" icon="eye-slash">
    Either AI SRE isn't enabled for the selected team, or the record is a scheduled maintenance incident. When AI SRE isn't enabled, **AI & Agents → AI SRE** shows a waitlist page. Contact your Rootly account team to enable it.
  </Accordion>

  <Accordion title="Start investigation isn't available on the AI SRE tab" icon="hand-pointer">
    If the tab shows the message about asking a teammate with write access, you don't have write access to the alert or incident. Ask a teammate who does, or see [Manage User Permissions](/managing-users/user-permissions#ai-agents-and-ai-sre). If the tab shows an investigation instead, the record already has one. Use **Rerun investigation** where it's available.
  </Accordion>

  <Accordion title="An automatic investigation didn't start on an alert" icon="play">
    Work through these causes:

    1. The rule isn't set to **Auto-run**. **Manual** rules never start a run on their own.
    2. The alert didn't match every condition at the moment it was created.
    3. The rule was created or edited after the alert arrived. Rules aren't applied to existing alerts.
    4. The alert already had an investigation.
    5. The matching rule's cooldown was active, so the alert was skipped.

    See [Investigation Rules](/ai/ai-sre/investigation-rules) for conditions, run modes and cooldowns.
  </Accordion>

  <Accordion title="Alerts are investigated automatically with no Auto-run rule" icon="bolt">
    Account-level automatic investigation is on for the selected team. **Manual** and **Paused** rules don't stop it. Contact your Rootly account team to change it.
  </Accordion>

  <Accordion title="Too many automatic investigations are running" icon="gauge-high">
    A broad **Auto-run** rule, or one with no conditions, is the usual cause. Tighten its conditions, add a cooldown, or switch it to **Manual** or **Paused**. If alerts are investigated with no rule behind them, account-level automatic investigation is on; contact your Rootly account team.
  </Accordion>

  <Accordion title="Rootly in Slack didn't start an investigation" icon="slack">
    Rootly couldn't tell which alert or incident you meant, you don't have write access to it, it's a scheduled maintenance incident, or it's a private incident and you asked outside its channel. Name the incident, for example `investigate INC-123`, or ask from the incident channel or the alert's announcement thread.
  </Accordion>

  <Accordion title="The investigation ended with Failed" icon="circle-exclamation">
    A failed investigation shows a **Failed** card and the **Investigation path**, with no report or Chat. Open the **Investigation path** to see how far it got. If a provider's checks failed, check that connector's status under **AI SRE → Atlas → Connectors** (**AI & Agents → Connectors** if your sidebar doesn't have an **AI SRE** item). Use **Rerun investigation**, where it's available, to try again.
  </Accordion>
</AccordionGroup>

## Frequently Asked Questions

<AccordionGroup>
  <Accordion title="Can I start an investigation from a workflow or the API?" icon="code">
    No. Investigations start from the **AI SRE** tab, from Rootly in Slack, from **Rerun investigation**, from an **Auto-run** investigation rule, or from account-level automatic investigation.
  </Accordion>

  <Accordion title="Can I stop an investigation that's running?" icon="circle-stop">
    No. The **AI SRE** tab has no cancel control. An investigation ends when it finishes or reaches its limits.
  </Accordion>

  <Accordion title="Does a follow-up question in Chat start a new investigation?" icon="comment">
    No. A follow-up is a private conversation about a finished investigation. It doesn't create a run and doesn't change the report.
  </Accordion>

  <Accordion title="Why does the AI SRE tab show a different investigation than the one I started?" icon="clock-rotate-left">
    The tab shows the most recent investigation for the alert or incident. A rerun or a Slack request after yours finished creates a newer one. Where the **Investigations** page is available, each run appears there as its own row. See [The Investigations Page](/ai/ai-sre/reading-the-result#the-investigations-page) for how each run's trigger is labelled.
  </Accordion>

  <Accordion title="Does pausing a rule stop an investigation that's already running?" icon="pause">
    No. Pausing a rule stops it from starting new automatic runs and from adding its instructions to new runs. Runs already in progress finish normally.
  </Accordion>
</AccordionGroup>

## Related Pages

<CardGroup cols={2}>
  <Card title="Rootly AI SRE" icon="robot" href="/ai/ai-sre/overview">
    How AI SRE investigates, the outcomes it reports, and its settings.
  </Card>

  <Card title="Investigation Rules" icon="sliders" href="/ai/ai-sre/investigation-rules">
    Choose which alerts AI SRE investigates automatically and which instructions it follows.
  </Card>

  <Card title="Reading the Result" icon="clipboard-check" href="/ai/ai-sre/reading-the-result">
    Read the outcome, evidence and next steps, rate the result, and ask follow-ups.
  </Card>

  <Card title="Hypothesis Testing" icon="flask" href="/ai/ai-sre/hypothesis-testing">
    How AI SRE tests possible causes against evidence before it names one.
  </Card>

  <Card title="Evidence Sources" icon="database" href="/ai/ai-sre/evidence-sources">
    What an investigation can read, and the access boundaries it runs under.
  </Card>
</CardGroup>
