Skip to main content
Root Cause Analysis (RCA) is the Analyze stage of Resolve. Anna gathers context, starts the read-only specialist work that the incident needs, tests competing explanations, and returns a structured verdict.

How an investigation runs

RCA can start automatically for an eligible Pulse incident when On Duty (automatic investigation) is on. A manually logged Incident waits until you click Investigate. RCA has three phases: The specialist set is dynamic. Anna selects the domains required by the evidence instead of running a fixed agent roster for every Incident. A typical investigation uses two to four subagents, with a maximum of eight.
RCA reads connected systems during investigation. A proposed action follows the runbook effect: Allow, Require Approval, or Deny.

Read the result

The investigation view keeps the conclusion and its proof together: Confidence is supporting context, not a guarantee. The interface groups the agent-recorded score as High at 0.8 or above, Medium from 0.5 to below 0.8, and Low below 0.5. Review the linked evidence before you approve a change.

Settle each remediation suggestion

Each remediation suggestion carries its own decision. From a suggestion’s actions menu, choose one and add an optional note: A settled suggestion keeps its state and note — a later analysis session never overwrites it. The note stays visible on the suggestion for anyone reviewing the incident.

Investigation outcomes

An investigation can end with one of these final outcomes: On hold is not a final outcome. It pauses the investigation when Anna needs information, access, or a decision. The Incident enters Needs your decision until a person supplies what RCA needs to continue. Acknowledged is also not final: a responder owns the Incident but analysis has not started. The Investigation queue groups work by what needs attention: AI is handling, Needs your decision, Not started, Resolved, and Dismissed. Incidents with a Not found result do not remain in the visible queue.

Correlated incident groups

When several alerts share a likely cause, Resolve groups them under one parent incident and runs RCA there, so all correlated alerts are analyzed together. Promotion asks you to confirm, then offers to start RCA on the promoted incident right away or leave it waiting for Investigate.

Start or re-investigate

1

Open an Incident

Select an Incident from the Investigation queue. Review its source, severity, signals, and existing evidence.
2

Start the investigation

Click Investigate when the Incident is waiting for manual analysis. Pulse-created Incidents can start automatically when On Duty is enabled and the routing rules qualify them.
3

Review the verdict

Read the root cause, causal graph, hypotheses, evidence, and remediation before you approve an action or resolve the Incident.
Re-investigate when new evidence changes the case. Every session updates the same investigation record: the timeline shows what each session added, and a changed conclusion is recorded as a root-cause revision rather than a second report.

Example investigation

These examples show how an investigation can move from one infrastructure symptom to a correlated root cause.
EC2 termination pattern analysis with Auto Scaling events and a timeline

An infrastructure investigation begins with the termination pattern.

Network failure correlation with CreateNetworkInterface errors

A second pass tests whether the symptoms share a cause.

Structured RCA report with evidence and remediation

Anna combines the supported findings into one reviewable verdict.

Log an Incident

Create an Incident from a human report, then start RCA when you are ready.

Control automatic RCA

Set On Duty behavior and re-investigation sensitivity.

Use runbooks

Review the actions that Resolve can suggest, approve, or block.

Reuse lessons

See how agent-written lessons can inform later investigations.