How evidence flows
The model reasons. The graph holds relationships. Live tools report current state. Confirmed learning is preserved — without retraining a model on your data.
From your systems to institutional memory
Section titled “From your systems to institutional memory”- Your systems — logs, metrics, queues, deployments and code.
- Read-only connectors — bounded access to each source. Secrets stay in your vault.
- Bounded investigation tools — allow-listed, read-only tools that run server-built queries. The model never writes its own queries or commands.
- Reasoning and evidence graph — every tool result is kept as cited evidence, linked to the services, changes and hypotheses it supports or contradicts.
- Human-confirmed RCA — an engineer reviews and confirms the root cause analysis.
- Institutional memory — only confirmed RCAs and resolutions become trusted memory for future investigations.
Four layers
Section titled “Four layers”| Layer | What it holds |
|---|---|
| Live signals | What is happening now — logs, metrics, queues, deployments. |
| Knowledge graph | How services, code, owners and incidents relate. |
| Semantic memory | Runbooks and confirmed past incidents, retrieved by meaning. |
| Reasoning | A language model that explains verified results — it never invents numbers. |
What is calculated, and what is explained
Section titled “What is calculated, and what is explained”Evidence status, transaction counts, affected-customer counts and policy decisions are calculated deterministically from tool results. The language model explains those verified results; it does not produce them.
Next: Evidence labels.