Skip to content

How evidence flows

The model reasons. The graph holds relationships. Live tools report current state. Confirmed learning is preserved — without retraining a model on your data.

  1. Your systems — logs, metrics, queues, deployments and code.
  2. Read-only connectors — bounded access to each source. Secrets stay in your vault.
  3. Bounded investigation tools — allow-listed, read-only tools that run server-built queries. The model never writes its own queries or commands.
  4. Reasoning and evidence graph — every tool result is kept as cited evidence, linked to the services, changes and hypotheses it supports or contradicts.
  5. Human-confirmed RCA — an engineer reviews and confirms the root cause analysis.
  6. Institutional memory — only confirmed RCAs and resolutions become trusted memory for future investigations.
Layer What it holds
Live signals What is happening now — logs, metrics, queues, deployments.
Knowledge graph How services, code, owners and incidents relate.
Semantic memory Runbooks and confirmed past incidents, retrieved by meaning.
Reasoning A language model that explains verified results — it never invents numbers.

Evidence status, transaction counts, affected-customer counts and policy decisions are calculated deterministically from tool results. The language model explains those verified results; it does not produce them.

Next: Evidence labels.