Skip to main content
Investigations are only as good as the context they can reach. Each source you connect gives investigations another angle on what’s happening, and findings grounded in several sources at once are far more reliable than guesses from one. The more independent evidence an investigation can find, the more conviction it can have in a finding rather than guess. Connect whatever you have; you don’t need everything to get value. All sources are configured from the Investigations settings in your dashboard.

Sources

Past incidents

Find similar incidents and the fixes that worked before.

Slack channels

Real-time context: deploys, config changes, and team discussion.

Change events

Deploys, feature flags, and config changes, extracted from your channels and correlated with incidents.

Documentation

Search your runbooks and reference docs from Confluence, Notion, GitHub, and GitLab.

Code repositories

Link relevant pull requests and read your code, safely sandboxed.

Telemetry

Logs, metrics, traces, and dashboards from your observability tools.

How investigations use each source

Connecting Slack channels as a source (and the change events built from them) is available for Slack only. Every other source works the same whether your incidents run in Slack or Microsoft Teams.
Start with the sources your responders already lean on during incidents. If your team lives in a particular Grafana dashboard and a Slack deploys channel, connect those first.

Always on: third-party dependencies

One source needs no setup. Every investigation automatically checks whether third-party providers you depend on, like AWS, GitHub, Stripe, or Datadog, were having an outage around the time of your incident. See Third-party dependencies.

FAQs

Yes. Extensions let you connect your own MCP servers, and write skills that tell investigations how to use them. To reach a private or self-hosted system, run a proxy in your network and attach the data source to it.
Yes. As well as opening a pull request itself, an investigation can delegate a code change to a coding agent your team already runs, like Cursor or Codex. See Delegating agents.