Investigations now available, powered by Nexus

August 5, 2026

Today we're making Investigations generally available. The moment an incident is declared, it reasons across your telemetry, code, past incidents, and dependencies, and within minutes posts a root cause hypothesis and its supporting evidence into the incident channel, before anyone's started digging. It's powered by Nexus, a living model of your environment that's now included on every plan.

Here's what's shipping:

  • An investigation kicks off automatically the moment an incident is declared, and surfaces wherever you work: Slack, MS Teams, the dashboard, the mobile app, the macOS app, and the remote MCP server.
  • Every finding links back to its evidence (a message, a PR, or a metric), so you can check the reasoning, not just the answer.
  • It works alongside you for the whole incident: ask it questions, steer it, or pull it into your coding agent over MCP.
  • You can delegate the fix: hand the code changes to an agent; our built-in agent, Cursor, GitLab Duo, or a custom agent.
  • A homepage that tracks accuracy, engagement, autonomy, and the feedback responders leave over time, so you can feel the impact of Investigations.
  • Nexus, the model underneath it all, is now available to every customer.

An investigation kicks off the moment an incident is declared

As soon as an incident is declared, an investigation does what an experienced engineer would: checks past incidents, commit history, telemetry, and logs, and whether upstream providers like AWS, GitHub, or Stripe were having an outage. See what you can connect.

The difference is it does all of it in parallel, from the second the alert fires, so there's already a hypothesis, the evidence behind it, and a recommended next step waiting in the channel by the time you open your laptop. See the incident channel experience.

You can also run an investigation on demand (with /inc investigate or by asking the agent), or set them to run on a condition or from a workflow. See triggering investigations.

Nothing is a black box. Every finding links straight to its source, whether a message, a pull request, or a spike in a metric, so you can see not just what it thinks but why. As new evidence arrives, it revisits its own hypotheses, strengthening or weakening them in the thread, and leaves the trail there for you to follow or challenge. See how investigations work.

An investigation works alongside you for the whole incident

An investigation keeps running for the life of the incident, taking in new information and surfacing what matters. Tag @incident to ask it questions ("have we seen this before?", "what changed recently?") or to steer it. With the macOS app you can pull the whole investigation into a coding agent like Claude Code, Cursor, or Codex in one click over MCP, work the problem with the same context it has, and share findings back to the channel.

Delegate the fix

Once an investigation reaches a conclusion, you don't have to take it from there by hand. Delegate the code changes to an agent (our built-in agent, Cursor, GitLab Duo, or a custom agent of your own), or pick the whole investigation up in your MCP and work it locally, with the same context it has. See making code changes and delegating agents.

Dig into any investigation, and track performance overall

The Investigations homepage tracks accuracy, engagement, and autonomy over time (how often it's right, whether responders act on it, and how much of each incident it diagnosed on its own), alongside the feedback responders leave on its messages. And you can open any past investigation and explore it in the timeline, from the first hypothesis through to the conclusion, to see exactly how it and your team got there.

Meet Nexus

Investigations is powered by Nexus, a living model of your production environment, built from your incidents, your systems, and your team. It's like having a teammate who's been in every incident you've ever had, knows every service you run, and can recall all of it instantly. Nexus gives every engineer that context, and it gets richer with every incident you resolve.

It's not a knowledge base that stores information; it reasons across it, connecting your catalog, telemetry, deploys, code, and past incidents into one picture and drawing conclusions in real time. That's what lets an investigation start from a hypothesis instead of a blank page: Nexus thinks, and the agent acts on what it knows.

A few things worth knowing:

  • Included on every plan. Nexus isn't a separate purchase; it's the foundation underneath the platform, from day one. View Nexus in the dashboard here.
  • Every product makes it richer. The more of incident.io you use, the more Nexus has to learn from.
  • Unique to your organization. Every customer gets their own instance. Your data never trains shared models.
  • SOC 2 compliant, zero data retention. We have agreements with every model provider, so your data is never stored or used for their training.

And a whole lot more

We've included so much more in Investigations, too:

  • Wait for an investigation: hold an escalation from paging until the investigation has a first hypothesis, so whoever you wake up arrives to context instead of a cold start. See wait for investigation.
  • Automatic duplicate merging: it spots when two open incidents are the same problem and merges them, or drops a one-click merge suggestion into the channel with its reasoning.
  • Catch-me-up: join a live incident and get a summary that folds in the investigation's findings alongside what's happened so far.
  • See who started an investigation: every investigation shows how it began (manually, by a workflow, or automatically) and who triggered it, across all surfaces.
  • Alternative explanations: when there's another equally likely theory, it surfaces it in the thread with an Add context button so you can steer.
  • Self-diagnosing telemetry connections: when a data source won't connect, a structured checklist shows exactly what's failing and how to fix it.
  • Configurable data retention: set a retention window per telemetry source, so investigations never query beyond where your data actually exists.

Nexus is included on every plan and rolling out today. Investigations is a new product, available to purchase now for Pro and Enterprise customers. Get a demo to see how it performs on your own incidents, and read more in our blog post.


So good, you’ll break things on purpose

Ready for modern incident management? Book a call with one of our experts today.

Signup image

We’d love to talk to you about

  • All-in-one incident management
  • Our unmatched speed of deployment
  • Why we’re loved by users and easily adopted
  • How we work for the whole organization