August 5, 2026
Today we're making Investigations generally available. The moment an incident is declared, it reasons across your telemetry, code, past incidents, and dependencies, and within minutes posts a root cause hypothesis and its supporting evidence into the incident channel, before anyone's started digging. It's powered by Nexus, a living model of your environment that's now included on every plan.
Here's what's shipping:
As soon as an incident is declared, an investigation does what an experienced engineer would: checks past incidents, commit history, telemetry, and logs, and whether upstream providers like AWS, GitHub, or Stripe were having an outage. See what you can connect.
The difference is it does all of it in parallel, from the second the alert fires, so there's already a hypothesis, the evidence behind it, and a recommended next step waiting in the channel by the time you open your laptop. See the incident channel experience.
You can also run an investigation on demand (with /inc investigate or by asking the agent), or set them to run on a condition or from a workflow. See triggering investigations.

Nothing is a black box. Every finding links straight to its source, whether a message, a pull request, or a spike in a metric, so you can see not just what it thinks but why. As new evidence arrives, it revisits its own hypotheses, strengthening or weakening them in the thread, and leaves the trail there for you to follow or challenge. See how investigations work.

An investigation keeps running for the life of the incident, taking in new information and surfacing what matters. Tag @incident to ask it questions ("have we seen this before?", "what changed recently?") or to steer it. With the macOS app you can pull the whole investigation into a coding agent like Claude Code, Cursor, or Codex in one click over MCP, work the problem with the same context it has, and share findings back to the channel.

Once an investigation reaches a conclusion, you don't have to take it from there by hand. Delegate the code changes to an agent (our built-in agent, Cursor, GitLab Duo, or a custom agent of your own), or pick the whole investigation up in your MCP and work it locally, with the same context it has. See making code changes and delegating agents.

The Investigations homepage tracks accuracy, engagement, and autonomy over time (how often it's right, whether responders act on it, and how much of each incident it diagnosed on its own), alongside the feedback responders leave on its messages. And you can open any past investigation and explore it in the timeline, from the first hypothesis through to the conclusion, to see exactly how it and your team got there.

Investigations is powered by Nexus, a living model of your production environment, built from your incidents, your systems, and your team. It's like having a teammate who's been in every incident you've ever had, knows every service you run, and can recall all of it instantly. Nexus gives every engineer that context, and it gets richer with every incident you resolve.
It's not a knowledge base that stores information; it reasons across it, connecting your catalog, telemetry, deploys, code, and past incidents into one picture and drawing conclusions in real time. That's what lets an investigation start from a hypothesis instead of a blank page: Nexus thinks, and the agent acts on what it knows.
A few things worth knowing:

We've included so much more in Investigations, too:
Nexus is included on every plan and rolling out today. Investigations is a new product, available to purchase now for Pro and Enterprise customers. Get a demo to see how it performs on your own incidents, and read more in our blog post.
Ready for modern incident management? Book a call with one of our experts today.
