# Investigations now available, powered by Nexus

*August 5, 2026*

Today we're making [**Investigations**](https://incident.io/investigations?utm_source=website&utm_medium=changelog&utm_campaign=FY26-Q3-905-WEB-LP-investigations-DemoRequest&utm_content=investigations-changelog&utm_term=) generally available. The moment an incident is declared, it reasons across your telemetry, code, past incidents, and dependencies, and within minutes posts a root cause hypothesis and its supporting evidence into the incident channel, before anyone's started digging. It's powered by [**Nexus**](https://incident.io/nexus?utm_source=website&utm_medium=changelog&utm_campaign=FY26-Q3-905-WEB-LP-investigations-DemoRequest&utm_content=nexus-changelog&utm_term=																		), a living model of your environment that's now included on every plan.

Here's what's shipping:

* **An investigation kicks off automatically** the moment an incident is declared, and surfaces wherever you work: Slack, MS Teams, the dashboard, the mobile app, the macOS app, and the remote MCP server.
* **Every finding links back to its evidence** (a message, a PR, or a metric), so you can check the reasoning, not just the answer.
* **It works alongside you** for the whole incident: ask it questions, steer it, or pull it into your coding agent over MCP.
* **You can delegate the fix**: hand the code changes to an agent; our built-in agent, Cursor, GitLab Duo, or a custom agent.
* **A homepage** that tracks accuracy, engagement, autonomy, and the feedback responders leave over time, so you can feel the impact of Investigations.
* **Nexus**, the model underneath it all, is now available to every customer.

### An investigation kicks off the moment an incident is declared

As soon as an incident is declared, an investigation does what an experienced engineer would: checks past incidents, commit history, telemetry, and logs, and whether upstream providers like AWS, GitHub, or Stripe were having an outage. See [what you can connect](https://docs.incident.io/investigations/connect/overview).

The difference is it does all of it in parallel, from the second the alert fires, so there's already a hypothesis, the evidence behind it, and a recommended next step waiting in the channel by the time you open your laptop. See [the incident channel experience](https://docs.incident.io/investigations/incident-channel-experience).

You can also run an investigation on demand (with `/inc investigate` or by asking the agent), or set them to run on a condition or from a workflow. See [triggering investigations](https://docs.incident.io/investigations/triggering).

![](https://cdn.sanity.io/images/oqy5aexb/production/d0fa4f15f54d47cbb28e33dba004152eba6cb52c-1500x901.png)

### Every finding links back to its evidence

Nothing is a black box. Every finding links straight to its source, whether a message, a pull request, or a spike in a metric, so you can see not just _what_ it thinks but _why_. As new evidence arrives, it revisits its own hypotheses, strengthening or weakening them in the thread, and leaves the trail there for you to follow or challenge. [See how investigations work](https://docs.incident.io/investigations/how-investigations-work).

![](https://cdn.sanity.io/images/oqy5aexb/production/8ebba4359294dcdb435818a8e7720bca0dac0664-1694x861.png)

### An investigation works alongside you for the whole incident

An investigation keeps running for the life of the incident, taking in new information and surfacing what matters. Tag `@incident` to ask it questions ("have we seen this before?", "what changed recently?") or to steer it. With the [macOS app](https://docs.incident.io/ai/desktop-app) you can pull the whole investigation into a coding agent like Claude Code, Cursor, or Codex in one click over [MCP](https://docs.incident.io/ai/remote-mcp), work the problem with the same context it has, and share findings back to the channel.

![](https://cdn.sanity.io/images/oqy5aexb/production/cad67024e04378b273359cda40079326ec4fde1d-2096x1281.png)

### Delegate the fix

Once an investigation reaches a conclusion, you don't have to take it from there by hand. Delegate the code changes to an agent (our built-in agent, Cursor, GitLab Duo, or a custom agent of your own), or pick the whole investigation up in your MCP and work it locally, with the same context it has. See [making code changes](https://docs.incident.io/investigations/connect/code/making-code-changes) and [delegating agents](https://docs.incident.io/investigations/connect/code/delegating-agents).

![](https://cdn.sanity.io/images/oqy5aexb/production/20cbf2c4072588a9d7f616b72bcbc4650ba28042-1700x752.png)

### Dig into any investigation, and track performance overall

The Investigations homepage tracks [accuracy](https://docs.incident.io/investigations/measuring-accuracy), [engagement](https://docs.incident.io/investigations/measuring-engagement), and [autonomy](https://docs.incident.io/investigations/measuring-diagnosis) over time (how often it's right, whether responders act on it, and how much of each incident it diagnosed on its own), alongside the feedback responders leave on its messages. And you can open any past investigation and explore it in the timeline, from the first hypothesis through to the conclusion, to see exactly how it and your team got there.

![](https://cdn.sanity.io/images/oqy5aexb/production/dd54c8c7ebbe5d3be84d8d64580f71c0863cde93-3000x1912.png)

### Meet Nexus

Investigations is powered by [**Nexus**](https://incident.io/nexus?utm_source=website&utm_medium=changelog&utm_campaign=FY26-Q3-905-WEB-LP-investigations-DemoRequest&utm_content=nexus-changelog&utm_term=																		), a living model of your production environment, built from your incidents, your systems, and your team. It's like having a teammate who's been in every incident you've ever had, knows every service you run, and can recall all of it instantly. Nexus gives every engineer that context, and it gets richer with every incident you resolve.

It's not a knowledge base that stores information; it reasons across it, connecting your catalog, telemetry, deploys, code, and past incidents into one picture and drawing conclusions in real time. That's what lets an investigation start from a hypothesis instead of a blank page: Nexus thinks, and the agent acts on what it knows.

A few things worth knowing:

* **Included on every plan.** Nexus isn't a separate purchase; it's the foundation underneath the platform, from day one. View Nexus in the dashboard [here](https://app.incident.io/~/nexus).
* **Every product makes it richer.** The more of incident.io you use, the more Nexus has to learn from.
* **Unique to your organization.** Every customer gets their own instance. Your data never trains shared models.
* **SOC 2 compliant, zero data retention.** We have agreements with every model provider, so your data is never stored or used for their training.

![](https://cdn.sanity.io/images/oqy5aexb/production/728d7f56bb11fdef780131016003c89af39fb234-1500x824.png)

### And a whole lot more

We've included so much more in Investigations, too:

* **Wait for an investigation:** hold an escalation from paging until the investigation has a first hypothesis, so whoever you wake up arrives to context instead of a cold start. See [wait for investigation](https://docs.incident.io/on-call/wait-for-investigation).
* **Automatic duplicate merging:** it spots when two open incidents are the same problem and merges them, or drops a one-click merge suggestion into the channel with its reasoning.
* **Catch-me-up:** join a live incident and get a summary that folds in the investigation's findings alongside what's happened so far.
* **See who started an investigation:** every investigation shows how it began (manually, by a workflow, or automatically) and who triggered it, across all surfaces.
* **Alternative explanations:** when there's another equally likely theory, it surfaces it in the thread with an **Add context** button so you can steer.
* **Self-diagnosing telemetry connections:** when a data source won't connect, a structured checklist shows exactly what's failing and how to fix it.
* **Configurable data retention:** set a retention window per telemetry source, so investigations never query beyond where your data actually exists.

Nexus is included on every plan and rolling out today. Investigations is a new product, available to purchase now for Pro and Enterprise customers. [**Get a demo**](https://incident.io/demo?utm_source=website&utm_medium=changelog&utm_campaign=FY26-Q3-905-WEB-LP-investigations-DemoRequest&utm_content=investigations-demo-changelog&utm_term=) to see how it performs on your own incidents, and read more in our **[blog post](https://incident.io/blog/introducing-investigations-powered-by-nexus?utm_source=website&utm_medium=changelog&utm_campaign=FY26-Q3-905-WEB-LP-investigations-DemoRequest&utm_content=blog-investigations-changelog&utm_term=).**