What problem does it solve?
Evidence gathering that correlates signals from code, infrastructure, and organizational sources for an incident. Use when an alert, incident, or symptom needs cross-system evidence collection — building a correlation timeline, evaluating hypotheses against evidence, and presenting findings in plain language. Presents the evidence report to the user. Does not plan the investigation or implement fixes.
Core Features & Use Cases
- Cross-system evidence gathering from code, infrastructure, and organizational sources.
- Build a correlation timeline including last known good, changes, and first symptom.
- Synthesize findings into plain-language conclusions with sources.
- Generate a structured evidence report ready for review and sharing using references/evidence-template.md.
Quick Start
Initiate evidence gathering by aggregating code, infrastructure, and organizational signals to produce a consolidated incident report.