Skip to main content
Root Cause Analysis (RCA) is the Analyze stage of the Deep Response Engine. Anna gathers context, starts the read-only specialist work that the incident needs, tests competing explanations, and returns a structured verdict. RCA can start automatically for an eligible Pulse incident when DRE auto-investigates is on. A manually logged Incident waits until you click Investigate.

How an investigation runs

RCA has three phases: The specialist set is dynamic. Anna selects the domains required by the evidence instead of running a fixed agent roster for every Incident. A typical investigation uses two to four subagents, with a maximum of eight.
RCA reads connected systems during investigation. A proposed action follows the runbook effect: Allow, Require Approval, or Deny.

Read the result

The investigation view keeps the conclusion and its proof together: Confidence is supporting context, not a guarantee. The interface groups the agent-recorded score as High at 0.8 or above, Medium from 0.5 to below 0.8, and Low below 0.5. Review the linked evidence before you approve a change.

Investigation outcomes

Anna can complete an RCA run with one of these terminal outcomes: On hold is not terminal. It pauses the investigation when Anna needs information, access, or a decision. The Incident enters Needs your decision until a person supplies what RCA needs to continue. Acknowledged is also not terminal: a responder owns the Incident but analysis has not started. The Investigation queue groups work by what needs attention: AI is handling, Needs your decision, Not started, Resolved, and Dismissed. Incidents with a Not found result do not remain in the visible queue.

Start or rerun RCA

1

Open an Incident

Select an Incident from the Investigation queue. Review its source, severity, signals, and existing evidence.
2

Start the investigation

Click Investigate when the Incident is waiting for manual analysis. Pulse-created Incidents can start automatically when On Duty is enabled and the routing rules qualify them.
3

Review the verdict

Read the root cause, causal graph, hypotheses, evidence, and remediation before you approve an action or resolve the Incident.
Rerun RCA when new evidence changes the case. The new run does not erase the earlier investigation.

Example investigation

These examples show how an investigation can move from one infrastructure symptom to a correlated root cause.
EC2 termination pattern analysis with Auto Scaling events and a timeline

An infrastructure investigation begins with the termination pattern.

Network failure correlation with CreateNetworkInterface errors

A second pass tests whether the symptoms share a cause.

Structured RCA report with evidence and remediation

Anna combines the supported findings into one reviewable verdict.

Log an Incident

Create an Incident from a human report, then start RCA when you are ready.

Control automatic RCA

Set On Duty behavior and re-investigation sensitivity.

Use runbooks

Review the actions that DRE can suggest, approve, or block.

Reuse lessons

See how agent-written lessons can inform later investigations.