Alert at 01:19.
Verified cause at 01:27
A team of Niro agents investigates in parallel on the code graph - and hands you the high-confidence causes, with the evidence chain behind each one. Not a replacement for your on-call. The layer under it.
A surface you work on,
not read
Interrogate any finding. Every answer cites the edge or the commit it stands on - and says so when it cannot.
Parallel hypotheses,
none of them lost
Anyone can open a thread against the same graph. A refuted thread closes with its evidence attached; a confirmed one merges into the main investigation.
Verified, with
the chain attached
A cause you cannot check is a guess with confidence. Every link in the chain is an edge in the graph or a line in the deploy log.
| On-call, reading files | The agent team, on the graph | |
|---|---|---|
| Where you start | grep for the error string | the alerting service |
| Hypotheses | one at a time, in your head | in parallel, each a thread |
| Config as evidence | not read | read as nodes |
| A ruled-out theory | lost in the channel scrollback | a closed thread, evidence attached |
| When you stop | when it looks plausible | when the chain is complete |
What the agent can
and cannot do
Can I use the incident agent today?
It is in private beta, on the same terms as RCA: an add-on for Team, as packs or a subscription, and included org-wide on Enterprise. It is not on Free or Solo.
Do the agents touch production?
No. They work on the graph and config read as nodes - never logs or live systems. Findings are Causal AI signals - structure resolved on the graph, then confirmed against the deploy timeline. Niro writes nothing to your repositories and ships nothing to production - what you do with a cause is entirely yours.
How is Niro’s team of agents different from one agent in a loop?
Multiple hypotheses run in parallel instead of in sequence, and the Verifier argues with the findings before you see them - the same self-check discipline the code reviewer uses. A refuted thread closes with its evidence attached rather than disappearing.
What if the cause is not in the code at all?
Then no cause is declared. You get the candidates with why each is a candidate, the threads stay open, and the trail records what was ruled out - which is itself worth having at 2am.
Run it on
your next incident
The one that would have taken an afternoon. Index the repos it touches and let the team take the first eight minutes.