Skip to content

Investigation with context and confidence

Investigation with context and confidence

Why would you need Bluebox to run an investigation?

In theory, your application is always working perfectly in the production environment. While in practice, it is not.

One night at 2AM, your application ran into issues, and you got paged for an overnight incident troubleshooting call. Despite its mighty power to create source code, your coding agent cannot help because it lacks insight into your product environment. That’s the moment you turn to Bluebox AI for help. That’s the moment you need “investigation” feature. 

What is an investigation in Bluebox?

More than a quick chat with AI, an investigation is how Bluebox goes deep on a problem to investigate a problem end to end.

Below is what’s happening under the hood when you trigger an investigation in Bluebox:

  • Situational Overview — With insight into your logs, spans, metrics and topology, Bluebox will understand your ask, then scan your environment for intelligence: what's broken, who's affected, the incident window, and judge whether there's enough data to proceed.
  • Hypothesis Formation — Based on the symptoms, Bluebox will propose specific, testable explanations for why the symptom occurred.
  • Investigation — Accepting no guesswork, Bluebox will test each hypothesis against evidence and mark it “confirmed”, “refuted”, or “inconclusive”.
  • Mitigation — To mitigate, Bluebox will recommend a concrete next step, classified as a code fix, a manual intervention, or as inconclusive, each with explicit risks.
  • Incident Issue — Depending on the situation, Bluebox will decide whether to open a tracking issue in the connected repository (e.g: GitHub), based on the previous outcome.
  • Final Report — This is the outcome of your investigation, a markdown summary you will read and share.

Let’s take a look at the report generated from one recent investigation as an example. You can see it highlights of “system status”, “root cause” and “customer impact” in its header and allows to you expand / dive into specific sections of investigate ("Executive summary", "Recommended actions", "Impact & blast radius", "Context & signals", "Root cause & hypotheses", "Evidence trail" and more).

TL;DR: Once you trigger an investigation, you will have Bluebox as your AI agent to investigate any issues and summarize the outcome in a nicely formatted report and GitHub issues.

How to trigger an investigation in Bluebox?

Sounds nice, but how can I use this feature?

Generally, an investigation can be triggered in manual way or automatic way.

Manual investigation is triggered by your explicit ask either in a new chat: choose "investigate", click from default common questions or raise your own questions like below:

Trigger from Chat

Or you can do it in the “investigations” UI, a page with all the investigation listed by status. Just click “New Investigation” button on the top right corner, Then fill the forms like below to trigger an investigation, where you can specify the title and visibility of your investigation:

Trigger from Chat

Or you can trigger it from a problems detected in the "Findings" page:

Trigger from Chat

Automatic investigation will be triggered automatically by a detected problem, which can be enabled/disabled in "Setup" page. Bluebox continuously watches your connected environment. The moment it spots an issue, Bluebox opens a full investigation on its own. No prompt needed.

That means the exact same rigor described above — situational overview, hypothesis formation, evidence testing, mitigation, report — runs automatically as soon as something breaks. By the time you'd think to ask, the investigation may already be done and waiting for you.

Worrying auto investigation eats up your AI budget? You control how much runs on autopilot. Every workspace has a daily AI usage quota, and a setting in "Setup" page lets you decide what share goes to automatic investigation — Bluebox never quietly spends your whole allowance without your say. You can also change the GitHub issue policy here:

Trigger from Chat

When to use investigation feature in Bluebox?

Remember that 2AM incident we mentioned at the beginning? Below is the best practice to change your life with Bluebox investigation.

  • At that very moment of incident, under pressure to solve issues? Check the investigation on the problems to guide you.
  • In the post-mortem meeting, need a post-incident root cause analysis report? Share the investigation result within your team.
  • Plan for next sprint, want to refactor this code but no clue on how? Tigger a proactive investigation to create a plan.
  • A new release is deployed, question if this update really prevents issues? Fire another investigation to evaluate the change.

Summary

Combining the "eyes" of observability and the "hands" of vibe coding together, Investigation in Bluebox helps you investigate any issues with context and confidence, even before you notice them!

 Now is the time to trigger an investigation, watch what happens. You will have the confidence to add it into your workflow to get ahead of the chaos and get rid of the risks.

Try Bluebox free →