Incident response
Put an agent in the incident channel
Start an agent from Slack when something breaks. It reads logs and recent changes with short-lived, read-only keys, runs next to your systems on your own servers, and brings what it finds to whoever is on call.
Read-only by default
The vault hands the agent short-lived, read-only keys for logs and metrics, never the real credentials.
Next to your systems
Run it on a self-hosted runner inside your own network.
Whoever’s on call
Its questions and findings go to the channel, and the first responder available answers.
An agent set up for this
agent/oncall
Investigates incidents
Claude OpusOwner
Omar Haddad
Platform
- Repositories
- infrabilling-service
- Network
- logs.internalmetrics.internalgithub.comEverything else is blocked.
- Secrets, from the vault
- Logs read-onlyA short-lived key for logs.internal, expires in 15:00
- Questions go to
- #incidents
Recent activity, as agent/oncall
- 02:14query logs: 5xx on /refunds, last 30 min
- 02:16git log --since=6h billing-service
- 02:17kubectl rollout restart deploy/billingblocked
Give your agents badges, not keys
Kosem is in early access with a small group of engineering teams. Tell us about yours.