Incident response

Put an agent in the incident channel

Start an agent from Slack when something breaks. It reads logs and recent changes with short-lived, read-only keys, runs next to your systems on your own servers, and brings what it finds to whoever is on call.

Read-only by default

The vault hands the agent short-lived, read-only keys for logs and metrics, never the real credentials.

Next to your systems

Run it on a self-hosted runner inside your own network.

Whoever’s on call

Its questions and findings go to the channel, and the first responder available answers.

An agent set up for this
agent/oncall
Investigates incidents
Claude Opus
Owner
Omar Haddad
Platform
Repositories
infrabilling-service
Network
logs.internalmetrics.internalgithub.comEverything else is blocked.
Secrets, from the vault
Logs read-only
A short-lived key for logs.internal, expires in 15:00
Questions go to
#incidents
Recent activity, as agent/oncall
  1. 02:14query logs: 5xx on /refunds, last 30 min
  2. 02:16git log --since=6h billing-service
  3. 02:17kubectl rollout restart deploy/billingblocked

Give your agents badges, not keys

Kosem is in early access with a small group of engineering teams. Tell us about yours.