Use case

AI incident response, with you in control

Escanor brings incidents from your connected monitoring and deployment providers into one workspace, helps you investigate them with the evidence attached, and lets an AI agent propose a repair that you approve before it ships.

How it works

  1. 01

    Alert

    From Sentry, PagerDuty, GitHub, Vercel or logs you send.

  2. 02

    Evidence

    Start time, environment, provider and recent deploys.

  3. 03

    Proposed repair

    Target, branch, commands and tests, laid out for review.

  4. 04

    You approve

    An owner or manager approves, denies or stops the change.

  5. 05

    Verify

    Deployment, health checks and the original failure.

  1. Step 1

    Collect the signals

    Incidents gathers supported provider findings and operational alerts. Monitoring combines connected-provider observations with logs you send to Escanor through the ingest endpoint.

    Monitoring and log ingestion
  2. Step 2

    Investigate with evidence

    Open an incident to see when it started, which environment it affects and which provider reported it. Compare it with recent deployments, and ask the assistant to summarize the evidence without changing anything.

    Incidents and investigation
  3. Step 3

    Review a proposed repair

    Auto-fix, repair missions and playbooks can propose a fix. Inspect the target, branch, commands, tests and approval state, and prefer a staging environment where possible.

    Repairs and playbooks
  4. Step 4

    Approve, then verify

    Approve one bounded change or a known-good rollback through your team’s process. Then verify the deployment, health checks and the original user-visible failure, and keep monitoring.

    Permissions and approvals

What the human approves

  • Every run records its steps. Anything that needs a decision appears under Needs you, where an owner or manager approves, denies or stops it.
  • You set the autonomy level, per-action overrides and budgets, including runs per day and automatic-approval limits.
  • Stop everything now pauses automation across the workspace.
  • Every finding links to its evidence, so you can check the source before you act.

See Automations and Autopilot for goals, triggers and budgets.

Where the signals come from

Connect the monitoring and deployment providers you already use, such as Sentry, PagerDuty, GitHub and Vercel, from the integrations catalog. You can also send your own logs as JSON, newline-delimited JSON, plain text or Loki push streams to the ingest endpoint with a dedicated ingest key. See Monitor production in one place.

A recovery checklist

  1. Establish the affected service and environment and keep an incident timeline.
  2. Check provider connection health if data is stale or incomplete.
  3. Compare logs and recent deploys; identify evidence for the suspected cause.
  4. Review a bounded repair or a known-good rollback with your team's approval process.
  5. Verify deployment, health and the original user-visible failure.
  6. Keep monitoring and record what you learned.