CauseSignalAgentic engineering investigation

Evidence-backed root cause and engineering investigation

An AI investigation system that finds the evidence-supported cause.

From an observed symptom, CauseSignal’s governed specialist playbooks reconstruct what happened, retrieve the evidence that matters, and challenge competing explanations — then report the cause the record supports, or state plainly when the evidence is not enough.

Your team retains authority over remediation and production change. The CauseSignal runtime is read-only — it recommends the next change or routes work to the accountable team, and never acts on production itself.

CASE / CS-2026-184READ ONLY
Observed symptom

Payment authorization failures after release 7.14

First observed 13:42 UTC · production / eu-west · change window +18 min

EVIDENCE ADMITTED01 Timeline & release delta 1202 Code & config paths 0803 Tests & validations 1904 Runtime / DB signals 3105 Prior patterns 04
CAUSAL CANDIDATESevidence support score / not probabilities
0.81
Configuration contract mismatch

Release delta and runtime evidence agree; integration test coverage is incomplete.

LEADING
0.46
Credential rotation delay

Timing is plausible; observed failure signature conflicts with two prior events.

CONFLICT
0.18
Upstream service degradation

No supporting latency or availability evidence in admitted sources.

WEAK
11 claims cited2 conflicts retained1 material unknown1 external action flagged requires accountable owner
Incident reconstructionChange intelligenceHypothesis challengeRegression analysisRemediation guidance
01 / UNDERSTAND

Establish what changed and when.

Build a common, evidence-backed account of the event before teams commit to an explanation.

02 / CHALLENGE

Test the possible causes.

Make competing explanations, contradictions, confidence, and material unknowns visible for review.

03 / DIRECT

Take the right next action.

Recommend a governed change or hand work to the platform, provider, or operating team that owns it.

Investigation intelligence

Move from scattered signals to a defensible engineering explanation.

CauseSignal combines timeline reconstruction, change intelligence, safe evidence retrieval, hypothesis challenge, and prior-case knowledge while keeping provenance and uncertainty visible.

01 / RECONSTRUCT

Build a shared account of the event.

01

Reconstruct the canonical timeline

Orders releases, code changes, tests, incidents, operational events, and evidence windows into a traceable chronology instead of a chat transcript.

SHARED INCIDENT RECORD
02

Connect nearby changes

Finds releases, commits, configuration shifts, database changes, dependency updates, and related product changes that could explain the observed behavior.

CHANGE INTELLIGENCE
03

Retrieve evidence safely

Searches code, tests, history, prior incidents, indexed knowledge, and admitted runtime context while preserving scope, identity, provenance, and stale-evidence boundaries.

GROUNDED RETRIEVAL

02 / REASON

Challenge the explanation before accepting it.

04

Challenge competing hypotheses

Develops multiple causal candidates, looks for both supporting and contradictory evidence, and keeps unresolved alternatives visible until the record justifies narrowing.

LESS CONFIRMATION BIAS
05

Plan the investigation

Identifies the next highest-value evidence to inspect, what is still missing, and which questions can actually change the confidence of the investigation.

FOCUSED NEXT ACTIONS
06

Use prior RCA patterns

Surfaces similar incidents and recurring causal patterns without treating a historical match as proof that the same cause applies now.

ORGANIZATIONAL MEMORY

03 / DECIDE

Make the evidence useful for the next decision.

07

Explain the finding

Separates observation, inference, finding, contradiction, recommendation, and unknown so reviewers can see exactly what the evidence does and does not support.

REVIEWABLE DECISIONS
08

Recommend the right remediation path

Distinguishes repository changes such as code, database, infrastructure-as-code, and configuration from actions that require an external owner or operational authority.

HONEST HANDOFF

Investigation method

A governed path from symptom to defensible cause.

CauseSignal’s investigation roles do not begin with a preferred answer. They frame the event, admit evidence deliberately, reconstruct the sequence, challenge causal candidates, and state only what the available record supports.

  1. 01 / FRAME

    Define the event

    Capture expected versus observed behavior, scope, time, environment, impact, and the question the investigation must answer.

  2. 02 / RECONSTRUCT

    Build the evidence timeline

    Connect source history, releases, tests, configuration, database and runtime evidence with exact identity and provenance.

  3. 03 / CHALLENGE

    Test causal candidates

    Rank hypotheses, seek disconfirming evidence, preserve contradictions, and stop safely when evidence is insufficient.

  4. 04 / DECIDE

    Report finding and next action

    Produce a cited finding, confidence boundary, alternatives, unknowns, and the governed remediation or external-action handoff.

Governed specialist playbooks

CauseSignal is built from governed specialist playbooks, each responsible for one part of an evidence-led investigation.

There is no autonomous agent swarm. CauseSignal maintains a governed registry of named specialist roles, keeps evidence gathering separate from causal judgement, and preserves human authority over remediation and production change.

Specialist playbooks, not one generalistIssue framing, retrieval planning, evidence gathering, causal analysis, independent critique, reporting, remediation, and safety each have their own bounded playbook.
Evidence does not certify itselfThe roles that gather evidence are not the role that decides what it proves, and the analyst cannot approve its own conclusion.
Humans retain consequential authorityCauseSignal investigates, explains, and recommends; people own the remediation and the production change.
01
FRAME

Define the event

Axiom, Lens, Scout

02
RECONSTRUCT

Gather the evidence

Trace, Intent, Recall, Mesh

03
CHALLENGE

Test and critique the explanation

Causa, Verity, Vigil

04
DECIDE

Report the cited finding

Scribe

REMEDIATION & SANDBOX VALIDATIONRemedy, Mender, Warden & Proving

Prepare a scope-bounded remediation proposal and candidate patch, and validate it in a policy-governed sandbox — never against production.

CROSS-CUTTING SAFETYSentinel

Reviews path safety, secret redaction, egress, command policy, and prompt-injection resistance across every role, at every stage.

OPERATIONSHarbor

Deploys CauseSignal itself into authorized environments. It takes no part in any investigation.

Meet the named specialist roles — 17

Stable role identities make responsibility, evidence, handoffs, and separation of duties visible.

FRAME

Axiom

Triage Orchestrator

Plans and bounds the investigation, validates every stage handoff, and escalates or stops when the evidence is insufficient. Read-only; it orchestrates, never concludes.

FRAME

Lens

Issue Parser

Normalizes the reported issue into expected-versus-observed framing and open questions, treating reported content as untrusted input rather than fact.

FRAME

Scout

Search Planner

Plans bounded retrieval: query strategy, evidence-gap priority, and retrieval cost control. Plans only - it issues no findings of its own.

RECONSTRUCT

Trace

Code Navigator

Read-only code navigation, symbol and reference search, test-to-code localization, and config inspection - approved roots only, pinned to an exact commit.

RECONSTRUCT

Intent

Requirement Analyst

Resolves the effective, approved requirement and detects drift or contradiction between what was intended and what was expected.

RECONSTRUCT

Recall

Historical Evidence Agent

Retrieves prior incidents and release-change context with provenance, and flags stale history. Reviewed memory only; similarity is context, not proof.

RECONSTRUCT

Mesh

Graph Context Agent

Bounded relationship, topology, and schema-lineage expansion with provenance preserved. Bounded hops and fan-out; never crosses scope.

CHALLENGE

Causa

Root Cause Analyst

Builds competing causal hypotheses, reviews counter-evidence, and abstains where evidence is insufficient. Creates no evidence and holds no action authority.

CHALLENGE

Verity

Evidence Critic

Independently reviews evidence admission, claim traceability, contradictions, and unsupported claims. Can only downgrade or reject - never upgrade.

DECIDE

Scribe

Report Writer

Renders the cited finding, confidence rationale, contradictions, and explicit non-actions - restricted to claims the evidence critic has approved.

REMEDIATION

Remedy

Remediation Proposal Agent

Generates remediation options within scope, plans a bounded fix, and binds each proposal to its evidence digest.

REMEDIATION

Mender

Candidate Patch Agent

Prepares a candidate patch under minimal-diff discipline, with protected paths enforced throughout.

SANDBOX VALIDATION

Warden

Sandbox Policy Evaluator

Evaluates sandbox admission policy, resource limits, and secret and egress exposure before anything is validated.

SANDBOX VALIDATION

Proving

Sandbox Validation Agent

Coordinates sandbox tests and reproducible build validation, binding every result to its digest.

CHALLENGE

Vigil

Remediation Safety Reviewer

Independently reviews remediation safety, residual risk, and separation of duties before a change is recommended.

CROSS-CUTTING

Sentinel

Safety Reviewer

Path safety, secret redaction, egress control, command policy, and prompt-injection resistance across every role. Denies or escalates; cannot override policy.

OPERATIONS

Harbor

CauseSignal Deployment Agent

Dual-provider deployment into explicitly authorized environments with immutable artifacts. Operates outside the investigation flow and never changes investigation logic.

Roster source of record: docs/agents/AGENT_ROSTER.yaml (PI-29R_49A / DEC-226). Role metadata describes contract capabilities and responsibility boundaries; it does not itself grant runtime authority, tool access, or installed packages.

Evidence domains

Cross-domain context without flattening provenance.

Every source keeps its origin, version, time, scope, and access conditions. CauseSignal can connect evidence across domains without silently turning retrieval results into facts.

DomainQuestions it can supportRequired context
RequirementsWhat behavior was intended?Version / owner / approval
RepositoryWhich code or config realizes it?Commit / branch / component
TestsWhat was exercised and observed?Run / environment / result
ReleaseWhat changed near the event?Artifact / promotion / time
RuntimeWhat happened in the running system?Service / tenant / window
DatabaseDid schema, query, data or migration state contribute?DB / migration / query / scope
InfrastructureDid deployment or platform state diverge?Environment / config / owner
Prior incidentsHas a similar pattern occurred before?Case / cause / applicability

Safety boundary

Analysis can recommend change without silently making it.

CauseSignal's product runtime is intentionally read-only. It can investigate, explain, and recommend. Where a remediation is representable in governed scope, it can identify the required code, database, infrastructure-as-code, or configuration change. Where the real fix belongs to an external operator, provider, network team, or platform owner, CauseSignal says so instead of fabricating a patch.

01 No autonomous customer-repository mutation 02 No unsupported causal certainty 03 No evidence without identity and provenance 04 No hidden contradiction removal 05 No cross-tenant or cross-scope evidence leakage 06 No fake code patch for an external operational action

Investigation & decision outputs

Evidence that engineering teams can review, challenge, and act on.

Outputs preserve the boundary between what was observed, what was inferred, what is recommended, and what still requires evidence or another authority.

RCA

Cited causal analysis

Ranked explanation with supporting evidence, contradictions, alternatives, confidence, and material unknowns.

TIME

Canonical timeline

A durable sequence of changes, releases, tests, and operational events relevant to the investigation.

MAP

Evidence & change map

Source lineage, affected components, and claim relationships that show why a conclusion is grounded.

PLAN

Investigation plan

The next evidence to collect, questions to resolve, and checks most likely to change the conclusion.

REM

Remediation guidance

Governed recommendation for code, database, IaC, configuration, or an explicit external-remediation handoff.

REV

Review packet

A durable investigation record for engineering, incident command, support, assurance, and follow-up work.

Emporia IT product portfolio

Connect investigation to delivery and product understanding.

CauseSignal is one part of an evidence-led product portfolio for complex software teams. Explore the products that help teams act on an investigation or establish a reliable product record.

Technical briefing

Evaluate CauseSignal against a real incident or defect investigation.

Discuss evidence admission, incident reconstruction, change intelligence, RCA workflows, remediation handoff, qualification, and enterprise controls.

support@emporiait.com