Skip to main content
Guided Tour · Part 4 of 5 Resolve OverviewConnect an IntegrationTeam Knowledge → Auto Investigations → Tuning Accuracy
Auto-investigations let Resolve start working the moment an alert fires — scoping impact, gathering evidence, and posting findings before your on-call engineer even opens the alert. This part walks through setting them up.

Find your alerts

Open Investigations from the sidebar and switch to the Alerts tab. You’ll typically see far more alerts than investigations — for example, 188 alerts in the last 24 hours versus 39 investigations. Some alerts are already investigated in triage mode. You can segment alerts by team and add filters to focus on a specific set of alerts. The goal: define a filter for the alerts you care about, then have Resolve auto-investigate them as they arrive.

Create an alert filter

  1. Go to the relevant team (for example, the product team) and open its Alerts configuration. You’ll see any filters already defined.
  2. Click the + to create a new filter. You’ll see the same alert view.
  3. Add a condition — for example, severity is critical. The view updates to show matching alerts (say, 41 in the last 24 hours).
  4. Save the filter.
Filters live in your team’s knowledge configuration alongside runbooks — see Teams & Knowledge and the Knowledge Setup Guide.

Turn on auto-investigation and pick a mode

Open the saved filter and enable auto-investigate. Resolve offers three modes, each matching a different amount of effort to the alert:
  • Triage — scopes impact, follows your runbooks, and stops when done. You decide whether to go deeper.
  • Adaptive — Resolve decides how deep to go, adjusting based on initial findings.
  • Investigation — always performs a thorough, multi-agent deep investigation to find the root cause.
You set the mode per alert filter, so different alerts can get different levels of scrutiny. For a full explanation of each mode and when to use it, see Alert Investigations. Auto-investigations draw on per-mode budgets and rate limits — see Limits.
Better runbooks and dashboard guidance make auto-investigations dramatically more useful. If you haven’t yet, work through Part 3 — Team Knowledge first.

Respond automatically in Slack or MS Teams

To have Resolve reply directly in chat, connect the App for Slack or App for MS Teams, then:
  1. Open Slack channels and add the channel your alerts land in.
  2. Set the channel type to Alert.
Now any alert that arrives in that channel — if it matches a filter with auto-investigation enabled — gets an automatic reply with Resolve’s investigation. See Workplace Collaboration Tools for how channel types work, and Auto-Investigations in the Slack app for details. For collaborative, human-in-the-loop incident response in these same channels, see Incident Investigations.

What’s next

Once auto-investigations are running, the last step is making them consistently accurate — a short, iterative loop of feedback and knowledge updates. Next: Part 5 — Tuning Accuracy Previous: Part 3 — Team Knowledge