> ## Documentation Index
> Fetch the complete documentation index at: https://docs.resolve.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Auto Investigations

<Info>
  **Guided Tour · Part 4 of 5**
  [Resolve Overview](/resolve-overview) → [Connect an Integration](/connect-an-integration) → [Team Knowledge](/D5xH-team-knowledge) → Auto Investigations → [Tuning Accuracy](/tuning-accuracy)
</Info>

Auto-investigations let Resolve start working the moment an alert fires — scoping impact, gathering evidence, and posting findings before your on-call engineer even opens the alert. This part walks through setting them up.

## Find your alerts

Open **Investigations** from the sidebar and switch to the **Alerts** tab. You'll typically see far more alerts than investigations — for example, 188 alerts in the last 24 hours versus 39 investigations. Some alerts are already investigated in **triage** mode.

You can segment alerts **by team** and add **filters** to focus on a specific set of alerts. The goal: define a filter for the alerts you care about, then have Resolve auto-investigate them as they arrive.

## Create an alert filter

1. Go to the relevant **team** (for example, the *product* team) and open its **Alerts** configuration. You'll see any filters already defined.
2. Click the **+** to create a new filter. You'll see the same alert view.
3. Add a condition — for example, **severity is critical**. The view updates to show matching alerts (say, 41 in the last 24 hours).
4. **Save** the filter.

Filters live in your team's knowledge configuration alongside runbooks — see [Teams & Knowledge](/team-knowledge) and the [Knowledge Setup Guide](/knowledge-setup-guide).

## Turn on auto-investigation and pick a mode

Open the saved filter and enable **auto-investigate**. Resolve offers three modes, each matching a different amount of effort to the alert:

* **Triage** — scopes impact, follows your [runbooks](/D5xH-team-knowledge), and stops when done. You decide whether to go deeper.
* **Adaptive** — Resolve decides how deep to go, adjusting based on initial findings.
* **Investigation** — always performs a thorough, multi-agent deep investigation to find the root cause.

You set the mode per alert filter, so different alerts can get different levels of scrutiny. For a full explanation of each mode and when to use it, see [Alert Investigations](/alert-investigation-modes). Auto-investigations draw on per-mode budgets and rate limits — see [Limits](/limits).

<Info>
  Better runbooks and dashboard guidance make auto-investigations dramatically more useful. If you haven't yet, work through [Part 3 — Team Knowledge](/D5xH-team-knowledge) first.
</Info>

## Respond automatically in Slack or MS Teams

To have Resolve reply directly in chat, connect the [App for Slack](/app-for-slack) or [App for MS Teams](/app-for-ms-teams-beta), then:

1. Open **Slack channels** and add the channel your alerts land in.
2. Set the **channel type** to **Alert**.

Now any alert that arrives in that channel — if it matches a filter with auto-investigation enabled — gets an automatic reply with Resolve's investigation. See [Workplace Collaboration Tools](/workplace-collaboration-tools-for-team-knowledge) for how channel types work, and [Auto-Investigations in the Slack app](/app-for-slack) for details.

For collaborative, human-in-the-loop incident response in these same channels, see [Incident Investigations](/incident-channels).

***

## What's next

Once auto-investigations are running, the last step is making them consistently accurate — a short, iterative loop of feedback and knowledge updates.

**Next:** [Part 5 — Tuning Accuracy](/tuning-accuracy)
**Previous:** [Part 3 — Team Knowledge](/D5xH-team-knowledge)
