Incidents
Find the change that broke it.
What it affected, who owns it, and a link on every claim to the deploy, log line or trace behind it
The finding
Start from the answer, not a blank page.
The change, its blast radius and its owner, each one linking to the deploy, log line or trace it came from
Theories
You can see what has been ruled out and why.
Supporting and contradicting evidence stay listed against each theory, so nobody re-argues one that is already closed
Actions
The fix waits for a person to approve it.
Reads run on their own, every write is held, and each one is signed into the tools you already audit
Memory
Nobody has to write the runbook afterwards.
A summary, a service doc and a runbook drafted when the investigation closes, each one approved by a person
Frequently asked questions.
How does an investigation start?
NOFire connects to Grafana, PagerDuty, Slack, and webhooks. When an alert fires, it starts investigating. You can also start one yourself by asking.
Does this replace on-call?
No. Engineers stay on the loop and make the call. You start from the investigation, not from a blank screen.
What if it is wrong?
You review every finding. Theories it rejected stay listed, with the signal that argued against them. What you correct can be written back once a person approves it.
Can we keep Claude?
Yes. Claude and Cursor can read the same investigation. They ask against this record. They do not replace it.
Does it change production?
No. Investigations do not change production. You decide what happens next.
How is this different from an AI investigator?
Most investigators still ask the person who knows. This one writes the change that caused it, with evidence. Every claim is a link. Rejected theories stay listed. 89% top-1 on RCAEval, 735 scenarios, 12 baselines, April 2026.
Stop rebuilding the incident from Slack.
Give on-call the change that caused it, with the proof.