Skip to content

AUTONOMOUS INCIDENT DETECTION & DECISION ENGINE

Know when production actually needs you.

Interrupt humans only when it matters.

AIDDE continuously evaluates production evidence, causality, impact and uncertainty to distinguish meaningful incidents from operational noise—and decide what deserves attention.

SAME PLATFORM. DIFFERENT DECISION.

The goal isn't detecting more anomalies. It's making better decisions.

Checkout degradation

Impact
HIGH
Evidence
STRONG
Confidence
91%
Trajectory
WORSENING

INTERRUPT

CPU deviation

Impact
NONE
Evidence
WEAK
Confidence
47%
Trajectory
STABLE

OBSERVE

The goal isn't detecting more anomalies. It's making better decisions.

THE PROBLEM

Thresholds detect conditions. They don't understand incidents.

TRADITIONAL ALERTING

  • CPU > 80%→ ALERT
  • Latency > 500 ms→ ALERT
  • Errors > 5%→ ALERT
  • Queue depth ↑→ ALERT
  • Pod restarted→ ALERT
  • Payment failures→ ALERT

ON-CALL

Which one matters?

AIDDE

  • CPU
  • Latency
  • Errors
  • Failed traces
  • Deployment
  • Topology

Evidence

Situation

CHECKOUT REGRESSION

Root candidate
checkout-api v2.14.7
Impact
Checkout + Payment + Orders
Confidence
91%
Decision
INTERRUPT

THE MODEL

From production signals to attention decisions.

  1. 01

    SIGNALS

  2. 02

    EVIDENCE

  3. 03

    SITUATION

  4. 04

    ASSESSMENT

  5. 05

    DECISION

  6. 06

    EXPLANATION

  7. 07

    RESPONSE

Situation is the user concept. Causal Aggregation is the technical mechanism inside it.

01 — EVIDENCE

Signals become evidence before they become incidents.

02 — SITUATION

Many symptoms. One underlying situation.

03 — ASSESS

Does this situation actually matter?

04 — DECIDE

An incident becomes an interruption only after a decision.

Assessment establishes what is true. Policy shapes what should happen. The decision is the product of both.

SITUATIONASSESSMENT
POLICY
DECISION

Assessment

Root cause
checkout-api v2.14.7
Confidence
91%
Impact
HIGH
Trajectory
WORSENING

Policy

Environment
Production
Service
Tier 1
Customer impact
Customer-facing path
Required confidence
> 85%

Decision

INTERRUPT ON-CALL

Assessment and policy agree — human attention is justified.

  • OBSERVE

    Not enough evidence

  • ENRICH

    Need more evidence

  • SUPPRESS

    Downstream symptom

  • CREATE INCIDENT

    Meaningful situation

  • INTERRUPT

    Human needed now

AIDDE DECISION LAB

Change the situation. See how the decision changes.

Deterministic scenario matrix for teaching — not a live production AIDDE run.

SITUATION

Customer impact
Evidence agreement
Trajectory
Maintenance window
Signal relationship

AIDDE DECISION

INTERRUPT

Confidence 91%

WHY

  • Customer impact is high
  • Independent evidence agrees
  • Situation is worsening
  • No suppression policy applies

05 — EXPLAIN

Never interrupt someone without telling them why.

The explanation object is what the engineer receives: situation, impact, probable cause, confidence, supporting evidence, and why interruption was justified.

CHECKOUT DEGRADATION

14:32:04

CRITICAL

What happened

Checkout failures increased after checkout-api v2.14.7 was deployed.

Root cause candidate

checkout-api v2.14.7

Confidence 91%

Impact

  • Checkout
  • Payment
  • Orders

WHY AIDDE INTERRUPTED

  • Customer-facing degradation
  • Multiple evidence sources agree
  • Failure followed deployment
  • Trace evidence points to checkout-api
  • Propagation matches topology
  • Situation is worsening

RECOMMENDED NEXT STEP

Review checkout-api v2.14.7 deployment

Confidence

91%

Confidence is inspectable — never a naked percentage.

UNCERTAINTY CHANGES BEHAVIOUR

Missing evidence should change the next decision.

Confidence

67%

Strong

  • Metric evidence
  • Deployment correlation

Uncertain

  • Trace coverage incomplete
  • Payment-provider telemetry unavailable

Missing evidence limits causal confidence.

Next decision · ENRICH

  1. Missing trace evidence

  2. Confidence insufficient

  3. ENRICH

  4. Request traces

  5. Multi-DSL investigation

  6. Evidence returned

  7. Reassess

Explore Multi-DSL →

06 — EVOLVE

Incidents aren't snapshots.

AIDDE doesn't fire once. It continuously re-evaluates as evidence arrives—and decisions change with confidence.

  1. 14:30:00

    DEPLOYMENT

    checkout-api v2.14.7 deployed

  2. 14:31:23

    ANOMALY OBSERVED

    Latency deviation detected — continue observing

    38%OBSERVE
  3. 14:31:31

    TRACE EVIDENCE

    Failed traces accumulate — request richer evidence

    57%ENRICH
  4. 14:31:42

    SITUATION FORMED

    Correlated evidence describes one checkout situation

    74%INVESTIGATE
  5. 14:31:58

    IMPACT CONFIRMED

    Customer impact confirmed — incident created

    86%CREATE INCIDENT
  6. 14:32:04

    INTERRUPT

    Interrupt on-call — confidence and impact justify attention

    91%INTERRUPT
  7. 14:36:00

    RECOVERY DETECTED

    Recovery signals appear after rollback

    94%
  8. 14:38:00

    RESOLVED

    Incident resolved — outcome retained as memory

    94%RESOLVE

AIDDE doesn't fire. AIDDE continuously evaluates.

INCIDENT RESOLVED

  • Root causeConfirmed
  • Deployment rollbackSuccessful
  • Suppressed downstream signalsCorrect
  • Human feedbackDiagnosis useful

INCIDENT MEMORY

Outcome retained as future investigation context. Adaptive retraining is not claimed.

ONE INTELLIGENCE SYSTEM

AIDDE decides. The platform supplies understanding.

When confidence is insufficient, AIDDE requests investigation—it does not passively wait for telemetry.

AIDDE

Do I know enough?

  • INVESTIGATION

    What explains this?

    1. 01Confidence insufficient
    2. 02Request investigation
    3. 03Generate competing hypotheses
    4. 04Test against evidence
    5. 05Updated evidence
    6. 06AIDDE reassesses
    Explore Investigation →
  • TOPOLOGY

    What is related?

    1. 01Root vs downstream
    2. 02Blast radius
    3. 03Causal consistency
    4. 04Suppression with evidence retained
    Explore Topology →
  • MULTI-DSL

    What evidence do we need?

    1. 01Evidence request
    2. 02Investigation planner
    3. 03Metrics · Logs · Traces
    4. 04Unified evidence
    5. 05AIDDE reassessment
    Explore Multi-DSL →

Evidence returns

→ AIDDE reassesses

TECHNICAL ARCHITECTURE

Built as a decision system, not an alert pipeline.

Enough architecture to reward technical visitors — no algorithms, equations, or ML model diagrams.

Production signals

  • Metrics
  • Logs
  • Traces
  • Events
  • Changes
  • Topology
  1. Signal normalisation

  2. Evidence layer

  3. Topology

    Causal aggregation

  4. Assessment engine

  5. Policy

    Decision engine

  6. Context builder

  7. Response / routing

BUILT FOR TRUST

Explainable. Inspectable. Integrated.

  • EXPLAINABLE

    • Evidence provenance
    • Confidence factors
    • Uncertainty
    • Alternative hypotheses
  • INSPECTABLE

    • Decision state
    • Incident history
    • Policy applied
    • Evidence chain
  • INTEGRATED

    Planned
    • APIs
    • Events
    • Audit trail
    • Webhooks

    Not sold as product until shipped.

For SRE →