Incident Investigation, Started Before On-Call Joins
When an alert fires, an agent gathers logs and metrics from your connected tools, plus recent changes, into a first analysis, and separates what it confirmed from what it suspects.
The First Minutes Go to Gathering Context
An alert wakes someone up, and the first stretch of the incident goes to opening dashboards, scrolling logs, and checking what shipped recently. That context-gathering is the same every time, and it happens exactly when the on-call engineer has the least time and attention to spare.
An Agent Brings the Evidence, a Person Decides
An automation starts an agent from the alert event. It inspects recent changes and the relevant code and configuration, compares what it finds with your runbooks, and drafts an investigation summary with the safest next checks. You set which systems it may inspect and which actions need human approval; the decision to roll back or mitigate stays with the on-call engineer.
checkout-api error rate
8.4%Error spike started 14:02, right after deploy #812. Rollback plan drafted for on-call.
What Teams Report
9.4x
growth in weekly agent requests, February to August 2026
Uber runs managed agents that triage on-call alerts, and measures them by cost per alert, mean time to recovery, and alerts triaged.
Uber's software factory postCommon Questions
What starts an investigation?
An alert event from a connected system, such as a PostHog log alert or an event your monitoring tool sends to Felan's webhook endpoint. A person can also start one by hand.
Can the agent change production?
Only if you give it that access. You decide which environments it may inspect or change, which commands are read-only, and which actions need human approval.
What does the on-call engineer get?
A first analysis that separates confirmed evidence from hypotheses, with the safest next checks and a draft update for the incident channel.
Which models can it use?
Any major provider, plus local and private models. Bring your own keys or subscription, and there's no markup on tokens.
Can it run on our own infrastructure?
Yes. Use Felan's managed cloud, or run Felan on your own infrastructure with the Enterprise plan.
Related: Site reliability engineering docs, Isolated by default, Always on.
Keep Your Attention for the Hard Problems
Start with one repo and one recurring task.