Skip to main content
Example showing two checkout errors assigned to investigation A and a worker error to investigation B

Related errors share an investigation; a later occurrence can resume it.

  1. A Cloud Logging sink forwards entries that match your selected sources and severity.
  2. Corvo stores each new entry and collects incoming alerts for a short window.
  3. The orchestrator compares the collected alerts with existing investigations. It groups alerts by likely cause and assigns every alert to a new or continuing investigation.
  4. Each investigation has an agent session that can resume when related alerts arrive later. The agent reads available logs, other selected Google Cloud data, repository code, and approved workspace memory.
  5. The investigation records its findings and may open a draft PR. Its result and links appear in Investigations and in the connected notification channel.
A single investigation may span several windows and many alerts. Its status describes the latest agent run. Review the evidence and any proposed fix before changing production.