> ## Documentation Index
> Fetch the complete documentation index at: https://docs.corvoai.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Investigation pipeline

> How a Google Cloud log entry becomes a continuing investigation.

<Frame caption="Related errors share an investigation; a later occurrence can resume it.">
  <img src="https://mintcdn.com/corvo-ai/3EBWOPH1lekWrDtF/assets/diagrams/investigation-pipeline.svg?fit=max&auto=format&n=3EBWOPH1lekWrDtF&q=85&s=f5eef2658ba1772d020a16a3cca21858" alt="Example showing two checkout errors assigned to investigation A and a worker error to investigation B" width="1000" height="610" data-path="assets/diagrams/investigation-pipeline.svg" />
</Frame>

1. A Cloud Logging sink forwards entries that match your [selected sources and severity](/integrations/google-cloud).
2. Corvo stores each new entry and collects incoming alerts for a short window.
3. The orchestrator compares the collected alerts with existing investigations. It groups alerts by likely cause and assigns every alert to a new or continuing investigation.
4. Each investigation has an agent session that can resume when related alerts arrive later. The agent reads available logs, other selected Google Cloud data, repository code, and approved [workspace memory](/features/memory).
5. The investigation records its findings and may open a draft PR. Its result and links appear in **Investigations** and in the connected notification channel.

A single investigation may span several windows and many alerts. Its status describes the latest agent run. Review the evidence and any proposed fix before changing production.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.