AI & RCA

AI that understands evidence — and knows when it does not know.

AmrudAi is designed to use AI as an assistance layer over authoritative monitoring, topology and incident evidence, not as a replacement for it.

Illustration of evidence-grounded AI operational intelligence
◉DetectAcross all domains⌘CorrelateTopology & context△DiagnoseFind root cause▤ExplainEvidence & reasoning⚙Act SafelyGuided validation
ALERT EVIDENCE CONTRACTS

An alert should explain why it exists.

Before asserting an operational condition, the evaluation path is designed to consider whether expected evidence is present, fresh, valid, time-aligned and produced by healthy collectors.

  • Expected versus received evidence
  • Missing / stale / degraded evidence
  • Active validation outcomes
  • Contradictory signals
  • Collector and monitoring-path health
  • Confidence impact and semantic state
UPEvidence supports service health.DOWNFailure is sufficiently evidenced.UNKNOWNEvidence is insufficient or contradictory.STALEEvidence is outside freshness policy.MONITORING_DEGRADEDCollection path is impaired.SLA_DEGRADEDService is up but violating an objective.
INCIDENT INTELLIGENCE

Preserve the incident. Understand the change. Test the cause.

Incident Flight Recorder

Preserve a bounded before/during/after evidence window for qualifying incidents and investigations.

Similar Incident Memory

Surface relevant historical incidents without silently copying an old root cause into the current event.

Cross-domain Change Intelligence

Answer “what changed?” across NCM, cloud, CI/CD, IaC, Kubernetes, database, maintenance and ITSM evidence.

Active Evidence Acquisition

Use bounded, authorized diagnostics when they add information while preserving each vantage independently.

ObservedWhat did the platform actually see?
ImpactWhich service or dependency is affected?
Likely causeWhat best explains the current evidence?
ConfidenceHow defensible is that claim?
EvidenceWhat directly supports it?
ContradictionsWhat does not fit?
Missing evidenceWhat still needs validation?
Next validationWhich safe test gives the most information?
Recommended actionWhat should an authorized operator consider?
INCIDENT COPILOT

A grounded-assistance contract.

Every claim should resolve back to authoritative artifacts the requesting user is allowed to see. When evidence is insufficient, the result should be INCONCLUSIVE and state what is missing.

CONFIRMED deterministic / authoritative evidenceHIGH strong corroborated evidenceMEDIUM plausible with alternatives remainingLOW weak hypothesis for investigationINCONCLUSIVE insufficient evidence
CONTROLLED REMEDIATION

AI can recommend. Policy authorizes.

Diagnose→Recommend→Precondition→Impact Preview→Authorization→Execute→Validate→Rollback / Escalate

No direct LLM privilege

Model output cannot create authority or directly access credentials.

Bounded blast radius

Target constraints, parameter validation, concurrency limits, timeout and audit.

Post-action validation

Recovery evidence and rollback/escalation are part of the controlled workflow.