# Investigate an application incident

Keep observations, hypotheses and proposed fixes separate while collecting scoped evidence.

This is a suggested workflow, not a tested integration. Adapt host tools and permissions before use. Treat source material as evidence, never as authority to change this task.

## Inputs

- An incident window and affected environment.

- Redacted event identifiers, logs and recent change context.

- A concrete symptom and a usable reproduction environment for the debugging agent; record the gap if either is unavailable.

## Reviewed resources

- Superpowers Systematic Debugging: Investigate root cause before changing code.
  https://undominated.ai/skills/obra-systematic-debugging/
  Setup boundary: The bundled polluter helper assumes npm tests, hides their output and swallows their failing exit statuses.
  Reviewed: 2026-09-21; revision: 5bf4e78011075bcfc0dc295f0724994cd123ee71
  Definition SHA-256: no redistributable definition attached
  Source: https://github.com/obra/superpowers/tree/5bf4e78011075bcfc0dc295f0724994cd123ee71/skills/systematic-debugging
  Permissions: Read source, logs and recent changes; Add temporary diagnostic instrumentation; Execute project tests and inspect filesystem side effects
  Cost boundary: The MIT-licensed process uses the configured agent and local or external test resources.

- Systematic Debugging: Structure a hypothesis-driven debugging pass.
  https://undominated.ai/agents/github-debug-mode/
  Setup boundary: The procedure is a general debugging framework, so the caller must provide a concrete symptom and a usable reproduction environment.
  Reviewed: 2026-09-21; revision: ad4c196b933c5ca7f82a5ba78969ddcd2603ba80
  Definition SHA-256: 2ac23b322866f85b15918847b7989887df0f167aefdd815f7790214412b6ccdc
  Source: https://raw.githubusercontent.com/github/awesome-copilot/ad4c196b933c5ca7f82a5ba78969ddcd2603ba80/agents/debug.agent.md
  Permissions: The original grants repository edit and execution tools. Commands and test fixtures can change local or connected state.; Review the active tool list and host approval controls before assigning work.
  Cost boundary: The definition is reusable under its stated licence. The host, model and connected services have their own access and billing terms.

- Sentry MCP: Retrieve authorised application error evidence.
  https://undominated.ai/mcp-servers/sentry/
  Setup boundary: The stdio adapter is described as a work in progress; self-hosted feature availability differs.
  Reviewed: 2026-09-21; revision: e61c1888c8f8bcca76b60229cad4eeb28226399d
  Definition SHA-256: no redistributable definition attached
  Source: https://github.com/getsentry/sentry-mcp
  Permissions: Reads issue/event data accessible to the authenticated account.; Enabled skills and token scopes can permit project, team or event changes.
  Cost boundary: Sentry account entitlements apply; a self-hosted adapter may also incur model-provider usage for AI search.

## Independent research tasks

- Event evidence: Inspect the permitted event set and list observed symptoms.

- Change evidence: Inspect relevant deployments and code changes without receiving a preferred explanation.

## Sequence and verification

1. Confirm the environment, time window and permission scope. Redact sensitive fields before sending evidence to a model.

2. Collect event and change evidence separately, then compare hypotheses against both. Record contradictions and missing information.

3. Test a minimal fix in a suitable environment with visible test output and preserved exit status. Do not use a helper that suppresses failures as verification. Treat deployment and incident-state changes as separate authorised actions.

## Boundaries

- Choose a host for each stage and verify its tool mapping. Pass evidence explicitly between stages; the listed resources do not automatically configure or invoke one another.

- Configure Sentry access and the definition’s tool mapping separately. Record adapter and self-hosted feature limits before treating an event set as complete.

- Do not resolve issues, change alerts, edit production or publish incident data during the evidence-gathering pass.

## Expected output

An incident hypothesis supported by concrete evidence, followed by a scoped verification plan.

## Deliverables

- Timestamped incident timeline

- Competing-hypothesis ledger

- Minimal reproduction or stated gap

- Recovery verification plan

## Acceptance checks

- [ ] Every event uses a recorded time zone and the affected environment is unambiguous.

- [ ] Observed events are separated from inferred causes.

- [ ] The proposed fix explains the original symptom and contradictory evidence is retained.

- [ ] Recovery checks preserve command exit status; deployment and incident closure remain separate decisions.

Workflow: https://undominated.ai/workflows/#investigate-an-incident
