What it does
You give it an incident description and the questions you want answered. It locates the affected resources, reads their metrics and logs, and correlates what it finds into structured findings — each one carrying a portal deeplink so the evidence can be opened rather than taken on trust.What it reads
All of it read-only. The five capabilities below were measured against a plain Reader role, not assumed from documentation.Before you deploy
Unlike the Datadog and Grafana investigators, this agent has no MCP Gateway path. Azure publishes no
hosted MCP endpoint, so there is no remote server for the gateway to be bound to and no group to
pick — the agent’s Azure tooling runs alongside it, configured from the connection you select.
Ask it for
In chat, or as a run’s prompt:incident_description, questions, affected_services,
investigation_start, context and budget_seconds.
Defaults and limits
The time budget degrades rather than fails. At 70% the agent is nudged to converge; at 100% further
tool calls are refused and it reports what it has.
In a workflow
This is a specialist, not a lead. An orchestrator delegates the Azure slice of an incident to it and synthesizes its findings with other specialists’ work. Where a workload spans Azure and Kubernetes, pairing it with a cluster investigator covers both halves. See Orchestration for how a step delivers work to it.What it will not do
It never changes anything in Azure. It has no mutating tool, so it cannot restart a resource, edit a configuration or adjust a scaling rule. It sees one subscription’s worth of evidence, bounded by what the connection’s role permits. Where a capability is not granted, it reports the gap instead of inferring around it.Next steps
Built-in integrations
Create the Azure connection this agent uses.
AWS Infrastructure Investigator
The same investigation shape, over AWS.
Runs & evidence
Read the tool calls behind a finding.
Agent catalog
Every catalog agent, side by side.