Skip to main content
Remediation is the decision step between an investigation and an action. It reads a finished investigation and returns one of three typed decisions — a proposed fix, no action warranted, or the questions that would settle it.

Overview

An investigation that ends in a finding creates pressure to act on it, and the finding is not always strong enough to deserve that. The judgement call — is this evidence, or is it a confident-sounding inference — is the one most often skipped when an incident is still open. Deploy it to make that judgement explicit. You hand it a finished investigation, and it reads the findings and the run transcripts behind them — separating what was actually observed from what was inferred — and returns one of three typed decisions: Reading the transcripts rather than only the summary is the point. A confident-sounding finding built on an inference is a different thing to act on than one built on an observation, and the distinction survives into its decision. For: teams who want a decision step between investigating and changing something. Not for: carrying the change out — despite the name, this agent plans. Remediation Executor is the one that acts.

Tools supported

It holds no cloud, cluster or repository credentials, and has no shell. Its only reach is back into the platform for the investigation it was given.

Scenario examples

It takes a completed investigation rather than a free-text question, so it is normally driven by a workflow step rather than by a person. Where you do invoke it directly, pass the investigation you want a decision on: Decide on one investigation
When you expect no action
When the evidence is thin

Prerequisites

Catalog ID: remediation — what the deploy API takes.

As part of a workflow

It is the decision step between investigation and action. An incident workflow investigates, passes the result here, and routes on what comes back: a proposed remedy goes to an executor or to a human for approval, questions go back to the specialists that can answer them, and no-action closes the loop without a change. That routing is what makes the third answer useful. An agent that could only propose fixes would propose one for every finding. See Orchestrator and Approvals.

Limitations

  • It never mutates a live system. Not as a policy setting, and not as a prompt instruction — it has no credentials for a target system and no shell, so there is nothing to mutate with. A proposed remedy is a recommendation until something else carries it out.
  • Its name invites the opposite assumption, which is worth stating plainly to anyone reviewing its access: this agent plans, and Remediation Executor is the one that acts.
  • It decides on what it was given. Its reach is the investigation passed to it, not the systems that investigation looked at.
  • It takes an investigation, not a question. A free-text prompt with no run behind it has nothing for it to read.
claude-sonnet-5 — the shipped default. The work is judgement over evidence someone else gathered, where a weaker model produces confident-sounding conclusions that do not hold.

Next steps

Remediation Executor

Carry a proposed remedy out.

Approvals

Put a human decision in front of an action.

Agent catalog

Every catalog agent, side by side.