Overview
An investigation that ends in a finding creates pressure to act on it, and the finding is not always strong enough to deserve that. The judgement call — is this evidence, or is it a confident-sounding inference — is the one most often skipped when an incident is still open. Deploy it to make that judgement explicit. You hand it a finished investigation, and it reads the findings and the run transcripts behind them — separating what was actually observed from what was inferred — and returns one of three typed decisions:
Reading the transcripts rather than only the summary is the point. A confident-sounding finding
built on an inference is a different thing to act on than one built on an observation, and the
distinction survives into its decision.
For: teams who want a decision step between investigating and changing something.
Not for: carrying the change out — despite the name, this agent plans. Remediation
Executor is the one that acts.
Tools supported
It holds no cloud, cluster or repository credentials, and has no shell. Its only reach is back into
the platform for the investigation it was given.
Scenario examples
It takes a completed investigation rather than a free-text question, so it is normally driven by a workflow step rather than by a person. Where you do invoke it directly, pass the investigation you want a decision on: Decide on one investigationPrerequisites
Catalog ID:
remediation — what the deploy API takes.
As part of a workflow
It is the decision step between investigation and action. An incident workflow investigates, passes the result here, and routes on what comes back: a proposed remedy goes to an executor or to a human for approval, questions go back to the specialists that can answer them, and no-action closes the loop without a change. That routing is what makes the third answer useful. An agent that could only propose fixes would propose one for every finding. See Orchestrator and Approvals.Limitations
- It never mutates a live system. Not as a policy setting, and not as a prompt instruction — it has no credentials for a target system and no shell, so there is nothing to mutate with. A proposed remedy is a recommendation until something else carries it out.
- Its name invites the opposite assumption, which is worth stating plainly to anyone reviewing its access: this agent plans, and Remediation Executor is the one that acts.
- It decides on what it was given. Its reach is the investigation passed to it, not the systems that investigation looked at.
- It takes an investigation, not a question. A free-text prompt with no run behind it has nothing for it to read.
Recommended model
claude-sonnet-5 — the shipped default. The work is judgement over evidence someone else gathered,
where a weaker model produces confident-sounding conclusions that do not hold.
Next steps
Remediation Executor
Carry a proposed remedy out.
Approvals
Put a human decision in front of an action.
Agent catalog
Every catalog agent, side by side.