An alert fires at 3am. FirstClue reads the logs, the metrics and the runbook, works out what changed, and posts what it found in the thread. You wake up to an investigation, not a page.
The part that is always the same: gather the evidence, line it up against what changed, and write it down.
Mention it in a thread, or let an alert wake it. It pulls the logs, the metrics and the recent deploys, forms a hypothesis, checks it, and writes up what it found and what it ruled out.
Slack, GitHub, Jira, Confluence and AWS are connected from the start. Your runbooks and your past incidents are what it reasons from, and you can correct it in plain language when it gets something wrong.
Every customer gets a dedicated deployment: its own namespace, its own database, its own credentials. Nothing is shared with anyone else, and on Starter the model key is yours, so your incident data goes to your own account.
Kevra provisions your instance and walks you through the Slack app. Add the cloud and ticketing credentials you want it to read. About five minutes, no infrastructure on your side.
Mention it in a thread, or connect an alert channel and let it start on its own. It investigates and reports back where the conversation already is.
Correct a wrong conclusion, point it at a runbook, adjust the prompts. Each incident it handles makes the next one shorter.
The prototype takes a weekend. Keeping it fed, safe and on call is the rest of the year.
When the rotation is three people, every page costs a night. FirstClue takes the first hour so the human who wakes up starts from a summary instead of a blank dashboard.
Service owners ask the same questions in every incident. Put the answers where they already are: in the thread, with the logs and the deploy history already pulled.
The timeline is already written by the time the incident closes: what fired, what was checked, what was ruled out, and what turned out to be the cause.
Your whole team uses it for one price. 2 months free with annual billing.
Starter
$39
/ month
One team, on your own model key, with no cap on how much you investigate.
Sign Up1 dedicated instance, 1 team
Unlimited investigations, 2 concurrent
Slack-triggered and console investigations
Slack, GitHub, Jira, Confluence and AWS included
Up to 3 additional integrations
Bring your own Anthropic API key
Team
$399
/ month
Several teams, automatic investigation of your alert channels, and the model key on us.
Contact us100M tokens per month (~500 investigations)
Up to 5 teams, 4 concurrent
Auto-investigate alert channels
Custom agents and model choice
Up to 10 additional integrations
Audit log
Anthropic API key included
Enterprise
Custom
Unlimited teams, change governance, and the knowledge base stack.
Contact usVolume agreed per contract, 8 concurrent
Unlimited teams
Everything in Team
Change approval workflow
Unlimited integrations and agents
Knowledge base with RAPTOR retrieval
Priority support
Connect Slack, point it at an alert, and read what it found. No infrastructure on your side.
No credit card required. Instant access.
Deploy your first open-source tool in minutes.
Contact us to start your journey with us.