# Investigation with context and confidence

> Source: <https://blog.bluebox.ai/investigation-with-context-and-confidence/>
> Published: 2026-09-14 13:00:22+00:00

[quick start](/get-started-with-bluebox-in-a-single-coffee-break/)

## Get Started with Bluebox in a Single Coffee Break

If you've ever shipped a feature and held your breath waiting to see what broke in production or spent hours re-prompting your coding agent just

In theory, your application is always working perfectly in the production environment. While in practice, it is not.

One night at 2AM, your application ran into issues, and you got paged for an overnight incident troubleshooting call. Despite its mighty power to create source code, your coding agent cannot help because it lacks insight into your product environment. That’s the moment you turn to Bluebox AI for help. That’s the moment you need “investigation” feature.

More than a quick chat with AI, an investigation is how Bluebox goes deep on a problem to investigate a problem end to end.

Below is what’s happening under the hood when you trigger an investigation in Bluebox:

Let’s take a look at the report generated from one recent investigation as an example. You can see it highlights of “system status”, “root cause” and “customer impact” in its header and allows to you expand / dive into specific sections of investigate ("Executive summary", "Recommended actions", "Impact & blast radius", "Context & signals", "Root cause & hypotheses", "Evidence trail" and more).

**TL;DR:** Once you trigger an investigation, you will have Bluebox as your AI agent to investigate any issues and summarize the outcome in a nicely formatted report and GitHub issues.

Sounds nice, but how can I use this feature?

Generally, an investigation can be triggered in manual way or automatic way.

**Manual investigation** is triggered by your explicit ask either in a new chat: choose "investigate", click from default common questions or raise your own questions like below:

Or you can do it in the “investigations” UI, a page with all the investigation listed by status. Just click “New Investigation” button on the top right corner, Then fill the forms like below to trigger an investigation, where you can specify the title and visibility of your investigation:

Or you can trigger it from a problems detected in the "Findings" page:

**Automatic investigation** will be triggered automatically by a detected problem, which can be enabled/disabled in "Setup" page. Bluebox continuously watches your connected environment. The moment it spots an issue, Bluebox opens a full investigation on its own. No prompt needed.

That means the exact same rigor described above — situational overview, hypothesis formation, evidence testing, mitigation, report — runs automatically as soon as something breaks. By the time you'd think to ask, the investigation may already be done and waiting for you.

Worrying auto investigation eats up your AI budget? You control how much runs on autopilot. Every workspace has a daily AI usage quota, and a setting in "Setup" page lets you decide what share goes to automatic investigation — Bluebox never quietly spends your whole allowance without your say. You can also change the GitHub issue policy here:

Remember that 2AM incident we mentioned at the beginning? Below is the best practice to change your life with Bluebox investigation.

Combining the "eyes" of observability and the "hands" of vibe coding together, Investigation in Bluebox helps you investigate any issues with context and confidence, even before you notice them!

Now is the time to trigger an investigation, watch what happens. You will have the confidence to add it into your workflow to get ahead of the chaos and get rid of the risks.

Coding agents are genuinely good at understanding a local codebase. Point one at a repository and it can read the architecture, trace the data flow, interpret configuration, and

Bluebox, Kiro, and AWS DevOps Agent bring production intelligence directly into AI-driven software delivery. By connecting development and operations with shared runtime context, teams can build, deploy,
