Same Investigation Graph DNA — different trigger. Laptop investigate is reactive; the optional Observe agent is continuous watch → Incident → gated notify.
Originally published at https://kprompt.ai/blog/observe-vs-investigate.
Operators ask the same question two ways: “why is checkout broken right now?” and “tell me when payments starts misbehaving without me watching.” kprompt answers both — but with different surfaces. Confusing them is how you end up expecting a laptop REPL to page Slack, or an in-cluster watcher to silently apply fixes.
| Surface | Trigger | Scope | Mutate? | Artifact |
|---|---|---|---|---|
CLI investigate / why / timeline |
||||
| You type a prompt | kubeconfig context(s) | Only after PlanResult approval | Investigation → optional PlanResult | |
| Observe agent | Always-on watch | One namespace (Role) | Never by default | Incident / AgentAlert |
| Autopilot (opt-in) | Open Incident + allowlist | Same ns agent | Propose-only; apply gated | PlanResult (Applied false) |
Always-on intelligence is the same gated Investigation Graph as CLI investigate — signal hops → findings → optional PlanResult → approve → apply → verify. It is not a free-form multi-agent fleet. Observe / Namespace Agent runs the continuous edge of that graph; investigate is the on-demand hop you steer from a laptop. Modes table: namespace-agent.
kprompt "investigate checkout" -n payments
kprompt "why is api crashing" -n payments
kprompt "timeline for checkout" -n payments
kprompt agent run -n payments \
--analyze --fetch-logs --health --heuristic
git clone https://github.com/kprompt/kprompt-examples.git
cd kprompt-examples
make walkthrough
kprompt "investigate checkout" -n payments
Heuristic Observe needs no LLM key. Investigate with a provider when you want richer narration — still read-first; mutations stay behind approval. Pair with alert fatigue gates and the kind demo. Experimental — prefer kind / non-prod first.
Try: kprompt.ai · GitHub · brew install kprompt/tap/kprompt
Muhtalip