# Observe vs investigate: always-on agent vs on-demand CLI

> Source: <https://dev.to/muhtalipdede/observe-vs-investigate-always-on-agent-vs-on-demand-cli-2ccj>
> Published: 2026-08-16 11:49:12+00:00

Same Investigation Graph DNA — different trigger. Laptop investigate is reactive; the optional Observe agent is continuous watch → Incident → gated notify.

*Originally published at https://kprompt.ai/blog/observe-vs-investigate.*

Operators ask the same question two ways: “why is checkout broken right now?” and “tell me when payments starts misbehaving without me watching.” kprompt answers both — but with different surfaces. Confusing them is how you end up expecting a laptop REPL to page Slack, or an in-cluster watcher to silently apply fixes.

| Surface | Trigger | Scope | Mutate? | Artifact |
|---|---|---|---|---|
CLI `investigate` / `why` / `timeline`
|
You type a prompt | kubeconfig context(s) | Only after PlanResult approval | Investigation → optional PlanResult |
| Observe agent | Always-on watch | One namespace (Role) | Never by default | Incident / AgentAlert |
| Autopilot (opt-in) | Open Incident + allowlist | Same ns agent | Propose-only; apply gated | PlanResult (`Applied` false) |

Always-on intelligence is the same gated [Investigation Graph](https://github.com/kprompt/kprompt/blob/main/docs/investigation-graph.md) as CLI investigate — signal hops → findings → optional PlanResult → approve → apply → verify. It is not a free-form multi-agent fleet. Observe / Namespace Agent runs the continuous edge of that graph; [investigate](https://github.com/kprompt/kprompt/blob/main/docs/investigate.md) is the on-demand hop you steer from a laptop. Modes table: [namespace-agent](https://github.com/kprompt/kprompt/blob/main/docs/namespace-agent.md).

```
# On-demand RCA (reactive)
kprompt "investigate checkout" -n payments
kprompt "why is api crashing" -n payments
kprompt "timeline for checkout" -n payments
# Always-on Observe (continuous)
kprompt agent run -n payments \
  --analyze --fetch-logs --health --heuristic

# in-cluster: Helm charts/kprompt-agent (namespace Role)
git clone https://github.com/kprompt/kprompt-examples.git
cd kprompt-examples
make walkthrough

# afterward, on-demand:
kprompt "investigate checkout" -n payments
```

Heuristic Observe needs no LLM key. Investigate with a provider when you want richer narration — still read-first; mutations stay behind approval. Pair with [alert fatigue gates](https://kprompt.ai/blog/observe-agent-alert-fatigue) and the [kind demo](https://kprompt.ai/blog/observe-agent-kind-demo). Experimental — prefer kind / non-prod first.

**Try:** [kprompt.ai](https://kprompt.ai) · [GitHub](https://github.com/kprompt/kprompt) · `brew install kprompt/tap/kprompt`

Muhtalip
