Observe vs investigate: always-on agent vs on-demand CLI Kprompt introduced an always-on Observe agent that continuously watches a Kubernetes namespace and triggers gated notifications on incidents, complementing its on-demand CLI investigate command. Both modes share the same Investigation Graph DNA, but differ in trigger, scope, and mutation behavior, with the Observe agent never mutating by default and requiring explicit approval for any changes. Same Investigation Graph DNA — different trigger. Laptop investigate is reactive; the optional Observe agent is continuous watch → Incident → gated notify. Originally published at https://kprompt.ai/blog/observe-vs-investigate. Operators ask the same question two ways: “why is checkout broken right now?” and “tell me when payments starts misbehaving without me watching.” kprompt answers both — but with different surfaces. Confusing them is how you end up expecting a laptop REPL to page Slack, or an in-cluster watcher to silently apply fixes. | Surface | Trigger | Scope | Mutate? | Artifact | |---|---|---|---|---| CLI investigate / why / timeline | You type a prompt | kubeconfig context s | Only after PlanResult approval | Investigation → optional PlanResult | | Observe agent | Always-on watch | One namespace Role | Never by default | Incident / AgentAlert | | Autopilot opt-in | Open Incident + allowlist | Same ns agent | Propose-only; apply gated | PlanResult Applied false | Always-on intelligence is the same gated Investigation Graph https://github.com/kprompt/kprompt/blob/main/docs/investigation-graph.md as CLI investigate — signal hops → findings → optional PlanResult → approve → apply → verify. It is not a free-form multi-agent fleet. Observe / Namespace Agent runs the continuous edge of that graph; investigate https://github.com/kprompt/kprompt/blob/main/docs/investigate.md is the on-demand hop you steer from a laptop. Modes table: namespace-agent https://github.com/kprompt/kprompt/blob/main/docs/namespace-agent.md . On-demand RCA reactive kprompt "investigate checkout" -n payments kprompt "why is api crashing" -n payments kprompt "timeline for checkout" -n payments Always-on Observe continuous kprompt agent run -n payments \ --analyze --fetch-logs --health --heuristic in-cluster: Helm charts/kprompt-agent namespace Role git clone https://github.com/kprompt/kprompt-examples.git cd kprompt-examples make walkthrough afterward, on-demand: kprompt "investigate checkout" -n payments Heuristic Observe needs no LLM key. Investigate with a provider when you want richer narration — still read-first; mutations stay behind approval. Pair with alert fatigue gates https://kprompt.ai/blog/observe-agent-alert-fatigue and the kind demo https://kprompt.ai/blog/observe-agent-kind-demo . Experimental — prefer kind / non-prod first. Try: kprompt.ai https://kprompt.ai · GitHub https://github.com/kprompt/kprompt · brew install kprompt/tap/kprompt Muhtalip