Prysm
// Module — Investigate

From alert to root cause in one conversation.

When something looks wrong — a failed sync, a contract violation, a spike in errors — open an Investigation in PrysmOS. Juno drives a dedicated toolkit of ~45 instruments across your workspace and comes back with a causal answer, not another pile of logs.

~45 dedicated investigation tools10 lenses, blended per caseOrg-scoped · approvals intact

INV-1042 · nightly_orders_sync

opened from trigger failure · lens: root-cause + impact

live
  • Pulled sync run history — last green at 01:58
  • Diffed runs #1182 → #1183 — field order_total renamed
  • Traced lineage — 3 dashboards read downstream
  • Correlating error spike with deploy window…

emerging finding

Deploy v2.14 renamed orders.total → sync schema mismatch at 02:14. Blast radius: 3 dashboards, 1 contract.

evidence trail · 6 entrieshypotheses · 2 ruled out, 1 standing

juno investigates inside PrysmOS — your org's data only

// How it works

Stop spelunking through logs

An investigation is a conversation with an analyst who can actually run the queries — and shows the work.

01

Open it from the alert

A failed sync, a contract violation, an error spike — one click opens an Investigation and Juno already has the context: what broke, when, and where it sits.

02

Juno drives the toolkit

A dedicated workbench of ~45 tools queries run histories, the audit log, violations, and lineage across the workspace — no tab-hopping, no log spelunking.

03

Hypotheses get tested

Juno tracks every hypothesis, rules them out with evidence, and blends lenses — root-cause plus impact plus timeline — as the picture sharpens.

04

Findings you can ship

Structured findings, an evidence trail, a timeline, and a causal diagram — exportable as a report and shareable through a token-gated link.

// Investigation lenses

Ten ways to look at a problem

Pick a lens or let Juno pick for you — a single investigation can blend several. Root-cause finds the why, impact maps the blast radius, and freeform follows wherever the evidence leads.

Lenses steer which tools Juno reaches for first.
root-cause
anomaly
impact
timeline
trend
data-quality
performance
lineage
compliance
freeform
// The toolkit

~45 tools, one driver

You describe the symptom. Juno picks the instruments, runs them in the right order, and writes down what each one proved.

Reach across the workspace

One investigation queries every corner of PrysmOS — no exports, no swivel-chair.

  • mapping, script & trigger run histories
  • audit log & contract violations
  • lineage traces & resource search
  • time-series aggregation & org health snapshot

Statistical analysis

The math an on-call engineer would run — run for you, cited in the evidence trail.

  • compare periods & detect outliers
  • change points, correlated series & periodicity
  • cluster errors, failure streaks & reliability stats
  • forecast series & diff any two runs

Data-quality instruments

Point the microscope at any sheet or feed and see what it's really made of.

  • profile columns, find duplicates & invalid cells
  • freshness checks & recent changes
  • connection health & blast-radius tracing
  • coverage gaps, orphaned resources & error-text search

Case management, built in

Investigations behave like real casework — organized, repeatable, shareable.

  • hypothesis tracking & related investigations
  • suggested metadata as findings form
  • reusable investigation templates (playbooks)
  • exportable reports via token-gated links
Everything stays org-scopedDestructive actions still need human approvalEvery claim cites the tool that produced it
// See it run

Watch Juno find the why

A sync has failed fourteen times. One click, five tool calls, three hypotheses — and a causal chain with a report attached.

app.prysmhq.co/investigate/INV-1042

nightly_orders_sync

trigger run failed · 14 consecutive failures

awaiting investigation

juno · run_history

Pulled sync run history — last green 01:58, failing since 02:14

juno · diff_runs

Diffed runs #1182 → #1183 — orders.total renamed to total_usd

juno · change_point

Change point detected — error rate 0.4% → 11.2% at 02:14

juno · correlate

Correlated with deploy log — v2.14 shipped 02:11

juno · lineage

Traced blast radius — 3 dashboards + 1 contract downstream

lenses · root-cause + impact

Findings · hypotheses

Hypotheses, the causal chain and the final report land here. Run the investigation →

org-scoped · approval-gated

Juno reads across your workspace and nothing else. Any destructive action still waits for a human to approve.

Simulated — in PrysmOS, Juno runs these tools against your real run histories, lineage and audit log.
// What you get

An answer you can defend

Not a summary of what happened — a causal claim with the receipts attached.

A causal diagram, not a guess

Findings land as a chain — deploy → renamed field → failed sync → stale dashboard — with evidence attached to every link.

Proof in the numbers

Change points, period comparisons and failure streaks are computed, not eyeballed. The stats are part of the record.

Reports people actually read

Export a structured Investigation Report — findings, evidence trail, timeline — and share it through a token-gated link. Postmortems write themselves.

Playbooks for the repeat offenders

Save any investigation as a template. Next time the feed stalls, Juno runs the same playbook before you've finished reading the alert.

// Boundaries

Autonomous where it's safe, supervised where it counts

Org-scoped, always

Every tool runs inside your organization's boundary. Juno sees your run histories, your audit log, your lineage — and nothing outside it.

Humans keep the keys

Juno investigates freely but acts carefully — destructive actions still require human approval, exactly like everywhere else in PrysmOS.

Evidence or it didn't happen

Every finding cites the tool calls that produced it. The evidence trail is the deliverable, not an appendix.

// Questions

Fine print, answered

Anything that looks wrong in the workspace: a failed sync, a contract violation, a spike in script errors, suspicious audit activity, a stale schedule. Pick a lens — root-cause, anomaly, impact, timeline, trend, data-quality, performance, lineage, compliance, or freeform — or let Juno blend them as the case develops.

// One workspace

Next alert: open an Investigation, get a causal answer.

Evidence trail, timeline, and causal diagram included. Free to start — no credit card required.