Introducing Swarm Investigation from BigPanda: Autonomous, multi-agent IT incident investigation

5 min read
Time Indicator

Context is fundamental for quickly resolving major IT incidents

When a major incident opens, the opening minutes often become a race across disconnected tools and competing theories. One engineer checks a monitoring tool. Another scrolls through change records, looking for the one line that explains everything. A third pings Slack, asking if anyone has seen this before. While these are reasonable steps, taken one at a time, in sequence, they are far too slow.

Imagine a payment gateway that starts throwing errors at 2 am. The on-call engineer checks the obvious service first, finds nothing wrong, and escalates. The next engineer checks a different layer of the stack. By the time someone finally connects the failure to a partner API that changed its rate limits the night before, forty minutes have passed. The average IT outage costs $14,056 per minute. That clock does not wait for the room to figure out where to look.

This isn’t a lack-of-data problem. Most enterprises already have the relevant evidence distributed across observability platforms, ITSM systems, change records, and collaboration tools. The challenge is connecting that evidence quickly enough to guide the response.

Introducing Swarm Investigation for the BigPanda AI Incident Assistant

The BigPanda AI Incident Assistant, named Biggy, lets responders ask questions in the context of an incident. Biggy draws on the IT Knowledge Graph and connected enterprise systems to return a synthesized answer, helping responders move from raw dashboards and records to relevant context.

Conversational investigation is powerful when a responder has a strong starting question. Swarm Investigation, the newest feature of the AI Incident Assistant, adds a persistent investigation loop. It autonomously generates and tests follow-up leads while the response team continues to coordinate the incident. It coordinates specialized AI agents to investigate multiple plausible causes in parallel, evaluate evidence as it emerges, and surface ranked root-cause hypotheses.

Swarm Investigation works

Swarm Investigation can launch from a major incident, a slash command, the BigPanda web app, or the API. From there, six types of agents work together on the problem.

Reasoning engine
Orchestrates the investigation. It reviews the current evidence and hypotheses, decides which leads to pursue next, and coordinates new investigation tasks.

Investigation agents
Execute focused tasks against the customer’s connected observability, ITSM, topology, and custom tools, returning findings and supporting evidence to the shared investigation.

Hypothesis Manager
Organizes potential causes, combines duplicate theories, and tracks how the available evidence strengthens or weakens each one.

Adjudicator
Evaluates proposed findings and next steps before they are accepted into the investigation.

Pulse agent
Produces concise progress updates so responders can see what Swarm has found, ruled out, and is investigating next.

Human-in-the-loop controls
Swarm can autonomously gather and analyze evidence, while remediation and other consequential actions remain subject to explicit human approval.

Tasks, findings, supporting evidence, and root-cause hypotheses are maintained in a shared investigation record. The Reasoning Engine uses that record to distinguish what is supported, what has been ruled out, and what still needs to be tested. Leads become hypotheses, and each hypothesis is strengthened, weakened, or ruled out as new evidence arrives. Responders can see the evidence trail behind Swarm Investigation’s conclusions rather than receiving an unexplained answer.

Give responders access to compounding institutional knowledge

Swarm Investigation draws on the BigPanda IT Knowledge Graph and the customer’s connected observability, ITSM, topology, and custom tools. That gives the investigation a broader view of the environment than any single system can provide.

When an investigation closes, its findings can be indexed into the IT Knowledge Graph and adaptive memory, depending on the organization’s configuration. This preserves the investigation record and creates the foundation for richer institutional knowledge over time. The result is a durable record of what was investigated, which evidence mattered, and how the incident was resolved.

Swarm Investigation is built to augment your team, not replace it. Responders can watch the investigation as it unfolds, ask it direct questions through Swarm Chat, or steer it toward a lead they already suspect. The agents do the legwork. Your engineers still make the calls that only a person should make.

What Swarm Investigation looks like in a real incident

During a major DNS outage, one BigPanda customer, a major hotel chain, had already spent more than two hours on manual troubleshooting before turning to Swarm Investigation.

“After more than two hours of troubleshooting across multiple teams, we activated a Swarm of Biggy agents due to the widespread impact,” the customer states. “The agents analyzed application errors, Dynatrace logs, and ServiceNow change records and identified the root cause in just 20 minutes.”

In an internal analysis of 29 closed production investigations across three organizations, Swarm produced a ranked root-cause conclusion in approximately 72% of cases. Median start-to-close time was approximately 33 minutes. Results vary with incident complexity, available evidence, and connected integrations.

Built for the people running the incident

Swarm Investigation is built for major incident managers, L2 and L3 engineers, and SRE teams: the people who need an answer fast and don’t have time to babysit an investigation on top of everything else. It fits alongside our Major Incident Management workflows and, when enabled in the applicable MIM configuration, can launch as part of the major-incident response. Responders can also start a Swarm from an active MIM when a deeper investigation is needed.

Get started with Swarm Investigation

Swarm Investigation is generally available as part of AI Incident Assistant, and does not require a separate license. Investigations consume credits through the same usage model as BigPanda’s other AI capabilities; usage varies with the number and depth of the agentic actions performed during an investigation.

Watch Swarm build and test root-cause hypotheses across connected observability and ITSM tools, and see how responders review the evidence and steer the investigation.