PETER PAN
01  /  08
Enterprise · Operations · AI

Observability and
Agentic Incident-response
platform

A trustworthy AI teammate for modern operations.

Alert → evidence → safe action.

Trustworthy Agentic Incident Response
© PETER PAN
PETER PAN/ The Problem
02  /  08
The Incident Reality

Too many tools.
Too much noise.
One tired analyst.
Not enough trusted context.

The real challenge is not detection.
It is trusted understanding.

Grafana
Metrics
New Relic
APM
Kubernetes
Orchestration
GitLab
Deploys
Confluence
Runbooks
Teams
Chat
JFrog Artifactory
Artifacts
F5
Load Balancer
AWS
Cloud
Slack
Alerts
MTTR ticking+0m 00sminutes lost
Trustworthy Agentic Incident Response
© PETER PAN
PETER PAN/ Origin
03  /  08
Meet

PETER

The First Generation

P
Prioritization
What matters, right now
E
Enrichment
Adds context from the org
T
Triage
Classifies the incident
E
Escalation
Routes to the right team
R
Resolution
Guides toward closure
EngineRAG-powered answers from organizational knowledge.
Trustworthy Agentic Incident Response
© PETER PAN
PETER PAN/ Evolution
04  /  08
The Transformation

From PETER to PETER PAN

PETER could answer.

But he could not prove.

The Four Wings
01
The Mind
Reasoning
Every conclusion comes with a chain of thought and citations.
02
The Shield
Guardrails
Blocks unsafe, uncertain, or destructive actions before they ship.
03
The Memory
Feedback Loop
Learns from analyst decisions to get sharper every incident.
04
The Eyes
Dynamic Dashboards
Paints the current problem live — exactly the view you need.
Trustworthy Agentic Incident Response
© PETER PAN
PETER PAN/ Architecture
05  /  08
The System

How PETER PAN Works

INGEST
RETRIEVE
REASON
GUARD
ACT
READY
Press SPACE to watch an alert become a safe, evidence-backed action.
ALERT
payments-api p99 = 2.7s
severity=critical · region=eu-west-1
ALERT · STEP 01
Raw alert from Grafana — no context, no cause, just a symptom.
WORKFLOW
wf_incident_v3 started
run_id=INC-4821 · steps=7
WORKFLOW · STEP 02
n8n normalizes the alert and starts the incident workflow with a trace id.
TRACE
trace: fanout / 5 sources
GET /metrics · /logs · /deploys · /kb
TRACE · STEP 03
One trace, 5 parallel fetches to metrics, logs, deploys and the knowledge base.
LOG
conn_pool_exhausted ×12
svc=payments · window=14m · Top-K=5
LOG · STEP 04
Pinecone returns the 5 highest-signal snippets — logs, runbooks, prior incidents.
METRIC
cause: DB pool exhausted
confidence=0.86 · evidence=4/5
METRIC · STEP 05
Bedrock proposes a cause with a confidence score and cites the evidence used.
NOTE
3 checks passed · 0 blocked
grounded · safe · reversible
NOTE · STEP 06
Every claim is grounded in evidence; unsafe or destructive actions are blocked.
ACTION
3 safe actions ready
rollback · scale pool · notify
ACTION · STEP 07
The on-call sees evidence, reasoning and safe actions — one click to approve.
▸ IDLE — press SPACE to run the pipeline
0 / 7
Evidence-grounded answers
Hallucination prevention
Human-controlled actions
Monitoring Agent OS
Observability for the AI itself — the watcher of the watcher.
Monitored dimensions
TokensLLM CallsAgentsToolsSessionsTipsSummaries
Observed AI environments
CursorClaude Code CLICodexOpenClawHermes
Trustworthy Agentic Incident Response
© PETER PAN
PETER PAN/ Demo
06  /  08
Live Demo · 2 edge cases

P1 · Payments latency incident

  1. 01
    High-priority alert
    P1 · payments-api p99 2.7s · eu-west-1
  2. 02
    Collect from sources
    Grafana · New Relic · K8s · GitLab · Confluence
  3. 03
    Embed · Top-K · Rerank
    1536-d · Top-K 20 → rerank → 5
  4. 04
    Reason over evidence
    Cause: DB pool exhausted after deploy #4821
  5. 05
    “Draw me the problem”
    Dashboard generated on demand
  6. 06
    Recommend safe actions
    Scale pool · Notify · Rollback (gated)
  7. 07
    Human approves
    AI assists, you decide
peterpan://incident/INC-4821/payments-p99
IDLE
▸ svc: payments-api▸ p99: 2.7s▸ err_rate: 4.1%▸ db_pool: 100/100▸ deploy: #4821▸ rps: 1,204▸ svc: payments-api▸ p99: 2.7s▸ err_rate: 4.1%▸ db_pool: 100/100▸ deploy: #4821▸ rps: 1,204
payments-api · p99 latency (agent-generated)
+240% vs 1h
-60m-30mnow
Ask: “Draw me the problem.”
Data sources
GrafanaNew RelicKubernetesGitLabConfluence
Retrieval
1536-d · Top-K 20 → rerank 5
awaiting retrieval…
Safe actions
Scale DB pool → 200
Notify #payments-oncall
Rollback deploy #4821
Trustworthy Agentic Incident Response
© PETER PAN
PETER PAN/ Takeaway
07  /  08
The Takeaway

Not another chatbot.
A trustworthy AI teammate
for modern operations.

Faster Understanding
Evidence retrieved, ranked, explained.
Evidence Before Action
Every recommendation is provable.
Observability for AI
Tokens, tools, sessions, and LLM calls — metered end to end.

PETER PAN reduces time to understanding and increases trust during critical incidents.

Trustworthy Agentic Incident Response
© PETER PAN
PETER PAN/ Ready to Fly?
08  /  08
Ready to Fly?

Ready to Fly?

Let's connect and reduce MTTR in production together.

Scan to connect
linkedin.com/in/reemmor
© PETER PAN
Trustworthy Agentic Incident Response
© PETER PAN
Edit with