Run an investigation in Incident Command Center

Incident Command Center is currently available through an early access program (EAP). Features, interfaces, and availability may change as we continue development.

The Incident Command Center is available to customers on the Jira Service Management Premium and Enterprise plans.

When an incident affects a service, figuring out where to look first can be difficult. Instead of manually cross-referencing dashboards, alerts, and recent deployments, use Investigation.

For a given incident, investigation in the Incident Command Center (ICC) analyzes your available incident data to surface potential root causes, supporting evidence, and dependency maps so your team can quickly find the source of the issue.

Before you begin

To access the Investigation tab, ensure that:

  • Incident Command Center is enabled for the Jira Service Management space where the incident is actively being managed.

  • You have the necessary agent permissions to view the incident.

  • Rovo is enabled for your site by your organization admin.

Run an investigation

  1. Open the incident in Jira Service Management.

  2. Select the Investigation tab.

  3. Select Run investigation.

  4. Wait while ICC analyzes available incident details, including affected services, related alerts, past incidents, telemetry, and development activity.

  5. Review the potential causes identified by ICC.

  6. For each hypothesis, review the supporting evidence, confidence level, and affected service relationships.

  7. Use the service graph to visually understand how the affected services relate to the suspected cause.

  8. Use these insights alongside your team’s standard process to validate or rule out each hypothesis.

Understand your investigation results

When the analysis finishes, ICC presents a list of hypotheses. These results are generated by analyzing your organization's connected data sources, including historical knowledge base content, recent deployments, and telemetry data.

Root-cause hypotheses

Suspected explanations for what caused the incident. Some of the most likely causes of the incident are a recent deployment, a database spike, or a downstream service outage. Review each hypothesis carefully to confirm the exact cause.

For each hypothesis, you see an indicator (for example, High, Medium, Low) to show how strongly the available evidence supports the hypothesis. High confidence usually means multiple data points, such as an alert and a deployment point, pointing to the same cause.

Supporting evidence

A breakdown of the exact signals ICC used to generate the hypothesis, giving your team a direct trail to follow and validate.

Service graph highlights

A visual dependency map that highlights the specific service or relationship associated with the suspected root cause, helping you visualize upstream and downstream impacts.

Telemetry data

Pulls in real-time information from your connected observability tools such as Datadog, New Relic, or Dynatrace. This allows you to view critical system signals, performance spikes, and error rates directly in ICC without switching tools.

While investigation analysis uses MCP integrations, telemetry data requires active Rovo connectors for your observability tools.

During an active incident, use these signals to guide your troubleshooting and decide what to look at next. You can first focus on validating the cause and stabilizing the service.

Read more on how to add connectors

If results are limited

If ICC can't identify a high-confidence hypothesis or the investigation fails to yield results, it usually means there isn't enough context for the incident.

To improve the analysis, try linking additional alerts, tagging all related affected services, or verifying that your third-party observability and deployment integrations are configured and actively sending data.

What to do next

  • Once you have validated a likely cause, select Create mitigation plan from the Investigation tab, and then view and manage recommended actions under Mitigation.

  • If you need to keep stakeholders informed of your findings, use the Communications tab to draft a status update based on your newly discovered details.

Still need help?

The Atlassian Community is here for you.