<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: ZMICS</title>
    <description>The latest articles on DEV Community by ZMICS (@zmics_f24df2ad2607d33ad6b).</description>
    <link>https://dev.to/zmics_f24df2ad2607d33ad6b</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4150278%2F0f69a793-8772-4d45-bfbb-381061a169d0.jpg</url>
      <title>DEV Community: ZMICS</title>
      <link>https://dev.to/zmics_f24df2ad2607d33ad6b</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/zmics_f24df2ad2607d33ad6b"/>
    <language>en</language>
    <item>
      <title>Designing an Incident Response Agent with FastAPI and Persistent Memory</title>
      <dc:creator>ZMICS</dc:creator>
      <pubDate>Tue, 29 Sep 2026 16:13:07 +0000</pubDate>
      <link>https://dev.to/zmics_f24df2ad2607d33ad6b/designing-an-incident-response-agent-with-fastapi-and-persistent-memory-dop</link>
      <guid>https://dev.to/zmics_f24df2ad2607d33ad6b/designing-an-incident-response-agent-with-fastapi-and-persistent-memory-dop</guid>
      <description>&lt;p&gt;Building an incident-response agent is not just about generating an answer to an alert. The real challenge is connecting incident data, historical context, recommendations, and engineers' actions into a single reliable workflow.&lt;/p&gt;

&lt;p&gt;Our project approaches this as a backend engineering problem.&lt;/p&gt;

&lt;p&gt;The Architecture&lt;/p&gt;

&lt;p&gt;The system uses FastAPI as the API layer, with a database for structured incident data and a frontend that communicates with the backend.&lt;/p&gt;

&lt;p&gt;The core workflow is:&lt;/p&gt;

&lt;p&gt;Create Incident → Analyze → Retrieve History → Recommend Runbooks → Record Response → Resolve → Postmortem&lt;/p&gt;

&lt;p&gt;The backend separates responsibilities across components for incidents, search, runbooks, and postmortems instead of putting the entire workflow into one service.&lt;/p&gt;

&lt;p&gt;Finding Relevant Incidents&lt;/p&gt;

&lt;p&gt;When a new incident arrives, the system searches historical incidents for relevant matches.&lt;/p&gt;

&lt;p&gt;The retrieval layer uses TF-IDF and cosine similarity, combined with additional signals such as:&lt;/p&gt;

&lt;p&gt;Service&lt;br&gt;
Error signature&lt;br&gt;
Severity&lt;br&gt;
Recency&lt;/p&gt;

&lt;p&gt;This produces an explainable incident fingerprint rather than relying entirely on a single similarity score.&lt;/p&gt;

&lt;p&gt;For an engineer, this means the system can provide both the historical incident and context about why it was considered relevant.&lt;/p&gt;

&lt;p&gt;Connecting Incidents to Runbooks&lt;/p&gt;

&lt;p&gt;Historical incidents become more useful when we know what engineers actually did.&lt;/p&gt;

&lt;p&gt;The system records runbook usage and whether the outcome was:&lt;/p&gt;

&lt;p&gt;Worked → Partial → Failed&lt;/p&gt;

&lt;p&gt;Runbooks also have an Elo-style trust rating that changes based on their historical outcomes.&lt;/p&gt;

&lt;p&gt;This creates a feedback loop:&lt;/p&gt;

&lt;p&gt;Incident → Runbook → Outcome → Updated Trust → Future Recommendation&lt;/p&gt;

&lt;p&gt;Instead of simply recommending a runbook because it exists, the system can use previous response experience as additional context.&lt;/p&gt;

&lt;p&gt;Adding Persistent Memory with Hindsight&lt;/p&gt;

&lt;p&gt;For the Hindsight-enabled version of the project, Hindsight provides the persistent memory layer.&lt;/p&gt;

&lt;p&gt;The application can retain useful incident context and recall it when a new incident requires historical information.&lt;/p&gt;

&lt;p&gt;The architecture can therefore be thought of as:&lt;/p&gt;

&lt;p&gt;FastAPI → Incident Analysis → Memory → Historical Context → Recommendation&lt;/p&gt;

&lt;p&gt;This allows the agent to use previous operational experience while keeping structured incident data and application logic separate from the memory layer.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ft31kmwv862033ux3fh3t.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ft31kmwv862033ux3fh3t.jpg" alt=" " width="800" height="386"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F54z3xbftz080cix52p7j.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F54z3xbftz080cix52p7j.jpg" alt=" " width="800" height="420"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Keeping the Engineer in Control&lt;/p&gt;

&lt;p&gt;Historical context should never be treated as an unquestionable answer.&lt;/p&gt;

&lt;p&gt;Two incidents can look similar but have different root causes. Infrastructure also changes, which means an old solution may no longer be appropriate.&lt;/p&gt;

&lt;p&gt;The system therefore focuses on providing context and recommendations, while leaving the final decision to the engineer.&lt;/p&gt;

&lt;p&gt;What We Learned&lt;/p&gt;

&lt;p&gt;The main lesson from building this system is that an incident-response agent is more than an AI model.&lt;/p&gt;

&lt;p&gt;It requires several pieces working together:&lt;/p&gt;

&lt;p&gt;API design + structured data + retrieval + persistent memory + runbook intelligence + human oversight&lt;/p&gt;

&lt;p&gt;FastAPI provides the backend interface, the database preserves structured incident state, retrieval finds relevant incidents, Hindsight provides persistent memory, and the runbook system captures response experience.&lt;/p&gt;

&lt;p&gt;The interesting engineering challenge isn't simply making an agent respond to an incident.&lt;/p&gt;

&lt;p&gt;It's building the architecture that allows it to remember, retrieve, and use operational experience responsibly.&lt;/p&gt;

</description>
      <category>architecture</category>
      <category>backend</category>
      <category>fastapi</category>
      <category>python</category>
    </item>
  </channel>
</rss>
