Most AI agents can analyze an incident. The harder problem is remembering what happened the last time something similar broke.
I built IncidentIQ to explore that problem: an AI incident response agent that uses Hindsight as long-term memory. Instead of treating every outage as a completely new investigation, IncidentIQ can recall previous incidents, their root causes, resolutions, runbooks, and outcomes.
The goal is simple:
Detect → Analyze → Recall → Recommend → Resolve → Learn
The Problem With Starting Every Incident From Zero
Consider an authentication service that suddenly starts returning failures because its Redis connection pool is exhausted.
A conventional AI assistant can analyze the current logs and explain that the connection pool may be saturated. But it does not automatically know that the same organization previously experienced a nearly identical incident, what fixed it, or which attempted fixes failed.
That historical context can be more valuable than another generic explanation of Redis.
IncidentIQ treats previous incidents as operational experience.
How IncidentIQ Works
IncidentIQ uses a Next.js frontend together with a FastAPI analysis backend.
The frontend handles the incident investigation workflow and communicates with the backend through server-side calls. Hindsight provides the long-term memory layer, while the analysis service uses the current incident together with recalled memories.
The workflow is:
- An incident is created or selected.
- IncidentIQ extracts important incident signals.
- Hindsight recalls relevant historical incidents.
- The analysis service combines current evidence with those memories.
- IncidentIQ generates a root-cause hypothesis and resolution recommendation.
- The engineer reviews the recommendation and creates a post-mortem.
- The resolved knowledge is retained in Hindsight.
- A future incident can recall that knowledge.
This makes memory part of the investigation rather than a separate search screen.
Hindsight Is the Important Part
The Hindsight integration is deliberately placed inside the investigation workflow.
For a new incident, IncidentIQ sends information such as the service, severity, error message, description, and incident context to the recall layer.
The application receives historical memories containing information such as:
- Incident ID
- Service
- Severity
- Root cause
- Resolution
- Runbook information
- Outcome
- Relevance
- Historical context
The investigation interface presents these memories alongside the current incident.
A simplified version of the recall workflow looks like this:
typescript
postJson("/api/hindsight/recall", incidentInput)
.then((data) => {
if (data.state === "ok" && data.results) {
setRecall({
phase: "ok",
results: data.results
});
}
});
Top comments (1)