Investigate with Flight Recorder
Flight Recorder helps operators reconstruct governed activity around an agent, action, or incident. It brings decisions, runtime observations, process relationships, gaps, and integrity signals into one timeline.
When to use it
Use Flight Recorder to answer questions such as:
- What happened before and after this governance decision?
- Which agent, process, or tool was involved?
- Was the evidence path healthy during the incident window?
- Are there gaps or integrity warnings that limit the conclusion?
- How does the runtime timeline compare with the destination system?
Start with evidence health
Before reading individual events, check:
- collector health for the incident window;
- chain and checkpoint verification state;
- stale, detached, or degraded warnings;
- pipeline-gap events; and
- the exact time range and environment selected.
If the evidence path was degraded, include that limitation in the incident record instead of assuming the timeline is complete.
Read the timeline
Filter by the narrowest useful identifiers: organization, agent, action, process, event type, and time window. Then move outward to related events.
Look for:
- the original governance request and outcome;
- review or approval activity;
- process or parent-child relationships;
- collector state changes;
- shadow or rollback activity; and
- unexpected events immediately before or after the action.
Interpret integrity signals
A valid chain or checkpoint means the records evaluated by that check were internally consistent. A missing or failed check means you need to review the reason and reduce the strength of your conclusion.
Incident workflow
- Preserve the incident window and relevant identifiers.
- Confirm evidence health and note any gap.
- Locate the governance decision and reviewer activity.
- Trace related process and runtime events.
- Compare the Sernixa timeline with the application and destination system.
- Record what is confirmed, what is inferred, and what remains unknown.
- Apply remediation through the appropriate policy, credential, deployment, or recovery path.
Next step
For high-impact mutable actions, use Shadow execution before production. For day-to-day review and remediation, return to the Command Center.