AI & Automation
Workbench User Guide
Day-to-day use of Workbench: investigating with Paige, adding context, and reviewing and approving actions.
This guide covers day-to-day use of Workbench once you have a Workspace open: investigating with Paige, adding context to your investigation, reading the Context panel, the Timeline, and Topology, understanding Paige's confidence and reasoning, reviewing and approving actions, sharing a Workspace, and accessibility. For how to open Workbench for the first time and what a Workspace contains, see the PD Labs Quick Start Guide and Workbench Overview.
Investigating with Paige
Chat is where you talk directly with Paige, PagerDuty's SRE Agent. Ask a question in plain language, and Paige:
- Looks up relevant alerts, deploys, logs, and metrics from your connected tools.
- Walks you through its reasoning step by step as it works.
- Surfaces findings and, where appropriate, suggests a next question to ask.
Because chat is personal, you are free to explore your own line of questioning without affecting what teammates see. Anything worth keeping as part of the shared investigation is added to the Context panel or reflected on the Timeline.
Adding Context to Your Investigation
There are two ways to bring information into a Workspace:
- Slash commands: Typing
/in chat brings up commands that tell Paige to take an action, such as starting a focused investigation or pinning something to Context. Commands run quietly in the background; only Paige's confirmation appears in chat. - Add Context to Workspace: A dedicated dialog, opened from the Context panel's + Add button or by typing
/add, for attaching incidents, alerts, services, links, notes, or uploaded files to the Workspace. Adding something this way is a Workspace action, not a chat message, so it does not clutter your conversation.
Uploaded File Limits
Uploaded files can be images, PDFs, text, Markdown, CSV, JSON, or log files up to 25 MB. PagerDuty scans uploaded files before making them available in the Workspace.
Anything you add in chat is also added to the investigation. Use chat to steer the investigation.
The Context Panel
The Context panel, on the right side of the Workspace, holds everything gathered during the investigation, split into two types:
- References: Things you or a teammate attached — PagerDuty data, files, links, or notes.
- Artifacts: Things Paige produced, such as a draft post-incident review, shown above references.
You can add anything to Context with a single Add action, and everything in the panel is visible to every member of the Workspace.
Deep Investigation
What the Deep Investigation Is
The Deep Investigation is an asynchronous, long-running diagnostic agent for live incidents. Unlike a typical single-shot AI agent (prompt in, answer out), it runs for as long as an incident stays open, ingests new evidence as it arrives, can be steered by a responder mid-run, and produces a structured diagnosis with confidence and supporting evidence.
Overview
- Once an incident opens, you can manually start a run; it then keeps investigating as new signal (logs, metrics, transcript, code) arrives.
- Responders can send messages mid-investigation — ask a question, redirect it, or cancel it — without waiting for it to finish.
- Produces a terminal diagnosis: root cause, affected service, the suspected change, its confidence, remediation steps, and the evidence behind the call, not just a black-box answer.
Timeline
The Timeline view in Workbench is a shared, chronological record of the investigation — alerts, deploys, Paige's findings, actions taken by teammates, and Workspace activity such as teammates joining. You can filter it to show everything, only human activity, only Paige's activity, or an audit-log view.
Key Concepts
- Run: One execution of the Deep Investigation. You manually execute a run.
- Finding: A structured hypothesis from one investigator — probable cause, confidence, supporting evidence, and the alternatives considered.
- Evidence: An observation supporting a hypothesis, linked to a source and classified by directness (direct, from code, or circumstantial).
- Diagnosis: The reviewer's terminal synthesis across investigators. There is at most one diagnosis per run.
Note
There is a limit of 50 runs per Workspace with Deep Investigation.
Note
Topology runs automatically for each incident if GitHub code access has been set up.
Topology: AI-Generated Service Map
Topology shows a visual map of the services, datastores, queues, and external systems connected to the incident. It highlights which parts of the map Paige has actually investigated, and shows how confident Paige is in a given connection using line weight and style rather than a raw number. Selecting a node opens details such as its repository link, related services, and any suggested remediation. Where Paige has reached a conclusion about a node, the node is labeled clearly — for example, root cause, exonerated, ruled out, or still investigating.
You do not need to regenerate your Topology each time. Workbench saves your map and may update it as Topology runs.
Understanding Paige's Confidence and Reasoning
Workbench is built around showing its work rather than asserting an answer. A few principles carry through everywhere Paige presents a conclusion:
- No raw confidence scores: Instead of a percentage, Paige describes confidence in plain terms, such as how much direct versus circumstantial evidence supports a claim, or a plain-language label like "Probable cause" or "Undetermined."
- Evidence you can verify: Findings link back to the original source, such as the specific log query or dashboard, so you can check Paige's work yourself rather than take a citation on faith.
- Findings show their limits: A finding includes not just the claim and evidence, but the alternatives Paige considered and ruled out, and, deliberately, anything Paige did not get a chance to check.
- Color is never the only signal: Status and confidence are always paired with a label or icon, never conveyed by color alone.
Reviewing and Approving Actions
When Paige recommends a remediation step, it appears as an inline card for you to review — never a pop-up that interrupts your work. Depending on how significant the action is, Workbench may let you approve it with one click, or ask you to confirm you have reviewed the relevant evidence first before the approval unlocks. You can approve an action, deny it, or ask Paige to try something else. After PagerDuty takes an action, Paige follows up to confirm whether it actually resolved the issue.
Sharing and Collaborating
When a Workspace is opened for an incident, PagerDuty posts a link to join it in the incident's notes. This link is shareable — sharing a Workspace is as simple as copying it. Anyone in your organization who opens that link automatically joins the Workspace as a full member — there is no separate invite or approval step. When you copy a link, Workbench confirms who will be able to join.
- Artifacts and the Timeline are visible to every Workspace member; each member's chat with Paige remains private to them.
- New members get their own personal chat with Paige, and immediately see the existing shared Timeline, Topology, and Context.
- PagerDuty records every join and view to an activity log, retained for 90 days, so you can see who has looked at a Workspace and when.
- You can save individual messages, findings, and pieces of evidence to Context, copy them as a reference, comment on them, or send them elsewhere, including to Slack or directly into a PagerDuty incident's notes.
Invalid or Deleted Workspace Links
If a link is invalid or the Workspace has been deleted, Workbench shows a generic "Workspace Not Found" message rather than confirming which case applies, to avoid revealing whether a given Workspace exists.
Role-Based Permissions Not Yet Available
Role-based permissions, such as view-only access, are not yet available. Everyone who joins a Workspace today has full access to it.
Accessibility
Workbench is built for keyboard navigation and screen reader use, including announcements when Paige is actively working on an investigation, so the experience stays usable without a mouse or with assistive technology.