By situation

Investigating production issues

Support and developers ask why something is broken for a customer, and AppThentic investigates with the business logic, the code and your logs.

“Customer XYZ sees no products.” Today that sentence goes to a senior engineer, who stops what they are doing to find out why. With AppThentic, support asks first.

What AppThentic investigates with

Investigations are something you switch on. When you enable them and grant access, AppThentic uses all four sources below. Without them, it answers from the code and Organization Memory alone.

  • Organization Memory: the business rules involved, and why they exist.
  • The code: which application and services serve that screen, and what they do.
  • Your logs and observability data, when you grant access: which API was called, what it returned, and which errors were raised.
  • Read-only data access, where you grant it: the customer’s actual records.

The business logic is what makes the difference. A log shows that the product list came back empty. Organization Memory knows that products are hidden for accounts whose KYC has expired, and why Risk decided that.

How an investigation runs

  1. Someone describes the problem in plain language.
  2. AppThentic identifies the customer, the application and the services involved.
  3. It reads the relevant logs: the API calls, their responses and their errors.
  4. It works out whether the cause is data, API behaviour, configuration or a business rule doing exactly what it was designed to do.
  5. It explains the cause, with the evidence, in terms that fit the person asking.

One cause, explained two ways

Support sees: This customer’s KYC expired on 2 Oct, so their account is restricted and products are hidden. Ask them to renew KYC from their profile. No engineering action needed.

A developer sees: GET /catalog returned 200 with an empty list. CatalogService filters on kyc_status = ACTIVE; this account is EXPIRED. The rule is approved by the Head of Risk (21 Jun 2026).

Known issues are answered from memory

When AppThentic has already investigated the same problem and the cause still holds, it answers from that investigation instead of running a new one. That is faster, and it costs nothing in AI inference. If the system has changed since, or the earlier cause no longer fits, it investigates again.

Access

An investigation only uses what the person asking is authorized to see, and a stored investigation is shown only to people allowed to see what it was built from. Log and data access is read-only, off until you enable it, and limited to what you connect. See Access and audit trail.

Esc