Enable automatic investigations
- Open a Kubernetes cluster or virtual machine.
- Open Settings and find Automatic investigations.
- Choose the minimum issue severity.
- Choose how the investigation may use write-capable tools.
- Add optional investigation instructions.
- For a Kubernetes cluster, configure namespace eligibility if needed.
- Save the settings.
Limit Kubernetes issue eligibility
Kubernetes targets provide three eligibility settings:
Use lowercase Kubernetes namespace names. You can provide up to 100 names in
each list.
These settings only decide which observed issues may start an automatic
investigation. They do not expand AgentK collection, Kubernetes RBAC, or tool
access. Configure AgentK namespace scope separately in Cluster Settings. See
Connect a Kubernetes cluster.
Virtual machine eligibility
Virtual-machine automatic investigations are target-wide. Severity is the only issue eligibility filter; Kubernetes namespace settings do not apply.Choose action safety
The saved action mode cannot grant more access than the target, connected agent, workspace role, and selected diagnostic tools already permit.- Diagnose only exposes no write tools.
- Ask before changes pauses for approval before a permitted write.
- Allow changes skips confirmation only when the target policy also allows it.
- Follow target settings inherits the target’s effective write policy.