Azure-first incident investigation

Find the change
that broke production. Fast.

ChangeOps turns Azure's scattered change history into a ranked, evidence-backed shortlist — so on-call goes from 40 minutes of portal-hopping to under five.

Azure today AWS & GCP next AI summaries later
// concept
RANKED EVIDENCE3 suspects · 14:00–14:10Z
#1 92 HIGH deterministic
Microsoft.Web/sites · app config updated
deploy-sp@prod · 4m before alert · Activity Log ↔ Resource Graph
#2
AKS · node pool image upgrade
AKS audit log · heuristic
MED71
#3
Network · NSG rule changed
Activity Log
LOW54

What ChangeOps is for

Triage in minutes

Find the change behind a live incident — under five minutes, no portal-hopping.

Evidence packs

Timestamped, attributed, confidence-labelled — and exportable anywhere.

Postmortems & audits

Blameless postmortems, compliance audits, and vendor escalations — in one export.

How it works

From a noisy cloud to a ranked answer

Connect · collect · evaluate · rank — then delivered where you work.

01 · CONNECT

Connect your Azure

Securely link subscriptions. Read-only.

Azure now · AWS & GCP next
02 · COLLECT

Collect change evidence

Every change in the incident window.

Multi-source · deterministic
03 · CORRELATE

Engines evaluate

Correlate, score & label confidence honestly.

+ AI summary later
04 · RANK

Ranked evidence pack

Most likely change first — attributed.

Source-attributed · exportable
EXPORT & NOTIFY
Evidence pack
PDF · JSON · CSV
Slackdelivered
Microsoft Teamsdelivered
Jiraticket
PDF / CSV exportsaved
incident.iosoon
PagerDutysoon

Under the hood

Built like an evidence engine — not a dashboard

The substance that makes the ranking trustworthy.

DETERMINISTIC

Joined on correlationId

Control-plane changes correlate deterministically, with a bounded time-window fallback. HIGH only when sources agree.

HONEST

Calibrated confidence

AKS audit evidence is heuristic and labelled MED — never dressed up as certainty. The engineer makes the call.

TRACEABLE

Source-attributed

Every ranked item keeps its raw Azure provenance, so you can drill straight back into the original evidence.

ISOLATED

Tenant-safe & read-only

Workload-identity access, no stored credentials, per-tenant row-level isolation. We never store your raw logs.

Where we're going

Azure-first by design — not Azure-only forever

NOW · 2027

Azure, done deeply

Activity Log, Resource Graph & AKS audit. Ranked evidence, honest confidence, export to Slack / Teams / Jira.

LATER

AI on the deterministic core

AI reads the trusted evidence pack to summarize and suggest next checks — never replacing the engine.