Concepts

Assessment and reports

How hypotheses are assessed, how a report reaches its conclusion, what the report contains, and how human resolutions are recorded separately.

v0.1.0 · experimentalPython 3.11+Updated 2026-10-05

What makes an explanation testable

FieldPurpose
id, statementA stable identity and a falsifiable explanation.
causal_pathEntities in the incident graph, starting where the fault originates.
evidence_neededRegistered query IDs whose facts cover the predictions and falsifiers.
predictionsFacts expected if the explanation holds.
falsifiersFacts that would contradict it.

Assessment

A hypothesis is supported only if every prediction is supported by a usable fact and no falsifier holds. Contradiction takes precedence. Missing, conflicting or degraded facts leave it unresolved.

StateMeaning
supportedThe facts agree with it. This is evidence support, not causal proof.
contradictedA prediction fails, or a falsifier holds.
unresolvedThe facts are missing, degraded, conflicting or not enough to decide.

How a report reaches its conclusion

A diagnosis requires the supported explanations to agree on one root cause. A Kubernetes resource that hosts a service counts as that service. If two supported explanations name different roots, the conclusion is insufficient_evidence and both are listed: Lumis does not invent a ranking. With no usable evidence, the conclusion is insufficient_evidence or requires_human_expert.

What the report contains

FieldContent
contextThe incident, scoped graph, queries and evidence.
findingsEach check's finding with its assessment.
assessmentsEach candidate hypothesis and its state.
receiptsRedacted records of every query and tool call.
suggestionsTentative, text-only next steps for a person.
unresolved_questionsWhat the evidence could not settle, and why candidates were dropped.
routedeterministic, agent or human.
conclusionsupported_diagnosis, insufficient_evidence or requires_human_expert.
stop_reasonWhy the investigation ended.
metricsModel requests, tokens, tool attempts, evidence queries and probes.
truth_state, requires_human_reviewAlways unconfirmed_hypothesis and true.

The report does not store the model's raw reasoning or the full provider conversation. Callers that need it for evaluation can read PydanticInvestigator.messages in memory.

Audit records and human resolutions

IncidentStore.save(report) writes the report, evidence and receipts to SQLite in one transaction. Saving the same incident ID twice is refused. After a person has dealt with the incident, they can append a separate resolution record:

json
{
  "id": "review-001",
  "incident_id": "api-001",
  "reviewer": "operator",
  "recorded_at": "2026-10-05T12:00:00Z",
  "summary": "Restarted the API after the report; health checks recovered.",
  "applied_change": "Manual restart by the on-call engineer; not executed by Lumis.",
  "outcome": "resolved",
  "evidence_references": []
}
bash
lumis record-resolution --store incidents.sqlite --resolution resolution.json --confirm

Outcomes are resolved, not_resolved or inconclusive. A resolution never changes the diagnosis, executes anything or creates a new rule.

Source: Incident investigation ↗ in the SDK repository.