microtica agents
Docs menu

Watches

A watch is a standing commitment: you’re doing something temporary or risky, and the Investigator keeps an eye on it until it’s resolved. It holds your own words — verbatim — with a review-by date, and where your words name something it can measure (an RDS instance’s status, an EC2 state, a CloudWatch metric threshold), it compiles cheap machine checks and runs them on a cadence, every six hours by default. When there’s nothing to measure, it simply holds the date and checks in when it arrives.

Create a watch

Tell the Investigator during any session:

I’m stopping staging-db over the weekend — keep an eye on it until I restore it.

It arms the watch and confirms back what it’s holding and until when. For a summon that should do nothing but arm a watch, type /watch followed by the intent in the console composer — that turn arms the watch and takes no other action. The Investigator also sets watches on its own initiative: when it would otherwise promise to “check back on that”, it arms a watch instead, because a watch is a commitment that actually gets checked. Watches are scoped to what the session could already see — a watch never widens the Investigator’s reach. An organization can hold up to 50 armed watches.

Where watches live

Armed watches sit in the inbox under On the horizon, soonest review date first, each with a countdown chip and a “checked 2h ago” heartbeat when it has machine checks. Select one to see the full picture: your intent quoted back, the horizon, exactly what it’s checking, and the recent check history.

The On the horizon section listing armed watches with countdown chips, and a watch detail pane showing the intent, horizon, and checks Armed watches on the horizon — the detail pane quotes your intent and shows what’s being checked.

When a watch fires

Two things can fire a watch:

  • The review date arrives. The Investigator takes a quick look at the current state and nudges you: where things stand, and what you said you’d do about it. It doesn’t escalate on its own — Deepen is there if you want the full look.
  • A check trips. The Investigator opens a real investigation with the evidence in hand.

Either way, a case opens, the watch moves to Needs you with a Fired — check now chip, and the case post carries a line saying which watch you set triggered it, and when.

Verify, then close

A fired watch never closes on your word alone — it verifies first. Press I fixed it — check (on the Slack post, the inbox row, or the watch detail) and the Investigator re-runs the checks right then. If the condition is gone, the watch resolves with a receipt: “Checked again — back to normal. Closing this watch.” If it’s still firing, it says exactly what it’s still seeing and the watch stays open.

A deadline-only watch has nothing to re-check, so its button just acknowledges and closes: Done in the console, Done — close it in Slack.

If a check can’t run at all — credentials, an unsupported scope — the watch lands in Needs you as Blocked, with the reason.

Dismiss a watch

If a watch no longer matters, press Dismiss in its detail pane, or the dismiss control on the row (E works too). Dismissing removes it for good — unlike case archiving, there’s no undo.

Next: Redirect a running investigation