Forensics · Behavior diagnosis

Diagnose agent behavior

Classify what went wrong with deterministic checks first, cited evidence, and explicit open categories.

For: engineers investigating AI-assisted work, reviewers deciding what the evidence establishes, and team owners checking the same record across devices

What it does, and why it helps

The diagnosis evaluates eleven versioned behavior categories. Nine have deterministic checks; ambiguous assignment stays open because the default product makes no model call. Claims cite in-scope evidence ids, and hostile transcript instructions cannot widen that scope.

The pain. A generic 'agent failed' label cannot guide a remedy and invites hindsight bias.

The point of view. Name only the behavior the record supports and preserve counterevidence.

What gets easier. Separating stale guidance, a dropped constraint, a wrong revision, and a tool failure.

When it helps. After evidence and attribution are sufficient to explain a case.

Its limits. No record means unknown, not clean. Ambiguity remains partial under the USD 0 model default.

Where to find it

  • Desktop: AI incidents, open a case and the Diagnosis view.
  • Hosted: /team/agent-incidents, case Security section.
  • API: GET /api/ai-incidents/detail

When to use it

Classify a wrong-revision check

Situation. An AI-assisted change needs an answer that another reviewer can reproduce.

What you do. Open the case diagnosis after verification receipts are attached.

What you see. The verdict cites the tested revision and shipped revision and names the taxonomy version.

What it establishes. The category is reproducible without sending evidence to a model.

Before you start

Supported versions
RepoOps v0.3.1, verified against the 2026-09-17 completion worktree.
Where it runs
The local view needs a tracked repository. The team view needs a bound device and an authenticated team membership.
Permissions
Local evidence follows the repository's own access. Hosted reads are tenant and repository scoped before rows, counts, filters, or exports are built.
Connections
Local inspection works offline. Team delivery needs the device binding and repoops.ai; a failed delivery keeps its cursor and reports the failure.
Plan
Local deterministic analysis is available without a paid runner. Hosted compute, private runners, and model analysis are disabled by default and never silently substituted.

Configure it

  1. Resolve the case evidence and attribution first.

    This establishes the scope before any conclusion is computed.

  2. Run diagnosis and review every open category and citation.

    The receipt records the decision and the evidence ids it used.

SettingWhereA sensible choiceWhy it matters
ⓘ
To stop or undo
There is no model toggle in the default product; deterministic analysis can be left unused without changing records.

What you should see

A partial diagnosis

Configuration. Use a tracked repository and leave every unknown or disputed input in its real state.

Expect. Decided categories carry reasons and evidence while ambiguous assignment remains open.

Verify. analysis.ran is false, modelVersion is null, and unknown is not rendered as absent.

Data and cost

What is captured
Category verdicts, reason codes, taxonomy version, evidence pointers, counterevidence, and bounds state.
Who can see it
The team sees case-scoped verdict records; restricted source content stays behind grants.
How long it is kept
Deleted with the owning case unless a stricter team deletion occurs.
What leaves the machine
None for deterministic analysis. No model credential is approved by default.
What it costs
USD 0 per case by product decision.

When the result differs

SymptomLikely causeNext action
Every case is partial.One or more categories lack a deciding record, commonly ambiguous assignment or tool outcome.Open the named category reason; improve capture rather than treating partial as a failure.
Disable
Stop the relevant capture or prevention toggle in Settings; already recorded evidence remains a historical record.
Roll back
Restore the earlier package version or withdraw the disputed edge. Append the correction; do not rewrite the earlier decision.
Revoke access
Revoke the device or transcript grant. Later reads become restricted while identifiers and non-secret receipts remain auditable.
Delete
Delete the owning case or team through its deletion flow. Prevention groups also expire coherently after 365 days of inactivity.

Maintenance evidence

Feature id
behavior-diagnosis (spine leaf behavior-diagnosis)
Owner
Forensics runtime and public-story owners (LDG-0695 through LDG-0699, LDG-0722)
Supported product version
RepoOps v0.3.1
Last verified
2026-09-17
Example fixtures
Deterministic unit and integration fixtures cited by the source modules; external acceptance gates remain named separately.
Source references
lib/behavior-diagnosis.mjs, lib/behavior-taxonomy.json, website/lib/ai-incident-cases/diagnosis.ts, docs/benchmarks/behavior-corpus-results.json
Documentation review
Claims checked against the implementation and dated evidence. Unknown, disputed, restricted, not-run, and unavailable states are retained.
Video review
No licensed rendered story is published for this guide yet. The guide does not render a placeholder player.

Last updated