groundcover Agent Mode
The AI that investigates your stack, from inside it
The more data you have, the harder it is to find what matters. groundcover has more data than any other platform. The Agent mode is built for exactly that.
.svg)
Investigate anything
Agent Mode runs on Amazon Bedrock, OpenAI ChatGPT, or Anthropic Claude inside your cloud. Prompts, logs, traces never leave. Compliance has never been easier.
Deeper data than any competitor
Built on eBPF, Agent Mode sees kernel-level telemetry: service dependencies, database connections, traffic patterns, without manual instrumentation.
Part of the investigation, not a detour
@mention Agent Mode and it picks up from your current context.
The only BYOC-native AI agent for observability
AI adoption inside engineering teams is blocked by compliance. The standard answer is to give a third-party your API key and let it fetch your production logs. That creates two actors handling your most sensitive data. groundcover's answer is architectural: the AI runs inside your account.
Agent Mode runs on Amazon Bedrock, Claude, or ChatGPT in your own cloud account, on your quota. Prompts, logs, traces, and results never leave your infrastructure. Nothing to configure, no security review required for a tool you already own.
Answer questions OTel alone cannot
groundcover deploys an eBPF sensor at the kernel, providing deep automatic telemetry that doesn't require developers to instrument anything. groundcover sees the complete picture of your infrastructure, not just the services someone remembered to trace.
Every signal is enriched with a cross-signal identifier at ingest. Agent mode connects the dots across logs, traces, metrics, and events automatically, inferring service purpose, dependencies, and topology from the data alone, without anyone building a map manually.
AI that lives in your investigation
groundcover Agent Mode is accessible from any page in the platform, or from your collaboration tools like Slack and Linear, via connectors. Spot something unusual? @mention Agent Mode and it continues from where you left off.
Agent Mode output creates first-class groundcover assets: dashboards, monitors, gcQL queries, and OTTL pipelines. Everything Agent Mode builds uses the same schema as the rest of the platform so outputs are immediately usable, modifiable, and observable. Every tool call is visible in the relevant product page.
Open-ended investigation, powered by gcQL
Most AI agents only activate when an alert fires. groundcover's Agent Mode supports open-ended investigation: questions without a pre-existing monitor, incident ticket, or known failure state. That covers the majority of day-to-day engineering work, not just on-call firefighting.
Agent Mode uses gcQL, groundcover's unified query language, to query logs, metrics, traces, and events through a single interface. It runs complex queries in parallel and pushes processing to the backend rather than pulling raw data into the context window, making responses faster and more accurate.
The first AI agent that keeps all your production data 100% in-house
Runs on your cloud account with no data transfer to audit, no third party to trust, and no compliance conversation required
Compliant with GDPR, CCPA, and the strictest enterprise data residency requirements by architecture, not by policy
FAQs
How is the groundcover AI Agent different from other AI observability tools?
Most AI features in observability connect to your telemetry through APIs and send it to an external LLM, meaning your production logs, traces, prompts, and often cloud credentials are shared with multiple third parties. groundcover Agent Mode is different. It runs on the LLM service in your own cloud account and analyzes telemetry where it already resides.
Why does eBPF matter for an AI agent?
An AI agent is only as good as the data it can see. Tools built on OpenTelemetry can only answer questions about services that were manually instrumented, which is never the complete picture. groundcover deploys an eBPF sensor at the kernel, capturing automatic telemetry across every service, database connection, and network call without any developer instrumentation.
Can the agent investigate issues that don't have an existing alert?
Yes. Most AI agents in observability are incident-triggered and only activate when an alert fires. groundcover's agent supports open-ended investigation: questions without a pre-existing monitor, incident ticket, or known failure state.
How does the agent understand our specific services and infrastructure?
Every signal groundcover collects, including logs, traces, metrics, and events, is enriched with a cross-signal identifier at ingest. The agent walks through them and connects the dots automatically.
What is gcQL and why does it matter?
GCQL is groundcover's unified query language, a single interface for querying logs, metrics, traces, events, entities, and monitors. Most observability platforms accumulate a different query model for each data type.
What does Agent Mode actually produce?
Agent Mode output creates first-class groundcover assets: dashboards, monitors, gcQL queries, and OTTL pipelines. Everything Agent Mode builds uses the same schema as the rest of the platform.