← Back to Support Center

Review Diagnosis findings and evidence

Review the saved investigation result, its evidence, and its run trace.

GuideLast verified Open Markdown version

Before you start

Intended audience

Responders who assess a completed or historical Diagnosis run.

Required permissions

You need permission to view the incident and its Diagnosis data.

Prerequisites

  • Open an incident with a saved Diagnosis result.

Procedure

Assess the finding

  1. Step 1 of 6

    Open the result

    Select Diagnosis. Find Investigation result.

  2. Step 2 of 6

    Identify the observation time

    Review the observation status and assessed time. If the result is labeled Historical snapshot, treat it as past scope, not current state.

  3. Step 3 of 6

    Use the review sequence

    Use this order: observation status → assessed time and scope → Evidence and checks → conclusion → suggested action, shown as Suggested fix.

Verify evidence and provenance

  1. Step 4 of 6

    Open checked evidence

    Select View checked evidence. You can also open Evidence and checks.

  2. Step 5 of 6

    Review supporting context

    Open Related signals and ruled out causes. Review what supports or weakens the conclusion.

  3. Step 6 of 6

    Review run provenance

    Open Run details. Review Raw local tool trace before you rely on an important claim.

You are done when…

You can trace each important finding to checked evidence and the local run that produced it.

Troubleshooting

The result is inconclusive.

Use Tool activity to find the missing source check, fix the local tool setup, and run a follow-up diagnosis.

A finding has no evidence.

Treat it as a hypothesis until a responder checks a source and records supporting evidence.

The result describes old scope.

Use the assessed time to confirm that the result covers old scope. Start a new run for current evidence.

A finding lacks adequate support.

Review Evidence and checks. Record missing evidence before accepting the recommendation.

Related articles