Evidence
Every claim, one click from its proof
Decim shows the query it ran and the rows that came back, the log lines it matched, and the commit it correlated. If the evidence does not support a conclusion, it says so.
What gets collected
Scoped to the incident, redacted at the agent, and addressable by id so a diagnosis can cite it.
Logs
Matched lines from application, agent, scheduler and system logs, scoped to the incident window.
Read-only SQL
Results of queries drawn from an approved, row-capped catalogue. Nothing outside it executes.
Database rows
Reference and mapping tables read directly, so you see what the pipeline actually read.
Source code
The exact file, commit and line range that matters, retrieved on demand. Never the whole repository.
Deployments
Releases correlated against the incident window, with the changed files and the pull request.
Metrics and manifests
Throughput against a healthy baseline, and expected-versus-received file manifests.
Get started
Bring us a pipeline that broke last week
The fastest way to evaluate this is a real incident you already know the answer to. If Decim gets it wrong, that is a far more useful demo than one where it doesn't.