# Triage everything that fired overnight

Sorts the overnight alerts from Datadog, Sentry and Better Stack into three lists (real, noise, still open), each with the query behind it.

## The prompt

```
I want to do this: Triage everything that fired overnight: what was real, what was noise, and what's still open?

## Setup (skip if Polylane is already set up)

Read and follow https://polylane.com/auth.md for non-interactive signup and setup. Start by checking whether I am already signed in; reuse my account and workspace.

If the CLI is missing, bootstrap it without starting the interactive wizard:

curl -fsSL 'https://polylane.com/setup?ref=prompts' | bash -s -- --install-only

Then follow the guide through email verification, workspace selection, source connections, and MCP authentication. Ask me for an email code or OAuth consent only when needed. Verify each step; report pending setup instead of claiming success from installation alone.

## How to work

Over MCP: searchTools lists what this workspace exposes, with each tool's schema; call it first. runTool runs one tool, runCode chains several in one call and returns just the answer. search and execute cover the full Polylane REST API: threads, issues, investigations, autofixes, memories.
From the terminal: the polylane CLI wraps the same API, with structured output and non-interactive flags everywhere.
Reads always work. Write tools appear only if I have opted in, and every write is screened.

## Task: Triage everything that fired overnight

Steps:
1. Pull every issue and alert that fired in the window
2. Group duplicates and storm re-fires into their underlying issues
3. For each issue, read the metric or log series behind it and judge it against normal
4. Split the pile: confirmed incidents, noise with the reasoning, still-open questions
5. Deliver the triage with links to each issue and the queries behind each verdict

Ground every claim in data you actually pulled: the query, the log line, the change record. If the data is inconclusive, say so. Ask me before anything that writes.
```

## What it replaces

**Forty alerts, four tabs, first coffee.** The overnight pile mixes one real incident with thirty-nine echoes of it. Sorting them means opening each alert, finding its query, and reading the graph, forty times.

- Reading the same alert storm one page at a time
- The real issue buried under its own duplicates
- "Is this still happening?" checked by hand, per alert

## What the agent does

1. Pull every issue and alert that fired in the window
2. Group duplicates and storm re-fires into their underlying issues
3. For each issue, read the metric or log series behind it and judge it against normal
4. Split the pile: confirmed incidents, noise with the reasoning, still-open questions
5. Deliver the triage with links to each issue and the queries behind each verdict

## What you get

**The pile becomes three short lists** Real, noise, and needs-a-human, each with the query behind it. The first hour of the day goes to the one issue that deserves it.

Every prompt: https://polylane.com/prompts/

Get started with one command: `curl -fsSL https://polylane.com/setup | bash` installs the CLI, connects your coding agents, and creates the account.
