Answer "what changed?" with the record
Reads the change history across AWS, Vercel, Cloudflare, Render and GitHub, and ranks the suspects by when they landed.
I want to do this: Did anything deploy or change config in the last two hours that could explain this latency? ## Setup (skip if Polylane is already set up) Read and follow https://polylane.com/auth.md for non-interactive signup and setup. Start by checking whether I am already signed in; reuse my account and workspace. If the CLI is missing, bootstrap it without starting the interactive wizard: curl -fsSL 'https://polylane.com/setup?ref=prompts' | bash -s -- --install-only Then follow the guide through email verification, workspace selection, source connections, and MCP authentication. Ask me for an email code or OAuth consent only when needed. Verify each step; report pending setup instead of claiming success from installation alone. ## How to work Over MCP: searchTools lists what this workspace exposes, with each tool's schema; call it first. runTool runs one tool, runCode chains several in one call and returns just the answer. search and execute cover the full Polylane REST API: threads, issues, investigations, autofixes, memories. From the terminal: the polylane CLI wraps the same API, with structured output and non-interactive flags everywhere. Reads always work. Write tools appear only if I have opted in, and every write is screened. ## Task: Answer "what changed?" with the record Steps: 1. Pull every change record in the window: deploys, config edits, infrastructure diffs 2. Include who or what triggered each one, from the provider event behind it 3. Rank the changes by blast-radius overlap with the failing service 4. Test the top suspects against the regression timing 5. Deliver the ranked list with each change's record and its likely mechanism Ground every claim in data you actually pulled: the query, the log line, the change record. If the data is inconclusive, say so. Ask me before anything that writes.
"Did anyone change anything?" Silence.
The answer exists, spread across deploy logs, cloud audit trails, and someone's terminal history. Mid-incident, nobody can assemble it, so the question just hangs in the war room.
- Change history scattered across five providers
- The confession arriving an hour into the incident
- Config drift that no deploy log ever mentions
One prompt, this much work. Every step on your real data.
- 1 Pull every change record in the window: deploys, config edits, infrastructure diffs
- 2 Include who or what triggered each one, from the provider event behind it
- 3 Rank the changes by blast-radius overlap with the failing service
- 4 Test the top suspects against the regression timing
- 5 Deliver the ranked list with each change's record and its likely mechanism
The question answers itself
Every change in the window, ranked by how plausibly it explains the symptom, with the records attached. Nobody has to confess: it's already written down.
What broke overnight?
“Triage everything that fired overnight: what was real, what was noise, and what's still open?” Root cause
“P99 on checkout-api doubled at 14:10. Find the cause and show the evidence.” Postmortem
“Write the postmortem for yesterday's incident: timeline, root cause, and the follow-ups.” First responder
“We're seeing 500s on api.example.com. Start an investigation and post findings to #incidents.” War-room brief
“Summarise the open incident for the exec channel: impact, cause so far, next steps.” Close the loop
“The incident is resolved. Draft the permanent fix and link the evidence.” Which release?
“Errors started around Tuesday. Which release introduced them?” Dedupe the pager
“Group last month's pages into distinct issues. How many were the same thing twice?” Audit the alerts
“Go through our alert rules: which ones fire the most, and which were ever real?”