RCA as a Service · Runs inside your VPC

We deliver the root cause. Not the tooling to find it.

Onepane is RCA as a Service for enterprise IT operations. AI agents investigate every Sev1 inside your own VPC, on the monitoring you already own; our engineers sign off; and you receive the finished, evidence-linked root-cause report inside an agreed SLA. You pay for accepted RCAs, not seats.

The problem

Every enterprise has monitoring. Almost none have root cause.

After a Sev1, three engineers spend four hours reconstructing what happened across five tools, then someone spends another day writing the RCA the customer or the auditor is waiting on. That work is manual, late, and owned by whoever was on call.

We do that work. Agents run the investigation where your data lives. Humans sign the result. The document arrives on time, every time, and someone other than your team is answerable for it.

Definition

What is RCA as a Service?

RCA as a Service (RCAaaS) is a managed root-cause service: a provider runs the post-incident investigation on your existing telemetry and delivers a finished, evidence-linked root-cause report under SLA, instead of selling you another platform to staff. In the agentic era, AI agents do the investigation and humans stay accountable for the conclusion.

What you get

A document your customer, your auditor and your problem-review board will accept, plus the evidence trail behind every sentence.

What you don't do

Replace your monitoring, ship your logs to a vendor cloud, or hire people to run another investigation tool.

What you pay for

Services under coverage plus accepted RCAs. Never per seat, per host or per GB, that's the model that makes your observability vendor's incentives point the wrong way.

How it works

How does a managed RCA actually get delivered?

Full walkthrough
01

Deploy in your VPC. Terraform or Helm reference deployment. Connect the tools you already have, read-only, scoped, logged.

02

Map services to owners. We build the service-and-ownership map ourselves; we don't need your CMDB to be accurate.

03

Agents investigate each Sev1. Change history, topology, telemetry, tickets, the causal chain stated as trigger → propagation → failure, every claim linked to evidence.

04

Humans sign off. Our engineers review. Where evidence is insufficient we say so in writing rather than guess.

05

Artifacts land in your process. Root Cause Report, customer-facing version, evidence pack, structured problem record into ServiceNow or Jira, inside the SLA window.

Category

How is RCA as a Service different from the tools you've been shown?

Observability-vendor AI
Datadog, Dynatrace, Splunk
Chat-first investigation tools
assistants for engineers
Legacy AIOps
BigPanda, Moogsoft
Onepane, RCA as a Service
What you get Hints, inside their data A faster answer in chat Alerts grouped into one incident A finished, evidence-linked RCA document
Where it runs Their cloud Their cloud (SaaS) Their cloud Your VPC, no data egress
Estate coverage Only their vendor's data Cloud-native stacks Alert streams Datadog + Splunk + CloudWatch + Oracle + mainframe + change tickets
Who is accountable Your engineers Your engineers Your engineers Us, under SLA, with credits
Pricing basis Per host / per GB Per seat / per investigation Per event volume Per service under coverage + accepted RCAs
Budget it comes from Tooling Tooling Tooling Labour, the triage and RCA-authoring hours you already spend

Correlation tells you forty alerts are the same incident. It doesn't tell you which change caused it, who owns the failing service, or what to write in the RCA. Keep it, we run on top of it. Full comparison →

To be clear

What Onepane is not.

Not an observability or monitoring product. We run on top of the observability you already own.

Not an assistant for your engineers. We deliver a service outcome, the RCA, with an SLA, to your operations leader. We are not an "AI SRE" tool.

Not SaaS. The software deploys into your VPC. Nothing you consider production data leaves it.

Not auto-remediation. Evidence-backed decision support with human sign-off. We find and document the cause; you decide what to change.

Not per-seat software. A managed service, priced on coverage and accepted outcomes.

Transparency

We publish the numbers even when they don't flatter us.

Every account gets a monthly SLA Attainment Report: accuracy against your own historical RCAs, abstention rate, time-to-RCA against the committed window, and the share of RCAs delivered with zero human touch. In a category where the last generation oversold, transparency is the differentiator that compounds.

US-headquartered, San Diego and the San Francisco Bay Area. US-timezone support, US jurisdiction, source escrow and data portability available in contract.

FAQ

Questions operations leaders ask us.

What is RCA as a Service?

RCA as a Service is a managed root-cause service: a provider investigates each major incident on your existing telemetry, inside your environment, and delivers a finished, evidence-linked root-cause report under SLA. You buy the outcome and the accountability, not a platform to staff. Onepane is RCA as a Service for enterprise IT operations.

Does our data leave our environment?

No. Onepane deploys into your VPC. Logs, traces and change data stay in your account under your keys; no production data is sent to a third-party model API. Anything that does cross the boundary, service heartbeats, aggregate service metadata, is disclosed in writing before you sign.

Do we have to replace our monitoring?

No. We connect to Datadog, Splunk, CloudWatch, New Relic, your databases, your change system and your ITSM. A failed AIOps deployment is fine too, we run on top of it.

How is this different from the chat-first incident-investigation tools we've been shown?

Three ways. Those tools are SaaS, your telemetry goes to their cloud; we run in your VPC. They deliver an answer to an engineer in chat; we deliver a document your customer, auditor and problem-review board will accept. They sell a subscription; we sell an outcome with an SLA and credits attached. Different category, often the same first meeting.

What if the AI is wrong?

Abstention is a first-class output: "insufficient evidence, here is what's missing." Every claim links to the evidence behind it so you can check our work rather than trust it. Human sign-off is mandatory; liability is capped contractually.

How long until we get an RCA?

Inside a committed window measured from Sev1 closure, set during the replay, based on your telemetry coverage, and reported against every month. Miss it and we credit.

How do we start?

Send us your last 90 days of Sev1 tickets. In two weeks, at no cost, we show you what we would have found, how fast, and what the RCA document would have looked like, scored against what your team actually wrote.

Send us your last 90 days of Sev1s. We'll show you what we would have found.

Not a demo. A replay on your own incidents, scored against the RCA a human actually wrote. Two weeks, no cost.