At a glance
Version: 10.1 | Last updated: 2026-09-28
Bluebox is built around a small set of concepts. Understanding them gives you a complete mental model of how the product works.
Findings
Bluebox continuously monitors your connected environment and surfaces issues as they occur, mapped to your services and codebase. See Findings for how to read and act on them.
Environment
The Environment page shows every service and application Bluebox is watching, with traffic, error rate, and response time for each. Use it to understand your service topology at a glance, spot anomalies before they become findings, and navigate directly to the services most relevant to an open investigation. See Environment for how to read and filter the list.
Investigations
An investigation works a problem end-to-end: forming and testing hypotheses, assembling evidence from your live telemetry, and producing an evidence-backed root-cause report. See Investigations for how to start one and what you get.
Approvals
Some actions Bluebox proposes need your explicit sign-off before Bluebox runs them—for example, an action that can't be undone. When this happens, Bluebox pauses and shows you what it wants to do and why; you approve to let it proceed, or deny with guidance so it can try a different approach.
The workspace owner sees a History tab alongside the active queue, listing every approval that has already been approved, denied, or expired unanswered, along with who decided it and when. This history tab is visible to the workspace owner only—other members see only the active queue.
Routines
A routine runs an agent on a schedule instead of waiting for you to ask. See Routines for how to create, schedule, and manage them.
Connections
Connections wire Bluebox to the services it works with—AWS DevOps Agent, Azure SRE Agent, and Kiro. A connection holds the credentials and configuration Bluebox needs to call that service on your behalf. Once set up, any member you share it with can invoke its tools without managing credentials themselves. See Connections for how to set them up, manage access, and share them with your workspace.
Workspaces
A workspace is your shared environment in Bluebox—everything (findings, investigations, connections) belongs to one. See Workspaces for roles, membership, defaults, and sharing.
Chat
Chat is your direct line to Bluebox—ask anything, track long-running tasks, and pick up past conversations where you left off. See Chat for how conversations work and how to manage tasks in progress.
Bluebox CLI
Query Bluebox, run setup, and interact with your workspace directly from the terminal. Use it standalone or alongside your coding agent in Claude Code or Kiro.
The most useful command to know:
bluebox ask "<question>"
Ask anything: what the top active findings are, what changed in the last deploy, whether a specific service is behaving normally. Bluebox queries your live observability data and streams the answer back, so it works as well piped into other tools as it does read directly in the terminal. You can also ask about Bluebox itself: its concepts, setup, or how it handles your data.
Each answer ends with an Evidence section: what it queried to answer, and where the data was thin or missing. The Evidence stays with the answer: when you reopen the conversation later, it appears in the history beneath the answer it belongs to.
See the CLI Reference for more information.
Proactive use
Bluebox isn't only useful when something has gone wrong. Before writing code for a new feature, refactoring a service, or deciding where to focus effort, you can ask Bluebox what your production system looks like right now.
bluebox ask "which endpoints in the payments service have the highest p99 latency"
bluebox ask "what are the most common errors in the last 7 days"
bluebox ask "is the checkout flow behaving normally compared to last week"
The answers draw from your live telemetry (real traffic patterns, real error rates, real service dependencies), not your mental model of the code. Paste that output into your coding agent and it writes to the system as it is. See How it works for patterns that combine production insights with investigations and coding agent handoffs.
Share links to your work
Every page in Bluebox carries your workspace in its address, so the link in your browser bar is always safe to bookmark or share. Open a saved link later, or send it to a teammate, and it reopens the exact investigation, task, or view in the right workspace, even if you work across more than one. Investigation, task, and overview pages have a Copy link button for this.
Opening a shared link never grants access on its own: you still see only what you're a member of and what has been shared with you. If a link points to a workspace you're not in yet, Bluebox offers Request access instead of a dead end, and a workspace owner can then approve or decline your request. While you wait on the request page, Bluebox checks for approval on its own and moves you into the workspace as soon as an owner approves, with no need to reload.