We deliver the root cause. Not the tooling to find it.
Onepane is RCA as a Service for enterprise IT operations. AI agents investigate every Sev1 inside your own VPC, on the monitoring you already own; our engineers sign off; and you receive the finished, evidence-linked root-cause report inside an agreed SLA. You pay for accepted RCAs, not seats.
Every enterprise has monitoring. Almost none have root cause.
After a Sev1, three engineers spend four hours reconstructing what happened across five tools, then someone spends another day writing the RCA the customer or the auditor is waiting on. That work is manual, late, and owned by whoever was on call.
We do that work. Agents run the investigation where your data lives. Humans sign the result. The document arrives on time, every time, and someone other than your team is answerable for it.
What is RCA as a Service?
RCA as a Service (RCAaaS) is a managed root-cause service: a provider runs the post-incident investigation on your existing telemetry and delivers a finished, evidence-linked root-cause report under SLA, instead of selling you another platform to staff. In the agentic era, AI agents do the investigation and humans stay accountable for the conclusion.
What you get
A document your customer, your auditor and your problem-review board will accept, plus the evidence trail behind every sentence.
What you don't do
Replace your monitoring, ship your logs to a vendor cloud, or hire people to run another investigation tool.
What you pay for
Services under coverage plus accepted RCAs. Never per seat, per host or per GB, that's the model that makes your observability vendor's incentives point the wrong way.
Four things no tool in your stack does.
Deploy in your VPC. Terraform or Helm reference deployment. Connect the tools you already have, read-only, scoped, logged.
Map services to owners. We build the service-and-ownership map ourselves; we don't need your CMDB to be accurate.
Agents investigate each Sev1. Change history, topology, telemetry, tickets, the causal chain stated as trigger → propagation → failure, every claim linked to evidence.
Humans sign off. Our engineers review. Where evidence is insufficient we say so in writing rather than guess.
Artifacts land in your process. Root Cause Report, customer-facing version, evidence pack, structured problem record into ServiceNow or Jira, inside the SLA window.
A chat answer is not a deliverable. A document is.
Every accepted RCA ships as a suite of artifacts written for the people who actually need them:
How is RCA as a Service different from the tools you've been shown?
| Observability-vendor AI Datadog, Dynatrace, Splunk | Chat-first investigation tools assistants for engineers | Legacy AIOps BigPanda, Moogsoft | Onepane, RCA as a Service | |
|---|---|---|---|---|
| What you get | Hints, inside their data | A faster answer in chat | Alerts grouped into one incident | A finished, evidence-linked RCA document |
| Where it runs | Their cloud | Their cloud (SaaS) | Their cloud | Your VPC, no data egress |
| Estate coverage | Only their vendor's data | Cloud-native stacks | Alert streams | Datadog + Splunk + CloudWatch + Oracle + mainframe + change tickets |
| Who is accountable | Your engineers | Your engineers | Your engineers | Us, under SLA, with credits |
| Pricing basis | Per host / per GB | Per seat / per investigation | Per event volume | Per service under coverage + accepted RCAs |
| Budget it comes from | Tooling | Tooling | Tooling | Labour, the triage and RCA-authoring hours you already spend |
Correlation tells you forty alerts are the same incident. It doesn't tell you which change caused it, who owns the failing service, or what to write in the RCA. Keep it, we run on top of it. Full comparison →
What Onepane is not.
Not an observability or monitoring product. We run on top of the observability you already own.
Not an assistant for your engineers. We deliver a service outcome, the RCA, with an SLA, to your operations leader. We are not an "AI SRE" tool.
Not SaaS. The software deploys into your VPC. Nothing you consider production data leaves it.
Not auto-remediation. Evidence-backed decision support with human sign-off. We find and document the cause; you decide what to change.
Not per-seat software. A managed service, priced on coverage and accepted outcomes.
Built for teams that owe someone an RCA.
B2B software & digital infrastructure
You owe enterprise customers a written RCA in 3–5 business days after a Sev1. Three monitoring stacks from three acquisitions, no single service map.
For SaaS teams →Banks, insurers, health systems, utilities
Mainframe + Oracle + cloud. Your data can't leave your environment, which disqualifies every SaaS alternative before evaluation starts. Ours doesn't ask it to.
For regulated estates →MSPs and MSSPs
On a fixed-price managed contract, every L1/L2 hour you don't spend is margin. White-label RCA under your brand, inside your SLA, deployable inside regulated clients' environments.
For MSPs →We publish the numbers even when they don't flatter us.
Every account gets a monthly SLA Attainment Report: accuracy against your own historical RCAs, abstention rate, time-to-RCA against the committed window, and the share of RCAs delivered with zero human touch. In a category where the last generation oversold, transparency is the differentiator that compounds.
US-headquartered, San Diego and the San Francisco Bay Area. US-timezone support, US jurisdiction, source escrow and data portability available in contract.
Questions operations leaders ask us.
What is RCA as a Service?
RCA as a Service is a managed root-cause service: a provider investigates each major incident on your existing telemetry, inside your environment, and delivers a finished, evidence-linked root-cause report under SLA. You buy the outcome and the accountability, not a platform to staff. Onepane is RCA as a Service for enterprise IT operations.
Does our data leave our environment?
No. Onepane deploys into your VPC. Logs, traces and change data stay in your account under your keys; no production data is sent to a third-party model API. Anything that does cross the boundary, service heartbeats, aggregate service metadata, is disclosed in writing before you sign.
Do we have to replace our monitoring?
No. We connect to Datadog, Splunk, CloudWatch, New Relic, your databases, your change system and your ITSM. A failed AIOps deployment is fine too, we run on top of it.
How is this different from the chat-first incident-investigation tools we've been shown?
Three ways. Those tools are SaaS, your telemetry goes to their cloud; we run in your VPC. They deliver an answer to an engineer in chat; we deliver a document your customer, auditor and problem-review board will accept. They sell a subscription; we sell an outcome with an SLA and credits attached. Different category, often the same first meeting.
What if the AI is wrong?
Abstention is a first-class output: "insufficient evidence, here is what's missing." Every claim links to the evidence behind it so you can check our work rather than trust it. Human sign-off is mandatory; liability is capped contractually.
How long until we get an RCA?
Inside a committed window measured from Sev1 closure, set during the replay, based on your telemetry coverage, and reported against every month. Miss it and we credit.
How do we start?
Send us your last 90 days of Sev1 tickets. In two weeks, at no cost, we show you what we would have found, how fast, and what the RCA document would have looked like, scored against what your team actually wrote.
Send us your last 90 days of Sev1s. We'll show you what we would have found.
Not a demo. A replay on your own incidents, scored against the RCA a human actually wrote. Two weeks, no cost.