Skip to main content

Snapshot Explained

A snapshot is Agent911’s core output: a unified, point-in-time picture of your agent system’s reliability state. It’s designed to answer one question:
“What is happening right now, and what should I do next?”

Anatomy of a Snapshot

A snapshot has five sections:

① Health Summary

The current liveness and behavioral state of each monitored agent:
Each agent shows:
  • HEALTHY — active, progressing, heartbeat current
  • DEGRADED — running but showing risk signals
  • STALLED — no progress detected within threshold
  • OFFLINE — no signal received

② Anomaly Correlation

Agent911 doesn’t just list raw alerts — it groups them into correlated events:
Correlated events reduce noise. Three separate alerts about the same underlying issue appear as one event, not three things to investigate separately.

③ Governance Status

If SphinxGate is configured, this section shows current routing policy state:
If SphinxGate is not configured, this section shows NOT CONFIGURED.

④ Recovery Readiness

If Lazarus is configured, this section shows your current backup posture:
If Lazarus reports a surface as NOT VERIFIED, resolve it before attempting recovery. Unverified backups may not restore cleanly.
Based on the anomaly correlation, Agent911 recommends the appropriate recovery playbook:

Snapshot Freshness

Snapshots reflect system state at the moment they’re generated. Signals older than 5 minutes are marked [STALE]. For incidents in progress, regenerate frequently:

Exporting Snapshots

Snapshots can be exported as proof bundles for compliance, post-incident review, or support escalation:
A proof bundle includes:
  • The snapshot JSON
  • All referenced log excerpts
  • Correlation analysis output
  • Lazarus readiness report (if configured)
  • Governance audit entries (if SphinxGate is configured)

Snapshot via CLI

Next Steps

Agent911 Overview

Back to the full Agent911 feature overview.

Lazarus

Understand and improve your recovery readiness score.