[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2vtic089kgawk":3},{"_id":4,"slug":5,"title":6,"subtitle":7,"kind":8,"cards":9,"tags":58,"categories":60,"source":62,"lang":65,"author":66,"audioState":69,"stats":70,"publishedAt":73,"renderer":74},"6abbf33dca21c797c7e9e2a3","your-next-incident-shouldnt-start-from-zero-building-recall-8e9dd992","Your Next Incident Shouldn’t Start From Zero: Building Recall","An incident is resolved.","news",[10,13,18,23,28,33,38,43,48,53],{"headline":6,"body":11,"imageUrl":12,"sourceImageUrl":12},"An incident is resolved. The dashboard turns green. Someone writes a short summary, closes the ticket, and moves on.","https:\u002F\u002Fmedia2.dev.to\u002Fdynamic\u002Fimage\u002Fwidth=1200,height=627,fit=cover,gravity=auto,format=auto\u002Fhttps%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsimmk9d2n31gwdjiuz04.png",{"headline":14,"body":15,"imageUrl":16,"images":17},"A few weeks later, another engineer sees similar","A few weeks later, another engineer sees similar symptoms. They search old tickets, scroll through chat messages, and ask whether anyone remembers what worked last time.","\u002Fapi\u002Fmedia\u002Fposts\u002Fyour-next-incident-shouldnt-start-from-zero-building-recall-8e9dd992\u002F1.webp",{"local":16},{"headline":19,"body":20,"imageUrl":21,"images":22},"The team has dealt with the problem before","The team has dealt with the problem before. Finding that experience—and deciding whether it still applies—is the difficult part. That gap is what we set out to explore with Recall, our Incident Memory Command Center. We wanted an incident workspace that could carry useful experience from one investigation into the next: Describe the current problem Retrieve relevant historical incidents Use historical context alongside fresh evidence Record what actually happened Preserve failed attempts and lessons learned The difficult part is deciding how that history applies. Two incidents can look similar and still have different causes. A previous fix is a clue, not permission to repeat it. That distinction shaped how we built Recall. From Symptoms to a Working Hypothesis An investigation starts with the information an engineer already has:","\u002Fapi\u002Fmedia\u002Fposts\u002Fyour-next-incident-shouldnt-start-from-zero-building-recall-8e9dd992\u002F2.webp",{"local":21},{"headline":24,"body":25,"imageUrl":26,"images":27},"The backend saves the incident locally before requesting","The backend saves the incident locally before requesting an analysis. If a provider call fails, the incident still exists, allowing the engineer to return to it later.","\u002Fapi\u002Fmedia\u002Fposts\u002Fyour-next-incident-shouldnt-start-from-zero-building-recall-8e9dd992\u002F3.webp",{"local":26},{"headline":29,"body":30,"imageUrl":31,"images":32},"Recall then asks Hindsight for relevant historical context","Recall then asks Hindsight for relevant historical context and sends the current evidence and retrieved memories to a model through Groq. References to the historical sources used We deliberately frame the diagnosis as a hypothesis because the engineer still needs to test it.","\u002Fapi\u002Fmedia\u002Fposts\u002Fyour-next-incident-shouldnt-start-from-zero-building-recall-8e9dd992\u002F4.webp",{"local":31},{"headline":34,"body":35,"imageUrl":36,"images":37},"For example, a previous incident might suggest that","For example, a previous incident might suggest that a connection pool caused a service slowdown. That makes pool utilization worth checking; it does not establish that today's slowdown has the same cause. Recall does not execute infrastructure commands. Its role is to help an engineer decide what to investigate next. Why We Used Two Kinds of Storage Recall uses two storage systems for different purposes. SQLite holds the structured state of an investigation: It gives the application a concrete record to display and update. Hindsight makes previous incident information available for retrieval across investigations. When an engineer records evidence or an outcome, Recall can send a readable incident document to the memory bank.","\u002Fapi\u002Fmedia\u002Fposts\u002Fyour-next-incident-shouldnt-start-from-zero-building-recall-8e9dd992\u002F5.webp",{"local":36},{"headline":39,"body":40,"imageUrl":41,"images":42},"It also labels investigation updates as human-reported evidence","It also labels investigation updates as human-reported evidence, preserving the distinction between an observation and a model's interpretation. An investigation is more than its final fix. Knowing that a restart did not help can save the next engineer from repeating the same attempt without a reason. A Comparison View That Makes Memory Visible One feature we particularly wanted was a with-memory versus without-memory comparison. The application analyzes the same incident through two paths: Using current evidence alone Using current evidence together with retrieved historical memory The results appear side by side. This lets us inspect what memory actually contributed. Suggest a more specific check? Surface an earlier failed attempt? Change the suspected cause? Provide useful historical context? Sometimes there may be no useful history to retrieve. That is a meaningful result too.","\u002Fapi\u002Fmedia\u002Fposts\u002Fyour-next-incident-shouldnt-start-from-zero-building-recall-8e9dd992\u002F6.webp",{"local":41},{"headline":44,"body":45,"imageUrl":46,"images":47},"The comparison is an inspection tool, not a","The comparison is an inspection tool, not a benchmark proving that memory always produces a better answer. Model responses can vary, and a different answer is not automatically a more accurate one. Building Around Imperfect AI Responses A useful AI interface needs more than a well-written prompt.","\u002Fapi\u002Fmedia\u002Fposts\u002Fyour-next-incident-shouldnt-start-from-zero-building-recall-8e9dd992\u002F7.webp",{"local":46},{"headline":49,"body":50,"imageUrl":51,"images":52},"We use Pydantic to validate structured model responses","We use Pydantic to validate structured model responses before accepting them, and check cited source IDs against the memories actually supplied to the model. If a response fails validation or cites an unknown source, the application requests a correction. If that attempt also fails, it reports the failure instead of inventing a replacement diagnosis. Retrieved text and incident fields are treated as evidence rather than instructions. The application also flags selected risky action patterns for review.","\u002Fapi\u002Fmedia\u002Fposts\u002Fyour-next-incident-shouldnt-start-from-zero-building-recall-8e9dd992\u002F8.webp",{"local":51},{"headline":54,"body":55,"imageUrl":56,"images":57},"These checks can catch malformed output and certain","These checks can catch malformed output and certain unsupported claims, but they cannot prove that a diagnosis is correct. Verification still belongs in the incident workflow. The interface brings together: What the Project Taught Us The most useful lesson was that adding memory involves more than saving text. The system needs to preserve context: Which environment an incident affected Whether recovery was actually confirmed It also needs to handle failure honestly. A model response and a verified diagnosis are separate events.","\u002Fapi\u002Fmedia\u002Fposts\u002Fyour-next-incident-shouldnt-start-from-zero-building-recall-8e9dd992\u002F9.webp",{"local":56},[59],"dev",[61],"Technology",{"name":63,"url":64},"Dev.to","https:\u002F\u002Fdev.to\u002Fkarthik0757m\u002Fyour-next-incident-shouldnt-start-from-zero-building-recall-1393","en",{"handle":67,"displayName":68},"spots","Spots","queued",{"views":71,"likes":72,"saves":72,"shares":72,"completions":72,"opens":72,"skips":72,"depthSum":72},3,0,"2026-09-29T17:19:57.403Z","local"]