Skip to content

Analysis Workspaces

An Analysis Workspace combines metric panels from multiple related resources on one canvas. Operators can compare operational state within a shared time range, inspect evidence during an incident, and present the same saved layout without maintaining a separate dashboard copy.

Analysis Workspaces are included with Enterprise and do not require a separate feature entitlement. Access to both the workspace and every source resource is nevertheless checked again whenever content is loaded, queried, or saved.

Find a workspace

Select Analysis Workspaces from the top navigation to see the workspaces available to the current user. Each card summarizes its description, page count, panel count, readable related-resource count, and a preview of resource names.

From a resource Monitor, Manage, or Edit screen, select Related Workspaces to filter the index to workspaces that directly contain a panel from that resource. This filter does not expand through the relation graph. Clear the filter to return to the complete workspace list.

Create a workspace

  1. Select Create workspace.
  2. Enter a recognizable name and a description of its purpose, incident context, or ownership scope.
  3. Add pages, sections, and panels after the workspace is created.

A useful description is recommended because names alone become difficult to distinguish as the workspace inventory grows.

Share a workspace

New workspaces are created as Private, accessible only to the owner and global administrators. Open Sharing in the workspace toolbar and add a user or group to change it to Shared. Shared does not mean public or anonymous access; only the explicitly listed subjects can access the workspace.

Every listed subject can view the workspace. Editing and presentation permissions are granted separately for each subject. Removing every subject and saving returns the workspace to Private.

Only the workspace owner and global administrators can change sharing. Finish layout editing and save any pending changes before opening sharing settings.

Organize pages and sections

A workspace can have multiple pages. Each page contains ordered sections whose title and description provide context such as Service health, Database latency, or Host resources.

Select Edit layout to:

  • add, duplicate, rename, reorder, or delete pages;
  • add, edit, reorder, or delete sections;
  • add, move, resize, or delete panels; and
  • drag panels within a section or between sections.

Layouts are stored on a canonical 12-column grid and project responsively to the available canvas. Drag the lower-right resize handle diagonally to change both panel width and chart height. Controls that expose keyboard instructions can be used instead of pointer dragging.

Time controls and automatic refresh pause while editing so a draft does not move underneath the operator. Select Save when finished. If another user saved a newer version first, follow the conflict prompt to reload the latest document or reapply the current draft.

In edit mode, activate the empty panel slot at the end of a section to open the related widget catalog.

  1. Select the starting plugin resource.
  2. Enable related resources only when they are needed.
  3. Narrow the list by search text, panel type, capability, or source section.
  4. Select one or more panels and apply the selection.

The catalog initially shows panels from the selected plugin resource. When related resources are included, it also follows approved resource relations and metric or log-source links to resources the current user may read.

Unloaded plugins, disabled resource interfaces, and unreadable configurations are omitted. A temporarily unhealthy resource can remain available so its historical metrics and incident evidence can still be investigated. A source panel already present on the page is not added twice.

Explore time ranges

Analysis Workspaces use the same time-range controls as plugin metric dashboards.

  • A live from ~ now range refreshes metrics on the current page at the selected interval.
  • A fixed from ~ to range pauses automatic refresh so investigation data does not move.
  • Previous and next window navigation, zoom, calendar selection, and return to live are available.
  • Drag across a timeseries chart to zoom into an absolute time range.
  • Personal chart preferences for synchronized hover, series summaries, point markers, latest-sample emphasis, and query step apply alongside system chart rendering policies.

Automatic refresh stopping in a fixed window is expected. Return to a live range to follow current data again.

Present a workspace

Presentation uses the saved pages and layout directly; it does not maintain a second fullscreen dashboard configuration.

  1. In the page controls, turn presentation inclusion on or off for each page. New pages are included by default, and presentation follows page order.
  2. Choose Manual, 30 seconds, 1 minute, or 1 minute 30 seconds for page rotation.
  3. Save the workspace and select Present.

Presentation keeps the time range currently displayed in the workspace. In a live range, metric refresh and page rotation run independently. Selecting a fixed range or dragging a chart to zoom pauses both automatic refresh and page rotation for investigation. Expanding a panel or interacting with time controls pauses page rotation only; live metric refresh continues.

If the browser denies fullscreen, presentation continues in the current window. The top controls hide after inactivity so the chart canvas can use the top of the viewport. Move the pointer or navigate with the keyboard to reveal previous, next, pause, refresh, and exit controls.

Query RCA evidence

RCA tools collect evidence using the resources and time range on the active page. A selected chart point can serve as the anchor; otherwise the current query range is used.

An evidence query combines:

  • stored alert and anomaly events;
  • plugin diagnostic history;
  • resource logs within the allowed bounds; and
  • readable resources within one approved relation hop of page resources.

Results include the resource, collector, observation time, relation path, stale state, and complete sanitized details. If only some collectors fail, successful evidence and failure reasons appear together as a Partial result. Empty means that no evidence was found in the selected range; it is not a healthy-state decision.

One query is bounded to 24 hours, 12 resources, and 100 evidence items. At most 20 log events are used per resource. Limit violations or unavailable plugin, diagnostic, or log sources are reported as collection failures.

RCA tools do not automatically identify a root cause or calculate candidate rankings and confidence scores. They collect metric, alert, anomaly, diagnostic, and log evidence for operator review.

Run Connected Diagnostics

When the active page contains at least one ready resource panel, select Connected Diagnostics in the workspace toolbar. The Connected Diagnostics page uses readable resources from the active page as starting resources and maps the current time range into the supported evidence lookback.

Connected Diagnostics expands from those resources through approved relations, collects diagnostic findings, and calculates operational risk, coverage, evidence confidence, impact, and urgency. Select a finding and Pin to workspace to keep a note on the current page. The diagnostic run itself is not saved, so pin anything that must remain available before leaving the result.

RCA tools collect alerts, anomalies, diagnostic history, and logs from a selected time range for operator review. Connected Diagnostics performs a one-time check of the currently readable topology and ranks explainable operational risk. Use RCA tools for broader historical evidence investigation and Connected Diagnostics for a quick, connected-resource risk assessment.

See the Connected Diagnostics manual for scope controls, score interpretation, and the transient-result policy.

Save and reopen an analysis

After reviewing evidence, select the relevant items and save an investigation note. A saved analysis belongs to the current workspace page and records:

  • the investigation note;
  • the absolute analysis time range;
  • save time and author;
  • selected evidence identities.

The Saved analysis tab loads previous notes in newest-first order without running the evidence collectors again. Select View time range to restore the workspace to that analysis window. Evidence access is still evaluated with current permissions, so revoked resource data is not disclosed.

Permissions and degraded states

  • An owner can edit, share, present, and delete the workspace.
  • A granted editor can edit pages, sections, and panels but cannot change grants or ownership.
  • A granted viewer has read-only access. Presentation also depends on its explicit permission.
  • A global administrator can read and edit workspaces for administration.
  • Workspace access never replaces source-resource access.

If a resource is deleted, inactive, or no longer readable, only that panel becomes missing, inactive, or inaccessible. Other panels and pages remain usable.

Troubleshooting

A panel is missing from the catalog

Confirm that the plugin is loaded, the resource interface is active, and the current account may read the resource. The default catalog scope contains only the selected resource; enable related resources when another source is required.

Metrics do not refresh automatically

Check whether the time range is fixed or the layout is being edited. Automatic refresh intentionally pauses for fixed windows and edit mode.

Pages do not rotate automatically

Confirm that at least two included pages are readable and that rotation is not set to Manual. A fixed time range, expanded panel, active time-control interaction, hidden browser tab, or offline state also pauses rotation.

RCA results are empty or partial

Review the query range, resource permissions, and reported collector failures. The selected time may genuinely contain no alert, anomaly, diagnostic, or log evidence. Do not treat an empty result as proof of health or a root-cause conclusion.

  • enterprise/docs/analysis-workspace-contract.md
  • enterprise/backend/docs/openapi-analysis-workspace.yaml
  • enterprise/docs/instance-relations-contract.md
  • enterprise/docs/connected-diagnostics-contract.md