When a database exhausts its connection pool, everything downstream lights up too — the app times out, the gateway starts returning 502s. Kllyroo's causal engine knows which of those alerts is the cause and which are just symptoms, and shows you one incident instead of a wall of noise.
Plenty of tools group alerts that fire close together in time and call it "correlation." That catches obvious cascades but also produces false groupings — two unrelated issues that happened to overlap get bundled, and a real cascade with an unusual delay between steps gets missed.
Kllyroo instead uses a hand-curated causal graph: each of the 223 root-cause signatures is tagged with its known upstream and downstream relationships ahead of time. When multiple linked signatures fire on the same asset (or a related one) inside a correlation window, the engine walks the graph back to the earliest node in that specific chain and presents it as the root cause — with the rest attached as effects, not separate incidents.
The rules are deterministic and inspectable, not a black-box score. That matters for trust: your team can see exactly why Kllyroo called something the root cause, not just that a model was 87% confident.
Each root-cause signature detects and fires on its own — the correlation layer doesn't change detection, it changes presentation.
Every signature carries a pre-defined set of known upstream/downstream relationships. When two or more linked signatures fire within the correlation window on the same or a related asset, they're candidates for the same incident.
Among the candidates, the one with no known upstream cause in the group is named the root cause. Everything else in the chain is attached as an effect.
You get a single incident record with the root-cause signature, the effect chain, and the fix — plus the reasoning, so the pattern is visible, not just the verdict.
Offices in India and the US — reach out and we'll get back to you.