Open-source monitoring & operations

Know what changed.
Understand why.

Watchpost is a self-hosted monitoring platform designed around durable evidence, clear operational state, and an agent that can investigate your systems without inheriting unrestricted control of them.

In active development · architecture published early

watchpost / edge-01 / incident 0042

Live signals

CPU42%
Memory68%
Disk /data86%
HTTP p95184ms

Evidence timeline

deploy api@8f21c7
DB pool saturation increased
latency rule firing
incident opened · evidence linked

Built for the whole incident

From observation to explanation.

Traditional monitoring often leaves the operator to connect dashboards, alerts, changes, logs, and runbooks by hand. Watchpost is being designed so those relationships are durable product objects rather than context scattered across browser tabs.

01 / Observe

Signals with provenance

Metrics, checks, logs, events, quality, freshness, units, and source identity remain explicit. Missing data is not quietly interpreted as a healthy zero.

02 / Decide

Deterministic rules

Duration, hysteresis, maintenance, dependencies, deduplication, acknowledgement, and resolution work without asking a language model what should be true.

03 / Investigate

An evidence-grounded agent

Ask what changed and why. The agent follows bounded operational evidence, shows its work, preserves uncertainty, and starts read-only.

Operational state, connected

A coherent path through failure.

Watchpost’s object model is intentionally small. Collection produces trustworthy observations; rules produce state; incidents preserve the investigation; actions remain separately authorised.

01Collect

Observe hosts, services, endpoints, applications, and events.

02Evaluate

Apply deterministic rules with explicit missing-data policy.

03Alert

Route and deduplicate state transitions without storms.

04Investigate

Join signals, changes, topology, logs, and history.

05Act

Use typed, scoped, approved operations with audit.

Agent-native, not agent-dependent

The model may explain an incident. It does not get to redefine authority.

Authentication, rule evaluation, retention, notification, approval, and audit remain ordinary deterministic software. AI operates inside those boundaries, treating monitored content as untrusted input and citing the evidence behind its conclusions.