For GCP teams without Premium Support
Nodrik —
your alerts, investigated.
Nodrik cuts the time it takes to investigate an incident. When a Google Cloud Monitoring alert fires, it reads your logs, metrics, deploys and commits — inside your own project, read-only — and posts to Slack with a likely cause and the evidence behind it.
orders 5xx responses — request count above threshold onorders-api

orders-api — likely cause
acme-prod · orders 5xx responses
Suggested fix: Restore the roles/pubsub.publisher IAM binding on topic projects/acme-prod/topics/order-events for the service account used by the orders-api Cloud Run revision.
High confidence · 35s
in thread
High confidence — Audit logs confirm the exact IAM policy modification on the Pub/Sub topic at 10:15:34, immediately preceding the publish errors and 500 status codes that started at 10:17:04 on revision orders-api-00049-49p.
Timeline
- 10:15:34 IAM policy updated on Pub/Sub topic
projects/acme-prod/topics/order-eventsviaSetIamPolicy. - 10:17:04 Cloud Run service
orders-api(revisionorders-api-00049-49p) begins failing to publish events and returning 500 errors. - 10:22:29 Monitoring alert triggers due to 5xx response rate.
Suggested fix
Restore the roles/pubsub.publisher IAM binding on topic projects/acme-prod/topics/order-events for the service account used by the orders-api Cloud Run revision.
suggested — verify before running
- 35s
- from alert to card, in the investigation above
- 4
- read-only IAM roles, granted and revoked by you
- 1
- thing kept — the report. Your telemetry is never stored
- 0
- write calls against your Google Cloud — every call is a get or a list
Before you grant anything
The questions a DevOps lead asks first.
Nodrik asks for four IAM roles into production. These are the things worth knowing before you say yes, answered at the level a security review works at.
- What can it write to my project?
- Nothing. Every call is a read — the list calls named on the security page, plus the get calls of any configuration role you opt into. The roles confer no write permission, and there is no code path that would use one.
- Where does my data go?
- It stays. Nodrik reads through your own APIs at investigation time and keeps only the report and its transcript, redacted. No telemetry is copied out or indexed.
- How do I know what it read?
- Your Cloud Audit Logs record every call under the service account you granted. One gcloud logging read shows you reads, and only reads.
- What happens when it is wrong?
- It says so. An honest miss lists what was ruled out and what would confirm the leading hypothesis. The promise is that you start twenty minutes ahead, not that every verdict is right.
- Will it post noise?
- No. It posts one card per incident and writes in its thread only when the incident changes or you ask it a question. No heartbeats, no status chatter, and an alert storm folds into one investigation.
- What does it cost to find out?
- 14 days of the whole product, card up front, $0 today. Cancel before day 15 and you pay nothing. Revoke the roles and it goes blind immediately.
How it works
Three steps, and nothing leaves your project.
- 1
Your alert fires
A Cloud Monitoring policy you already own notifies a Pub/Sub channel. You decide what is worth investigating; we never invent alerts.
- 2
Nodrik investigates in place
Using a service account you granted four viewer roles, it reads logs, metrics, error groups, Cloud Run revisions, the admin audit log, and the commits behind the deploy.
- 3
The answer lands in Slack
One incident, one thread: the likely cause, a timeline, what changed, the blast radius, and a suggested fix — with the evidence it used.
Nodrik stores the report and its transcript. It does not store your telemetry — every read is transient, at investigation time, through your own APIs.
Why trust the answer
It tells you when it doesn't know.
Every AI product claims accuracy. The useful question is what it does when the evidence runs out. Nodrik returns an honest miss: what it checked, its leading hypothesis, and exactly what would confirm it — never a confident guess dressed as a finding.
Confidence is a word, with a reason attached. A suggested fix only carries a runnable command when confidence is high, and it is always framed as a suggestion to verify — Nodrik is read-only, permanently, and cannot apply anything.
checkout 5xx responses — request count above threshold oncheckout-api

checkout-api — no clear cause yet
acme-prod · checkout 5xx responses · 6 alerts · 2 policies
Leading hypothesis: An upstream dependency slowdown rather than a deploy — checkout-api has no new revisions in the window.
39s
in thread
What would confirm it
payments-apilatency over the same window
Security
Read-only, in your project, in your audit log.
Four viewer roles, granted by you and revocable by you. Every call Nodrik makes is a read — get, list, query. The grant is your action and every read is attributable, in your own Cloud Audit Logs.
- roles/logging.viewer
- roles/monitoring.viewer
- roles/errorreporting.viewer
- roles/run.viewer
- No writes. Against your Google Cloud, no write, update, create, delete or patch call exists. Tools you connect yourself are yours — Nodrik calls them and cannot verify what they do.
- No storage. Reads are transient; only the report persists.
- No self-expansion. The grant is IAM, held by you.
Who it's for
A good fit, or an honest no.
Built for you if…
- You run on GCP, mostly Cloud Run and managed services
- You are two to ten engineers, past MVP, with real users
- Slack is where your incidents actually happen
- Datadog quoted you more than your compute bill
Not for you if…
- Your logs and metrics live in Datadog, Honeycomb or New Relic
- You are multi-cloud, or AWS/Azure first
- You are GKE-heavy — that is a later expansion, not today
- You want dashboards; the Slack thread is the whole product
Pricing
Every tier is the whole product.
No feature gating, unlimited users, priced per monitored project. Tiers differ in capacity and support — nothing else.
Starter
$59/month
- 1 monitored project, then $40 each
- 60 investigations a month
- Email support
Team
$199/month
- Up to 5, then $40 each
- 200 investigations a month
- Priority email / Slack Connect
Scale
$449/month
- Up to 15, then $40 each
- 450 investigations a month
- Onboarding call + named contact
Need more of one but not the other? Extra projects and extra investigations are bought separately on any tier — $40 a month per project, and investigations by volume from $0.80 each.
An alert storm counts once — coalescing folds it into a single investigation. Go past your monthly allowance and nothing switches off mid-incident: we tell you, and the difference is not billed. Only if you finish 2 of 3 billing periods over it do we add the investigations you are actually using to your subscription, a week after telling you — so one bad month costs nothing.
From the founder
“Google put incident investigation behind a $15,000-a-month support tier. I built the version for everyone else.”

See it on your own alerts.
Sign in with Google or GitHub, choose a tier, connect a project and Slack. Every plan in full for 14 days — $0 today, first charge on day 15, cancel any time before then.
Start your 14-day trial