For GCP teams without Premium Support

Nodrik —
your alerts, investigated.

Nodrik cuts the time it takes to investigate an incident. When a Google Cloud Monitoring alert fires, it reads your logs, metrics, deploys and commits — inside your own project, read-only — and posts to Slack with a likely cause and the evidence behind it.

Every feature for 14 days. Card up front, $0 today. You grant four read-only roles on the projects you choose, and you can revoke them at any time.

incidents

Cloud MonitoringAPP10:22

orders 5xx responses — request count above threshold onorders-api

nodrikAPP10:23

orders-api — likely cause

acme-prod · orders 5xx responses

Suggested fix: Restore the roles/pubsub.publisher IAM binding on topic projects/acme-prod/topics/order-events for the service account used by the orders-api Cloud Run revision.

High confidence · 35s

in thread

High confidence — Audit logs confirm the exact IAM policy modification on the Pub/Sub topic at 10:15:34, immediately preceding the publish errors and 500 status codes that started at 10:17:04 on revision orders-api-00049-49p.

Timeline

  • 10:15:34 IAM policy updated on Pub/Sub topic projects/acme-prod/topics/order-events via SetIamPolicy.
  • 10:17:04 Cloud Run service orders-api (revision orders-api-00049-49p) begins failing to publish events and returning 500 errors.
  • 10:22:29 Monitoring alert triggers due to 5xx response rate.

Suggested fix

Restore the roles/pubsub.publisher IAM binding on topic projects/acme-prod/topics/order-events for the service account used by the orders-api Cloud Run revision.

suggested — verify before running

A real investigation from our demo environment, names changed. No deploy and no commit — the cause was in the audit log.
35s
from alert to card, in the investigation above
4
read-only IAM roles, granted and revoked by you
1
thing kept — the report. Your telemetry is never stored
0
write calls against your Google Cloud — every call is a get or a list

Before you grant anything

The questions a DevOps lead asks first.

Nodrik asks for four IAM roles into production. These are the things worth knowing before you say yes, answered at the level a security review works at.

What can it write to my project?
Nothing. Every call is a read — the list calls named on the security page, plus the get calls of any configuration role you opt into. The roles confer no write permission, and there is no code path that would use one.
Where does my data go?
It stays. Nodrik reads through your own APIs at investigation time and keeps only the report and its transcript, redacted. No telemetry is copied out or indexed.
How do I know what it read?
Your Cloud Audit Logs record every call under the service account you granted. One gcloud logging read shows you reads, and only reads.
What happens when it is wrong?
It says so. An honest miss lists what was ruled out and what would confirm the leading hypothesis. The promise is that you start twenty minutes ahead, not that every verdict is right.
Will it post noise?
No. It posts one card per incident and writes in its thread only when the incident changes or you ask it a question. No heartbeats, no status chatter, and an alert storm folds into one investigation.
What does it cost to find out?
14 days of the whole product, card up front, $0 today. Cancel before day 15 and you pay nothing. Revoke the roles and it goes blind immediately.

The full trust page, with the audit-log query →

How it works

Three steps, and nothing leaves your project.

  1. 1

    Your alert fires

    A Cloud Monitoring policy you already own notifies a Pub/Sub channel. You decide what is worth investigating; we never invent alerts.

  2. 2

    Nodrik investigates in place

    Using a service account you granted four viewer roles, it reads logs, metrics, error groups, Cloud Run revisions, the admin audit log, and the commits behind the deploy.

  3. 3

    The answer lands in Slack

    One incident, one thread: the likely cause, a timeline, what changed, the blast radius, and a suggested fix — with the evidence it used.

How Nodrik reaches into your Google Cloud projectA Cloud Monitoring alert notifies a Pub/Sub channel. Nodrik's investigation runs inside your own Google Cloud project, reading logs, metrics, error groups and Cloud Run revisions read-only. The report is posted to Slack. No telemetry leaves your project.YOUR GOOGLE CLOUD PROJECTAlertCloud MonitoringPub/Suba channel you ownNodrik readslogs · metrics · errorsrevisions · commitsread-onlySlackone incident, one threadThe report leaves.Your telemetry does not.Every read is transient, at investigation time, through your own APIs.

Nodrik stores the report and its transcript. It does not store your telemetry — every read is transient, at investigation time, through your own APIs.

See the whole path →

Why trust the answer

It tells you when it doesn't know.

Every AI product claims accuracy. The useful question is what it does when the evidence runs out. Nodrik returns an honest miss: what it checked, its leading hypothesis, and exactly what would confirm it — never a confident guess dressed as a finding.

Confidence is a word, with a reason attached. A suggested fix only carries a runnable command when confidence is high, and it is always framed as a suggestion to verify — Nodrik is read-only, permanently, and cannot apply anything.

incidents

Cloud MonitoringAPP09:33

checkout 5xx responses — request count above threshold oncheckout-api

nodrikAPP09:34

checkout-api — no clear cause yet

acme-prod · checkout 5xx responses · 6 alerts · 2 policies

Leading hypothesis: An upstream dependency slowdown rather than a deploy — checkout-api has no new revisions in the window.

39s

in thread

What would confirm it

  • payments-api latency over the same window
Illustrative — the honest miss, shown because it is the point.

Security

Read-only, in your project, in your audit log.

Four viewer roles, granted by you and revocable by you. Every call Nodrik makes is a read — get, list, query. The grant is your action and every read is attributable, in your own Cloud Audit Logs.

  • roles/logging.viewer
  • roles/monitoring.viewer
  • roles/errorreporting.viewer
  • roles/run.viewer
  • No writes. Against your Google Cloud, no write, update, create, delete or patch call exists. Tools you connect yourself are yours — Nodrik calls them and cannot verify what they do.
  • No storage. Reads are transient; only the report persists.
  • No self-expansion. The grant is IAM, held by you.

Read exactly what it can and cannot do →

Who it's for

A good fit, or an honest no.

Built for you if…

  • You run on GCP, mostly Cloud Run and managed services
  • You are two to ten engineers, past MVP, with real users
  • Slack is where your incidents actually happen
  • Datadog quoted you more than your compute bill

Not for you if…

  • Your logs and metrics live in Datadog, Honeycomb or New Relic
  • You are multi-cloud, or AWS/Azure first
  • You are GKE-heavy — that is a later expansion, not today
  • You want dashboards; the Slack thread is the whole product

Pricing

Every tier is the whole product.

No feature gating, unlimited users, priced per monitored project. Tiers differ in capacity and support — nothing else.

Starter

$59/month

  • 1 monitored project, then $40 each
  • 60 investigations a month
  • Email support
Start your 14-day trial

Team

$199/month

  • Up to 5, then $40 each
  • 200 investigations a month
  • Priority email / Slack Connect
Start your 14-day trial

Scale

$449/month

  • Up to 15, then $40 each
  • 450 investigations a month
  • Onboarding call + named contact
Start your 14-day trial

Need more of one but not the other? Extra projects and extra investigations are bought separately on any tier — $40 a month per project, and investigations by volume from $0.80 each.

An alert storm counts once — coalescing folds it into a single investigation. Go past your monthly allowance and nothing switches off mid-incident: we tell you, and the difference is not billed. Only if you finish 2 of 3 billing periods over it do we add the investigations you are actually using to your subscription, a week after telling you — so one bad month costs nothing.

Full pricing and questions →

From the founder

“Google put incident investigation behind a $15,000-a-month support tier. I built the version for everyone else.”
Jens Skott, founder of Thoughtgears
Jens SkottFounder, Thoughtgears

See it on your own alerts.

Sign in with Google or GitHub, choose a tier, connect a project and Slack. Every plan in full for 14 days — $0 today, first charge on day 15, cancel any time before then.

Start your 14-day trial

Prefer to talk first? support@nodrik.dev— a person answers.