For every incident Lemwatch correlates recent deploys, DNS diffs, cert changes, and upstream provider status pages to pinpoint the likely cause.
Quick answer
We cross-reference the incident timestamp with your last deploy, DNS diff, cert change, and upstream cloud provider status pages, then rank the top 3 causes by likelihood.
Signals correlated
Git deploy webhooks (if wired)
DNS record diffs
SSL cert renewal / rotation events
Cloudflare / AWS / GCP status pages
WordPress plugin/theme version changes
Autopilot actions in the same window
Where to find it in Lemwatch
Incident detail → Likely cause. Each candidate has an evidence link.
How to fix
Read the top-ranked cause and its evidence.
If wrong, click "Not this" — the model learns per-org over time.
When confirmed, click "Add to postmortem" to seed the incident report.
FAQ
What if it can't find a cause?
You'll see "No correlated changes in the last 60 minutes" — start with outage triage.
Does it access my server logs?
No — it uses only signals Lemwatch already collects.