Mini RCA · Investigation Readiness · v0.15.3

Turn investigation evidence into bounded operational explanation.

Mini RCA v0.15.3 accepts both canonical Cross-Diff and timeline-native investigation input. Both paths now share one Investigation Readiness contract and one frozen HTML, Markdown, and canonical JSON artifact model, alongside deterministic Evidence Correlation and shared recommendations.

New in v0.15.3: Ready, Conditional, Limited, and NotAssessable explain contributor availability, evidence quality, material gaps, confidence effects, and the next evidence worth collecting. Readiness is advisory; it never certifies truth, raises confidence, or authorises remediation.

Evidence preparation, clearly bounded

Readiness without certification

Investigation Readiness preserves Missing, NotConsulted, PermissionLimited, Unsupported, Stale, Partial, and Available contributor distinctions. It evaluates only supplied evidence and never initiates a Dataverse read, write, query, upload, or remediation action.

Investigation Readiness

Explains the Ready, Conditional, Limited, or NotAssessable posture, confidence effect, material gaps, and the next evidence worth collecting.

Executive Summary

Starts with the bounded outcome, evidence confidence, correlation coverage, supporting observations, closest contributor patterns, and first action.

Investigation Story

Turns normalised investigation evidence into a readable story without claiming deployment correctness, runtime impact, or causality.

Why DVQR Thinks This

Shows the deterministic path from provider-owned evidence to scoped contributor candidates, dominance assessment, and recommendations.

Evidence Correlation

Shows how existing findings support, reinforce, limit, contradict, remain missing, or stay neutral through explicit deterministic rules.

Evidence

Separates representative subject-local evidence, missing evidence, cross-cutting environment context, and high-volume noise clusters.

Recommended Next Steps

Turns ranked explanations into evidence-aware investigation actions without performing remediation or claiming authority.

Appendix

Keeps the readiness fingerprint, contributor states, evidence-quality dimensions, canonical gaps, Understanding Bundle, Evidence Relationships, correlation graph, and supporting evidence available for deeper review.

Four qualitative postures · no readiness score

Ready

The supplied evidence supports bounded synthesis without a material readiness gap.

Conditional

Useful synthesis remains possible, with visible qualifications and evidence limitations.

Limited

One or more material gaps require a conservative confidence reduction.

NotAssessable

The supplied evidence cannot responsibly support a meaningful synthesized confidence level.

Stable application boundary

One transport-neutral readiness contract.

Timeline and Cross-Diff evidence are normalised through canonical investigation input and assessed without VS Code host dependencies. The stable request, result, error, and semantic-operation fixtures are ready for a future MCP adapter; v0.15.3 ships no MCP server or runtime.

Investigation flow

Cross-Environment Diff or Timeline ReconstructionExact source/target differences or snapshot-bounded first-observed evidence.
Understanding Bundle v2Scope-aware contributor interpretation through investigation-input-v1.
Investigation ReadinessContributor states, evidence quality, canonical gaps, and confidence effects.
Frozen Mini RCA artifactAligned HTML, Markdown, and canonical JSON until explicit regeneration.
/reports/sample-account-crossdiff-mini-rca-report.html
/reports/sample-account-timelinemock-mini-rca-report.html
.dvforgelab/dvqr/reports/sample-account-timelinemock-mini-rca-report.md
Markdown Preview

DV Quick Run Mini RCA (Experimental)

> Mini RCA is experimental, deterministic, and evidence-backed. Explain assists. Evidence decides.

Generated: 2026-07-23T11:18:26.588Z Subject: Account · TIMELINE-MOCK Question: What operational explanation best fits the available evidence?

Executive Summary

  • Outcome: No dominant contributor confirmed
  • Evidence confidence: 49% (Low)
  • Correlation confidence: 91% (Very High)
  • Leading-candidate evidence: 5 observations
  • Closest contributor patterns: Automation Participation (100%); Configuration Drift (24%)
  • First action: Investigate the strongest contributor candidates separately

DVQR analysed 5 snapshots across 4 intervals and found Automation Participation to be the strongest bounded explanation. The conclusion remains bounded to the available evidence.

Investigation Readiness

  • Posture: Limited
  • Confidence effect: Dampen (Medium → Low)
  • Evidence gaps: 1
  • The supplied evidence supports only a limited synthesis because one or more High-priority gaps remain.
  • High: Provenance evidence gap
  • Next evidence: Re-capture or attach provenance-bearing evidence
  • Boundary: readiness is advisory and does not certify truth, causality, completeness, remediation, or operational authority.

Investigation Story

  • Mini RCA reviewed 5 snapshots across 4 intervals and summarised 38 timeline events.
  • Automation Participation is the leading operational explanation for Account.
  • Configuration Drift remains visible as a competing contributor at 24%, below Automation Participation at 100%.
  • Correlation is strong at 91%, but evidence confidence is 49%, so the explanation should be treated as probable rather than conclusive.
  • Use the evidence references as the source-of-truth: Mini RCA explains the pattern; it does not prove exact change time, runtime causality, remediation status, or operational authority.

Why DVQR Thinks This

  • Timeline Understanding: 38 timeline event(s)
  • Evidence grouped into:
    • Automation Participation: 5
    • Configuration Drift: 1
    • Metadata Evolution: 1
    • Operational Profile: 1
    • Relationship Behaviour: 1
    • Security Participation: 1
  • Outcome path: No dominant contributor confirmed
  • Confidence adjustment: Audit evidence unavailable; Low evidence confidence; Very High correlation confidence
  • Mini RCA recommendation: Investigate the strongest contributor candidates separately
  • Note: This section summarises reportable deterministic evidence flow, not hidden chain-of-thought.

Bounded Outcome

No dominant contributor confirmed

Dominance assessment

  • Highest contributor: 100%
  • Required threshold: 60%
  • Lead margin: 76 points
  • Independent evidence families: 2
  • Cross-evidence relationships: None identified
  • Outcome: No dominant contributor confirmed
  • Why: The leading contributor did not satisfy all bounded dominance requirements.

Strongest Contributor Candidates

  • Automation Participation — 100% (High)
    • Automation or execution participation changed during the reconstructed investigation window. These observations identify operational participation, but do not prove runtime causality. Supported by 5 evidence observations.
    • Evidence: Account Create Validation plugin state changed (Enabled → Disabled); Account SIT Enrichment Dispatch added in target; Account Update Integration Dispatch execution pipeline changed; Legacy Account Background Sync removed from target; Account Sync Realtime state changed (Deactivated → Activated)
  • Configuration Drift — 24% (Low)
    • Configuration references evolved during the reconstructed investigation window. These observations indicate environmental or application configuration changes, but do not prove runtime correctness or deployment outcome. Supported by 1 evidence observation.
    • Evidence: Account Change Tracking Enabled changed: false → true

Evidence Correlation

  • Evidence relationship summary: supports 0; reinforces 0; limits 0; contradicts 0
  • No deterministic relationships were identified between the available evidence. This does not weaken the investigation; it indicates that the available observations were independent.
  • Boundary: correlation connects existing evidence; it does not create evidence or assert causation.

Evidence

Leading-Candidate Evidence

  • Account Create Validation plugin state changed (Enabled → Disabled)
  • Account SIT Enrichment Dispatch added in target
  • Account Update Integration Dispatch execution pipeline changed
  • Legacy Account Background Sync removed from target
  • Account Sync Realtime state changed (Deactivated → Activated)

Missing Evidence

  • Audit evidence was not available. Timeline evidence confidence is unchanged, but exact change-time confidence remains limited.
  • Optional reconstruction artifacts were not attached to this Mini RCA bundle.
  • Timeline evidence is not fully verified

Other Relevant Evidence

  • DVQR Score density changed: 42 → 67
  • Power Pages Runtime Core changed from Managed → Unmanaged
  • Account Change Tracking Enabled changed: false → true
  • Relationship no longer present in later snapshot: lk_accountbase_modifiedby (Account → SystemUser, ManyToOne)
  • human.operator.dev@example.com present only in source

Confidence Notes

  • Strengthens: A deterministic leading explanation is available: Automation Participation (100%).
  • Strengthens: 9 high-confidence evidence references support the evidence set.
  • Limits: Evidence confidence (49%) is lower than correlation confidence (91%).
  • Limits: Timeline evidence is not fully verified (Medium).
  • Limits: Audit evidence unavailable (Low).
  • Limits: Multiple competing contributor categories remain visible.

Recommended Next Steps

  • Investigate the strongest contributor candidates separately — Start with Automation Participation and Configuration Drift; validate each contributor independently because the current evidence does not support a single dominant explanation.
    • Rationale: The evidence distribution is non-dominant, so difference volume must not be converted into causal certainty.
    • Evidence: Account Create Validation plugin state changed (Enabled → Disabled); Account SIT Enrichment Dispatch added in target; Account Update Integration Dispatch execution pipeline changed; Account Change Tracking Enabled changed: false → true
  • Review the strongest first-observed interval and adjacent intervals — Open Timeline Understanding and inspect the strongest first-observed interval together with the intervals immediately before and after it.
    • Rationale: Snapshot reconstruction identifies an observed window, not an exact change time; adjacent intervals help test whether the pattern is isolated or repeated.
    • Evidence: DVQR Score density changed: 42 → 67; Account Create Validation plugin state changed (Enabled → Disabled); Account SIT Enrichment Dispatch added in target; Account Update Integration Dispatch execution pipeline changed
  • Review reconstruction candidates by capability — Use only evidence families that map to a DV ForgeLab reconstruction utility; Mini RCA guides investigation and does not perform remediation.
    • Rationale: 3 reconstruction-oriented evidence references are available.
    • Evidence: Power Pages Runtime Core changed from Managed → Unmanaged; Relationship no longer present in later snapshot: lk_accountbase_modifiedby (Account → SystemUser, ManyToOne); human.operator.dev@example.com present only in source
  • Retrieve Audit evidence where available — Review Audit records inside the first-observed interval using an identity with the required Audit-read privileges.
    • Rationale: Audit evidence unavailable: Timeline findings remain valid, but audit evidence would narrow the first-observed window when available.
  • Keep the conclusion bounded to the available evidence — Verify the leading pattern against runtime, deployment, Audit, or operational evidence before making remediation decisions.
    • Rationale: Recommendations guide the next investigation step; they do not prove root cause or authorise a change.
    • Evidence: Account Create Validation plugin state changed (Enabled → Disabled); Account SIT Enrichment Dispatch added in target; Account Update Integration Dispatch execution pipeline changed

Appendix

Contract Metadata

  • Understanding Bundle: understanding-bundle-v1
  • Investigation Input: investigation-input-v1
  • Evidence Correlation: evidence-correlation-v1
  • Investigation Readiness: investigation-readiness-v1
  • Generated by: DV Quick Run v0.15.3

Understanding Bundle

  • Bundle version: understanding-bundle-v1
  • Understanding coverage: Medium (contributor availability; not explanatory confidence)
  • Available (5): Timeline, Metadata, Identity, Relationship, Configuration
  • Unavailable (1): Audit (Audit evidence was not retrieved or audit is disabled, so exact change confirmation remains limited.)
  • Not applicable (3): Choice, Cross Diff, Query
  • Confidence reasons:
    • Understanding registry: 5 contributors are available.
    • Available registry contributors: Timeline Understanding, Metadata Understanding, Identity Understanding, Relationship Understanding, Configuration Understanding.
  • Confidence limitations:
    • Audit Understanding: Audit evidence was not retrieved or audit is disabled, so exact change confirmation remains limited.
    • First observed is not changed at; Timeline Understanding narrows investigation windows but does not prove exact change time.
    • Metadata drift is investigation evidence; it is not deployment correctness proof.
    • No choice or option-set evidence was present in this investigation bundle.
    • Participation is not authority; identity drift does not prove effective access.
    • Relationship visibility is not dependency certainty.
    • Configuration drift is not runtime correctness proof; secret values remain masked or omitted.
    • Cross Diff Understanding is not applicable unless cross-environment evidence is explicitly included in the investigation input.

Contributor Confidence Summary

  • Timeline Understanding — available; confidence Medium
    • Summary: Timeline Understanding reviewed 38 event(s) across 4 interval(s).
    • Evidence: DVQR Score density changed: 42 → 67; Account Create Validation plugin state changed (Enabled → Disabled); Account SIT Enrichment Dispatch added in target; Account Update Integration Dispatch execution pipeline changed; Legacy Account Background Sync removed from target; +5 more in technical appendix
  • Audit Understanding — unavailable; confidence Unknown
    • Summary: Audit evidence was not retrieved or audit is disabled, so exact change confirmation remains limited.
    • Limitation: Audit evidence was not retrieved or audit is disabled, so exact change confirmation remains limited.
  • Metadata Understanding — available; confidence High
    • Summary: Metadata Understanding found 1 relevant evidence reference.
    • Evidence: Power Pages Runtime Core changed from Managed → Unmanaged
  • Choice Understanding — Not applicable; confidence Unknown
    • Summary: No choice or option-set evidence was present in this investigation bundle.
    • Limitation: No choice or option-set evidence was present in this investigation bundle.
  • Identity Understanding — available; confidence Medium
    • Summary: Identity Understanding found 1 relevant evidence reference.
    • Evidence: human.operator.dev@example.com present only in source
  • Relationship Understanding — available; confidence High
    • Summary: Relationship Understanding found 1 relevant evidence reference.
    • Evidence: Relationship no longer present in later snapshot: lk_accountbase_modifiedby (Account → SystemUser, ManyToOne)
  • Configuration Understanding — available; confidence High
    • Summary: Configuration Understanding found 1 relevant evidence reference.
    • Evidence: Account Change Tracking Enabled changed: false → true
  • Cross Diff Understanding — Not applicable; confidence Unknown
    • Summary: Cross Diff Understanding is not applicable unless cross-environment evidence is explicitly included in the investigation input.
    • Limitation: Cross Diff Understanding is not applicable unless cross-environment evidence is explicitly included in the investigation input.
  • Query Understanding — Not applicable; confidence Unknown
    • Summary: Query Understanding is not applicable unless query evidence is explicitly included in the investigation input.
    • Limitation: Query Understanding is not applicable unless query evidence is explicitly included in the investigation input.

Evidence Relationships

  • Mini RCA investigation
    • missing
    • audit unavailable
    • Reason: audit evidence is unavailable: Audit evidence was not retrieved or audit is disabled, so exact change confirmation remains limited.
  • Mini RCA investigation
    • neutral
    • choice not applicable
    • Reason: choice was not applicable and does not change the current evidence interpretation.
  • Mini RCA investigation
    • neutral
    • crossDiff not applicable
    • Reason: crossDiff was not applicable and does not change the current evidence interpretation.
  • Mini RCA investigation
    • neutral
    • query not applicable
    • Reason: query was not applicable and does not change the current evidence interpretation.
  • Boundary: correlation connects existing evidence; it does not create evidence or assert causation.

Evidence Correlation Graph v1

  • Graph version: evidence-correlation-v1
  • Evidence immutable: yes
  • Deterministic: yes
  • Evidence nodes: 10
  • Availability nodes: 4
  • Evidence relationships: 0
  • Availability relationships: 4
  • Relationships: supports 0; reinforces 0; limits 0; contradicts 0; missing 1; neutral 3
  • missing — correlation-investigation → availability:audit
    • audit evidence is unavailable: Audit evidence was not retrieved or audit is disabled, so exact change confirmation remains limited.
    • Rule: Unavailable evidence limitation (unavailable-contributor-is-missing)
  • neutral — correlation-investigation → availability:choice
    • choice was not applicable and does not change the current evidence interpretation.
    • Rule: Not-applicable evidence boundary (not-applicable-contributor-is-neutral)
  • neutral — correlation-investigation → availability:crossDiff
    • crossDiff was not applicable and does not change the current evidence interpretation.
    • Rule: Not-applicable evidence boundary (not-applicable-contributor-is-neutral)
  • neutral — correlation-investigation → availability:query
    • query was not applicable and does not change the current evidence interpretation.
    • Rule: Not-applicable evidence boundary (not-applicable-contributor-is-neutral)

Investigation Readiness Technical Trace

  • Contract: investigation-readiness-v1
  • Profile: timeline-mini-rca-v1 v1.0
  • Input fingerprint: sha256:052b03e9d27ef640aa18a237ae3aa55c01f0f177e89e12e7ad0f599cb01d8ff8
  • Assessment UTC: 2026-07-23T11:18:26.588Z
  • Generated UTC: 2026-07-23T11:18:26.588Z

Contributor States

  • timeline.reconstruction — Primary; Available; applicable; 10 evidence reference(s)
  • timeline.understanding — Required; Available; applicable; 10 evidence reference(s)
  • timeline.trust — Required; Partial; applicable; 1 evidence reference(s)
  • audit.evidence — Recommended; NotConsulted; not applicable; 0 evidence reference(s)
  • identity.evidence — Recommended; Available; applicable; 1 evidence reference(s)
  • relationship.evidence — Recommended; Available; applicable; 1 evidence reference(s)
  • configuration.evidence — Recommended; Available; applicable; 7 evidence reference(s)
  • crossDiff.evidence — Recommended; NotConsulted; not applicable; 0 evidence reference(s)
  • query.evidence — Optional; NotConsulted; not applicable; 0 evidence reference(s)
  • metadata.evidence — Optional; Available; applicable; 1 evidence reference(s)

Evidence Quality

  • Provenance: Limited — Provenance is materially limited by one or more applicable contributors.
  • Coverage: Limited — Coverage is materially limited by one or more applicable contributors.
  • Freshness: Unknown — No explicit provider validity or profile threshold establishes freshness; no global TTL was invented.
  • Scope: Sufficient — Scope is sufficient for this bounded readiness assessment.
  • Repeatability: Sufficient — Repeatability is sufficient for this bounded readiness assessment.
  • Consistency: Sufficient — Consistency is sufficient for this bounded readiness assessment.

Canonical Gaps and Recommendations

  • GAP-PROVENANCE-001 · High Provenance · timeline.trust
  • readiness-recommendation:GAP-PROVENANCE-001:timeline-trust · GAP-PROVENANCE-001 · Re-capture or attach provenance-bearing evidence

Supporting Evidence Appendix

Automation Participation (5)

  • Account Create Validation plugin state changed (Enabled → Disabled)
    • Technical ID: timeline-2
    • Source: Timeline
    • Confidence: High
    • Provider: Plugin Step Diff
    • Summary: Observed plugin step registration metadata differs across snapshots. Use this as runtime behaviour orientation, not as root-cause certainty. First observed between 2026-06-16T06:20:23.405Z → 2026-06-16T06:31:26.106Z.
    • First observed: 2026-06-16T06:20:23.405Z → 2026-06-16T06:31:26.106Z
  • Account SIT Enrichment Dispatch added in target
    • Technical ID: timeline-3
    • Source: Timeline
    • Confidence: High
    • Provider: Plugin Step Diff
    • Summary: Target-only plugin step registration. Treat this as runtime behaviour context, not deployment validation. First observed between 2026-06-16T06:20:23.405Z → 2026-06-16T06:31:26.106Z.
    • First observed: 2026-06-16T06:20:23.405Z → 2026-06-16T06:31:26.106Z
  • Account Update Integration Dispatch execution pipeline changed
    • Technical ID: timeline-4
    • Source: Timeline
    • Confidence: High
    • Provider: Plugin Step Diff
    • Summary: Observed plugin step registration metadata differs across snapshots. Use this as runtime behaviour orientation, not as root-cause certainty. First observed between 2026-06-16T06:20:23.405Z → 2026-06-16T06:31:26.106Z.
    • First observed: 2026-06-16T06:20:23.405Z → 2026-06-16T06:31:26.106Z
  • Legacy Account Background Sync removed from target
    • Technical ID: timeline-5
    • Source: Timeline
    • Confidence: High
    • Provider: Plugin Step Diff
    • Summary: Source-only plugin step registration. Treat this as runtime behaviour context, not deployment validation. First observed between 2026-06-16T06:20:23.405Z → 2026-06-16T06:31:26.106Z.
    • First observed: 2026-06-16T06:20:23.405Z → 2026-06-16T06:31:26.106Z
  • Account Sync Realtime state changed (Deactivated → Activated)
    • Technical ID: timeline-7
    • Source: Timeline
    • Confidence: High
    • Provider: Workflow / Automation Participation Diff
    • Summary: Observed state and owner metadata differ across snapshots. Use this as orchestration orientation, not as execution causality. First observed between 2026-06-16T06:20:23.405Z → 2026-06-16T06:31:26.106Z.
    • First observed: 2026-06-16T06:20:23.405Z → 2026-06-16T06:31:26.106Z

Configuration Drift (1)

  • Account Change Tracking Enabled changed: false → true
    • Technical ID: timeline-8
    • Source: Timeline
    • Confidence: High
    • Provider: Entity Configuration Diff
    • Summary: Entity change tracking configuration differs across snapshots. Change tracking may affect integration, synchronization, and delta-observation behaviour, but DVQR does not infer runtime impact or remediation scope. First observed between 2026-06-16T06:31:26.106Z → 2026-06-16T07:23:46.723Z.
    • First observed: 2026-06-16T06:31:26.106Z → 2026-06-16T07:23:46.723Z

Metadata Evolution (1)

  • Power Pages Runtime Core changed from Managed → Unmanaged
    • Technical ID: timeline-6
    • Source: Timeline
    • Confidence: High
    • Provider: Solution Participation Diff
    • Summary: Observed solution package metadata differs across snapshots. Use this as deployment/layering orientation, not as proof that a deployment caused runtime behaviour. First observed between 2026-06-16T06:20:23.405Z → 2026-06-16T06:31:26.106Z.
    • First observed: 2026-06-16T06:20:23.405Z → 2026-06-16T06:31:26.106Z

Operational Profile (1)

  • DVQR Score density changed: 42 → 67
    • Technical ID: timeline-1
    • Source: Timeline
    • Confidence: High
    • Provider: Operational Profile Diff
    • Summary: Observed operational-density score differs across snapshots. Use this as comparison orientation, not as health, risk, or root-cause evidence. First observed between 2026-06-16T06:20:23.405Z → 2026-06-16T06:31:26.106Z.
    • First observed: 2026-06-16T06:20:23.405Z → 2026-06-16T06:31:26.106Z

Relationship Behaviour (1)

  • Relationship no longer present in later snapshot: lk_accountbase_modifiedby (Account → SystemUser, ManyToOne)
    • Technical ID: timeline-9
    • Source: Timeline
    • Confidence: High
    • Provider: Relationship Metadata Diff
    • Summary: This ManyToOne relationship (account → systemuser) exists in the source snapshot but is missing in the target. Relationship drift can occur when lookup fields or relationship metadata are removed, renamed, added, or changed between snapshots. DVQR treats this as high-signal metadata evidence because relationships can affect lookup/navigation/traversal interpretation, but it does not infer deployment causality, runtime impact, or remediation scope. First observed between 2026-06-16T06:31:26.106Z → 2026-06-16T07:23:46.723Z.
    • First observed: 2026-06-16T06:31:26.106Z → 2026-06-16T07:23:46.723Z

Security Participation (1)

  • human.operator.dev@example.com present only in source
    • Technical ID: timeline-10
    • Source: Timeline
    • Confidence: Medium
    • Provider: Identity Participation Diff
    • Summary: Identity appears only in the source evidence set. First observed between 2026-05-25T05:27:12.006Z → 2026-06-16T06:20:23.405Z.
    • First observed: 2026-05-25T05:27:12.006Z → 2026-06-16T06:20:23.405Z

Experimental Boundary

Mini RCA suggests probable operational explanations. It does not prove exact change time, root cause, remediation status, deployment correctness, or operational authority.

Mini RCA is experimental, advisory, and evidence-backed. It suggests probable operational explanations; it does not prove exact change time, root cause, remediation status, deployment correctness, or operational authority.