DV Quick Run · Mini RCA · Experimental · Engine v2.2
DV Quick Run Mini RCA (Experimental)
Question: What operational explanation best fits the available evidence?
Subject: Account · TIMELINE-MOCK
Mini RCA is experimental, deterministic, and evidence-backed. Explain assists. Evidence decides.
Investigation Readiness · Advisory
Limited
The supplied evidence supports only a limited synthesis because one or more High-priority gaps remain.
PostureLimited
Confidence EffectDampen
Synthesized ConfidenceMedium → Low
Material Evidence Gaps
- High — Provenance evidence gap
Next Evidence
- Re-capture or attach provenance-bearing evidence
Readiness is advisory and does not certify truth, causality, completeness, remediation, or operational authority.
Investigation ObjectiveExplain the operational pattern most consistent with the available understanding evidence for Account.
Experimental BoundaryMini RCA is experimental and advisory. It does not prove exact change time, root cause, remediation status, deployment correctness, or operational authority.
Investigation Story
Mini RCA reviewed 5 snapshots across 4 intervals and summarised 38 timeline events.
Automation Participation is the leading operational explanation for Account.
Configuration Drift remains visible as a competing contributor at 24%, below Automation Participation at 100%.
Correlation is strong at 91%, but evidence confidence is 49%, so the explanation should be treated as probable rather than conclusive.
Use the evidence references as the source-of-truth: Mini RCA explains the pattern; it does not prove exact change time, runtime causality, remediation status, or operational authority.
Evidence Correlation
How the available evidence relates
These relationships are produced from explicit deterministic rules. They connect existing evidence; they do not create evidence or assert causation.
0 supports
0 reinforces
0 limits
0 contradicts
No deterministic relationships were identified between the available evidence.
This does not weaken the investigation; it indicates that the available observations were independent.
Next Investigation
Recommended Next Steps
Investigate the strongest contributor candidates separatelyStart with Automation Participation and Configuration Drift; validate each contributor independently because the current evidence does not support a single dominant explanation.
The evidence distribution is non-dominant, so difference volume must not be converted into causal certainty.
Evidence: Account Create Validation plugin state changed (Enabled → Disabled) · Account SIT Enrichment Dispatch added in target · Account Update Integration Dispatch execution pipeline changed · Account Change Tracking Enabled changed: false → true
Review the strongest first-observed interval and adjacent intervalsOpen Timeline Understanding and inspect the strongest first-observed interval together with the intervals immediately before and after it.
Snapshot reconstruction identifies an observed window, not an exact change time; adjacent intervals help test whether the pattern is isolated or repeated.
Evidence: DVQR Score density changed: 42 → 67 · Account Create Validation plugin state changed (Enabled → Disabled) · Account SIT Enrichment Dispatch added in target · Account Update Integration Dispatch execution pipeline changed
Review reconstruction candidates by capabilityUse only evidence families that map to a DV ForgeLab reconstruction utility; Mini RCA guides investigation and does not perform remediation.
3 reconstruction-oriented evidence references are available.
Evidence: Power Pages Runtime Core changed from Managed → Unmanaged · Relationship no longer present in later snapshot: lk_accountbase_modifiedby (Account → SystemUser, ManyToOne) · human.operator.dev@example.com present only in source
Retrieve Audit evidence where availableReview Audit records inside the first-observed interval using an identity with the required Audit-read privileges.
Audit evidence unavailable: Timeline findings remain valid, but audit evidence would narrow the first-observed window when available.
Keep the conclusion bounded to the available evidenceVerify the leading pattern against runtime, deployment, Audit, or operational evidence before making remediation decisions.
Recommendations guide the next investigation step; they do not prove root cause or authorise a change.
Evidence: Account Create Validation plugin state changed (Enabled → Disabled) · Account SIT Enrichment Dispatch added in target · Account Update Integration Dispatch execution pipeline changed