Splunk-native · Observability · Agentic Ops

It doesn't read the blood. It watches the journey.

A flight recorder for hospital specimen transport. It scores every journey's integrity from telemetry alone - and routes the suspect ones to human review before degraded data is ever trusted downstream.

runtime AI, not mock token-auth MCP never a diagnosis
The hidden blind spot

The result passed every instrument check.
The specimen still arrived broken.

Most lab error is born before the analyzer ever runs - a coag tube stuck 38 minutes in a faulted line, a fridge door left open, a handoff scan that never happened. The sample degrades. The data flows on as if nothing happened.

0%of total lab error is pre-analytic
0systems that own “the journey” today
4m 12smedian time to detect silent corruption

Transport logs live in facilities. Fridge temps in building management. Handoff scans in the LIS. The correlation that exposes a bad journey doesn't exist anywhere - until now.

A real multi-step agent · not a single LLM call

Five steps. Every claim cited to a Splunk event.

01

Discover

The agent lists indexes and metadata over a token-authenticated MCP server, least-privilege scoped.

list_indexes()
02

Query

A bounded, short-lookback SPL search assembles one specimen's timeline across indexes.

run_search · earliest=-2h
03

Ground

It pulls the route-baseline knowledge object so “out of spec” means something real.

get_lookup(route_baselines)
04

Forecast

CDTSM where available, with an always-on fallback - runtime AI never single-threads a preview.

forecast_transit · CDTSM | STL
05

Decide

The model classifies trust and recommends one bounded action - a human approves, nothing auto-executes.

reason → HOLD + REDRAW
What it actually does

Narrow. High-stakes. Honest about its limits.

Cross-index correlation

Stitches transport, environment, custody and queue telemetry into one per-specimen journey.

Cited evidence

Every line of the verdict resolves to a raw Splunk event. Uncited claims are rejected and re-run.

Human-gated actions

Hold, redraw, confirm custody, release - all reversible, all confirmed by a person.

Writeback audit trail

Decisions are written back to Splunk, so the platform owns the record and learns over time.

Resilient forecasting

Dual-path CDTSM + fallback. The active source is shown on every single decision.

Never a diagnosis

It never reads clinical meaning. Its only output is an operational trust signal. That discipline is the point.

Watch it catch a result
nobody else would.

Three minutes. A specimen that passed QC, flagged by its journey, held by one human click - the loop closing back inside Splunk.