Know why production changed in minutes, not hours
Your infrastructure constantly changes. Deployments, Kubernetes rollouts, host configuration, metric baselines. We collect every change across your stack — and when an incident hits, show the likely causes ranked, with the evidence behind each one.
Last 24h
Change summary
error_rate p95 • 0.4% → 2.1%
billing-api • Memory +28%
api-17 • vm.swappiness 60 → 10
Every incident starts with the same question
Answering "what changed?" by hand means digging through Grafana, GitHub, kubectl and Slack. WhatChanged has the timeline and ranked causes ready the moment the alert fires.
4m before the alert • metrics shifted after it: memory +28%
Catch drift before it pages you
Every host and metric gets a rolling baseline. When a value drifts 2σ, 3σ or 4σ away, you get a finding — and it resolves itself when things return to normal.
Finding: metric drift
error_rate p95 · billing-api
Custom Prometheus metric drifted from its rolling baseline — no alert rule needed.
Code & Delivery
GitHub webhooks turn merges, pushes and pipelines into change events, mapped to services
Kubernetes
Read-only watchers catch rollouts, config changes, OOM kills, crash loops and node events
Host Internals
A 6MB agent diffs sysctl, kernel, packages, services and network config — no eBPF
Metric Drift
Your own Prometheus metrics — error rate, RPS, latency percentiles — against rolling baselines
Alerts → Incidents
An Alertmanager webhook opens an incident with a two-hour change timeline around it
Ranked Causes
Every candidate scored by timing, scope, metric shifts and change-type risk — fully explainable
Works with your stack, not instead of it
Keep Grafana, Prometheus and your alerting. WhatChanged adds the layer they are missing: what changed, and which change is the likely cause.
Stop asking "What changed?"
Connect a GitHub webhook and see your first change events in minutes — on your own infrastructure.
Early access • Free while in beta • Self-hosted