# FAQ

> Short answers to the questions that come up most, with links to the long ones.

Source: https://triagic.com/docs/reference/faq

## Product [#product]

**Does my data go to you?**
No. Investigations run on your machines against your infrastructure. Ticket text and
gathered evidence go to *your* LLM provider using *your* key. Query results, reports,
Console threads and usage totals never leave the desktop. See
[Security model](/docs/admin/security#what-leaves-your-network).

**Can the agent change anything in my systems?**
No. Write protection is enforced at the MCP server level, not by prompting. Use
read-only credentials as well, so the guarantee doesn't depend on one layer being
bug-free. Note that a few providers (BigQuery, New Relic, Zendesk, HubSpot, Freshdesk)
do not block writes upstream at all. See
[Read-only guarantees](/docs/admin/security#read-only-guarantees).

**Do my databases need to be on the internet?**
No, that is the point of the desktop split. They need to be reachable from the
machine running Triagic. If you need a VPN to reach production, so does Triagic.

**Can it email customers?**
Only with a human confirming each send. Replying by email is a dialog you open from a
suggested reply or the Console answer bar: you see the exact recipient, subject and
body, and you press send. The agent has no tool that reaches it. That's deliberate,
so a prompt-injected ticket cannot cause an outbound email. Every send is recorded on the
ticket's activity and writes a `ticket.email_send` audit entry.

**What are Checkups?**
Standing read-only reviews of your systems and your support operation (a Snowflake
cost review, a SOC 2 readiness walkthrough, an access review) that you run on demand
or on a schedule and that produce a report plus tracked findings. Fifteen curated
ones ship with the app, including code review checkups for GitHub and GitLab, and
you can generate your own from the integrations you have connected. See
[Checkups](/docs/checkups).

**Is there a hosted version that runs the investigations?**
No. Tool calls are long-lived local processes talking to systems that are usually
private. See [Architecture](/docs/concepts/architecture).

## Setup [#setup]

**What do I need before I can investigate anything?**
An [AI provider](/docs/admin/ai-providers) and at least one
[integration](/docs/admin/integrations). Playbooks are optional; unmatched tickets
get generic triage.

**Do I need Node or Python installed for the MCP servers?**
No. The installer ships a portable Node and `uv` inside the app, so `npx`- and
`uvx`-based integrations work on a machine with neither. Only the three Docker-based
ones (GitHub, Grafana, Terraform) need something installed first. See
[Runtimes are bundled](/docs/desktop/install#runtimes-are-bundled).

**In what order should I set things up?**
Integrations before playbooks, because the playbook's data-source picker can only
offer integrations that exist. Full list: [Admin setup checklist](/docs/admin).

**Why can I not add a second member?**
The trial is one seat. Buy seats on the **Account** page and the invite goes through.
See [Roles, plans and seats](/docs/concepts/roles-and-access#plans-and-seats).

**I changed something in the portal and the app has not noticed.**
Sync is a poll, roughly every 15 minutes, or immediate on a manual refresh. See
[the checklist](/docs/concepts/config-sync#i-changed-it-and-nothing-happened).

## Playbooks [#playbooks]

**How does a ticket get assigned to a playbook?**
An LLM classifier matches it against every enabled playbook's description and routing
hints at ingest. Assigning one by hand pins it so the classifier will not override it.

**Why did my new playbook not apply to existing tickets?**
Classification runs at ingest or on an explicit **Re-investigate**, never
retroactively. Re-investigate the tickets you want re-routed.

**What does an empty data-source list mean?**
All of them. Empty is "no restriction", not "no tools".

**Does team scoping affect which playbook a ticket gets?**
No. Teams govern who can *manually use* a playbook. Auto-classification considers
every enabled playbook in the organization.

## Access and secrets [#access-and-secrets]

**Can members see shared credentials?**
No. The member-facing view has no credential fields at all, not even masked ones, and
members cannot edit shared configurations, so they cannot repoint a credential either.

**But can they read the data those credentials reach?**
Yes, through the agent. "Cannot view" means the secret's value, never the data it
unlocks. Scope the credential itself.

**How do I remove someone?**
Disable them on the Members page. It takes effect on their next authenticated call,
frees the seat, and keeps their history attributed. See
[Members](/docs/admin/members#removing-someone).

**I lost the admin password.**
Password resets are done by another org admin from the member edit dialog. The account
owner's own credentials are managed on the **Account** page.

## Cost [#cost]

**Where do I see what this is costing?**
The desktop's **Usage** page, for this machine. Admins also get an **Organization**
scope there (every machine's spend, broken down by member), and the portal's Usage
page shows the same rollup. See
[History and usage](/docs/desktop/history-and-usage#usage).

**What happens at the spend cap?**
Background triage defers and retries; Console and chat refuse cleanly before streaming;
a run that crosses the cap mid-flight stops. See
[Spending](/docs/admin/spending#what-happens-at-the-cap).

**How do I make investigations cheaper?**
Narrow playbook data sources, sharpen triage instructions, prune unused playbooks, and
check the per-task split on Usage. Classification runs on every ticket and is often a
bigger share than expected.

## Desktop [#desktop]

**Which build do I need on macOS?**
Apple Silicon for M1 and later, Intel otherwise. Apple menu → **About This Mac** →
**Chip**.

**macOS or Windows says the developer is unverified.**
The build is unsigned. Verify the SHA256 against the download page first, then
right-click → **Open** on macOS or **More info → Run anyway** on Windows. See
[Install](/docs/desktop/install).

**Does it work offline?**
An open session does, and configuration stays as of the last sync. A *new* sign-in
does not, because credentials are verified against the cloud every time. Investigations do
not either; they need your infrastructure and your LLM provider.

**Why can I not edit playbooks in the app?**
Your install is centrally managed. Edit them in the portal; the local refusal exists
so your edit is not silently lost on the next sync.

## Getting help [#getting-help]

**Something is not covered here. Who do I ask?**
Email [hello@triagic.com](mailto:hello@triagic.com). Support, billing, sales and
security reports all reach us at that one address.
