Agent

Run PacketSafari Agent for a deeper automated investigation with capture-specific tasks and evidence-backed findings.

PacketSafari Agent is the deeper autonomous analysis workflow. It starts from a capture-aware hypothesis, proposes focused tasks, and can continue into a fuller investigation pass than Quick Insights.

PacketSafari Agent task launcher

Use Agent when:

  • you want to upload a PCAP and ask for an answer in one flow
  • the first-pass brief suggests a real issue worth deeper review
  • you want PacketSafari to drive the next steps instead of asking a back-and-forth chat
  • you need a more structured investigation path than Quick Insights provides

Upload and ask AI

The fastest route into Agent is Ask AI in the upload dialog. Choose an Executive summary, Root cause, Security review, or Custom prompt, then choose how PacketSafari should balance first-result speed and capture-wide context:

  • Fast + verification starts a focused preliminary Agent while PacketSafari Triage builds indexed evidence for a later independent verification follow-up. This is the recommended operational default.
  • Fast answer starts one bounded preliminary Agent as soon as the capture is safely readable. It is fastest when the question includes a useful selector, but it may miss correlations elsewhere in the capture.
  • Triage then deep waits for indexed rules, priority flows, protocol signals, and correlations before starting one deep Agent. It is the slowest path to the first report and the strongest capture-wide starting point.

See Investigation Path Guide for the full comparison. Manual inspection, guided Copilot, and Agent automation can all use the PacketSafari Core Engine; they describe who drives the investigation, not how much processing must finish before Agent starts.

When anoncap is enabled, Agent runs against the anonymized sibling capture. Where mail delivery and entitlement allow it, PacketSafari can email the preliminary report and later verification outcome as distinct persisted milestones.

Typical flow

  1. Start from Ask AI during upload, or review Quick Insights or your current analyzer context.
  2. Open Agent from the analyzer header when you are already inside the capture.
  3. Choose the investigation tier that fits the task.
  4. Add Case context when the capture has known symptoms, measurement points, or operational notes.
  5. Start one of the capture-specific tasks.
  6. Review the resulting findings and pivots, then continue in packets, stats, security, or infrastructure as needed.
  7. Use Generate report after a completed run when you need a comprehensive write-up that can be shared outside the live analyzer.

Investigation tiers

PacketSafari uses weighted Agent units instead of raw token credits. This keeps usage predictable while still letting heavier investigations consume more of the monthly allowance.

TierBest forAgent-unit use
Fast answer · Standard modelFocused autonomous preliminary investigation for normal troubleshooting.1 Agent unit.
Fast + verificationPreliminary report followed by independent evidence verification in the same investigation.2 Agent units.
Fast answer · Strongest modelFocused preliminary investigation on the strongest configured model profile.2 Agent units.
Triage then deep · Strongest modelCapture-wide discovery followed by deep investigation on the strongest configured model profile.4 Agent units.

Hosted Agent Pro includes 50 Agent units per month. If the whole allowance is used on one profile, that is up to 50 focused standard-model runs, 25 Fast + verification or focused strongest-model runs, or 12 deep strongest-model runs, with two units remaining, or any weighted mix.

The progressive Fast + verification upload workflow uses a fixed validated progressive runtime profile, meters 2 Agent units once, and includes both the preliminary pass and the later independent verification pass. The follow-up reports its exact outcome; it is called verified only when verification succeeds.

Enterprise allowances use the same weights. Shared Enterprise SaaS includes 500 pooled Agent units per month, Dedicated Enterprise SaaS includes 2,000, and On-Prem Enterprise includes 5,000 per licensed deployment. Normal SaaS users see the lane names above rather than provider model IDs.

Case context

Case context is optional text you can add before starting an Agent run. Use it for details that are not obvious from packets alone, such as where the trace was captured, what the user reported, which systems are expected to be involved, or what changed before the issue started.

Good context is short and operational:

Captured on the client side during a reported website timeout. The user can
reach other sites. Focus on whether the failure is local, policy-related, or a
server-side delay.

Agent uses this context to focus the investigation, but packet evidence remains the source of truth for findings.

Reports and exports

Agent can save a structured final report for a completed investigation. The report keeps the narrative answer, findings, evidence references, model/session details, and capture context together so the work can be reopened from the Agent stream or the shared AI Analyses history page.

Saved reports can be exported as HTML or JSON where report export is enabled. PDF export is tracked separately and is not required for the SaaS launch path.

The report export action is available from the focused report view after a report has been generated and saved. Deployments with configured mail delivery can also offer requested email delivery for the saved final report, subject to plan entitlement and consent rules.

Report watermarking

Every saved Agent report export includes provenance metadata intended to make resale, redistribution, or leak investigation easier. The watermark is included in JSON metadata and rendered into HTML exports.

Watermark metadata includes:

  • report ID
  • user ID
  • organization ID when available
  • capture ID and capture name
  • generated timestamp and export timestamp
  • deployment ID
  • license ID
  • deployment mode
  • app version and build
  • derived watermark ID

Watermarking is a traceability control, not encryption or DRM. It helps identify where an exported report came from, but it does not prevent an authorized viewer from copying text or screenshots.

When not to start with Agent

  • Use Copilot if you want an interactive conversation.
  • Stay in the packet list if you already know the exact filter or frame range you need.
  • Use Raw-First Captures when a capture has been uploaded or migrated but PacketSafari Triage has not run yet. Agent can use Fast answer for bounded packet questions, but triage summaries and enriched trace tools are intentionally unavailable until processing completes.

Agent and Copilot results also appear in the shared AI Analyses history page.