detect/investigate/remediate is the right shape, but that last step decides whether people actually turn it on in prod. auto-fix the safe reversible stuff, hard stop before anything destructive, or it's just a dashboard nobody trusts. (biased: i build a k8s cli with that model)