# Learning

> How 3AM gets better on your estate, what your team's answers do, and what it will never learn on its own.

Source: https://docs.3am.si/how-3am-decides/learning · Markdown: https://docs.3am.si/how-3am-decides/learning.md · All docs: https://docs.3am.si/llms.txt
3AM is an on-prem AI on-call engineer for regulated enterprises (https://3am.si).

Every closed incident teaches 3AM something about your estate. Over time it ranks the right causes first, stops
proposing fixes for causes that keep turning out wrong, and diagnoses failures it has already proven at once.

## Where it learns from

| Source                          | Counts as right                                              | Counts as wrong                                                |
| ------------------------------- | ------------------------------------------------------------ | -------------------------------------------------------------- |
| The outcome                     | A fix was made and the cause cleared                         | A fix was made and the cause didn't clear, or it failed        |
| Your team, on the incident page | **We did what 3AM proposed** or **We followed 3AM's advice** | **We did something else** (say what) or **Nothing was needed** |

Only incidents with a proven cause are judged. A "not proven" is never counted either way. Answering **What did your
team do?** on each incident is the most useful thing you can do: it also counts towards a service's readiness for L1
in the [digest](https://docs.3am.si/console/digest).

## What changes

* **Ranking.** Causes that have been right on your estate are weighed higher next time, and causes that have been
  wrong are weighed lower.
* **Confidence that means something.** Once enough incidents are judged, 3AM maps its own likelihoods to how often it
  has really been right here.
* **Demotion.** When the record shows a cause is right less than about 70% of the time, it's **demoted**. It still
  diagnoses, but no longer proposes a fix: the incident gives its advice to a person, and the console says why. A
  good record lifts the demotion again.
* **Learned patterns.** A cause 3AM proved by investigating (a change, or something the investigator found), that
  your outcome or your team confirmed, is kept as a **learned pattern**. The next time, it's diagnosed at once by
  re-running its own check.

## Learned fixes need a person

A learned pattern diagnoses straight away, but **its fix is never proposed until an admin promotes it**. On the
**Learned** page you can:

| Action           | Effect                                                                                                          |
| ---------------- | --------------------------------------------------------------------------------------------------------------- |
| Promote          | Its fix may be proposed. It still goes through System 1's review, the rehearsal, your policy and your approvers |
| Reject           | Its fix is never proposed; it keeps diagnosing                                                                  |
| Disable / Enable | Stop or resume using it                                                                                         |
| Delete           | Remove it                                                                                                       |

A pattern labelled wrong twice, and at least as often as right, is demoted automatically.

## What it never does

* Make anything proven. Learning changes ranking and can take a fix away; proof still comes from live checks.
* Add a fix on its own, or change your policy, autonomy or approvals.
* Send your incidents anywhere. Everything it learns stays in the install's data volume (`learning/`, `learned/`).

`GET /v1/learning` and `GET /v1/learned` show what it has learned ([API](https://docs.3am.si/reference/api)). Doctor's **Accuracy**
check shows the share of judged diagnoses that were right ([Health](https://docs.3am.si/operations/health)).
