Sherlocks AI vs Datadog Bits Investigation
An honest comparison for engineering teams choosing where their AI investigation should run, and what it should be able to see.
TL;DR. Datadog Bits Investigation and Sherlocks AI both investigate production incidents with AI, but they are built on opposite assumptions. Bits runs inside Datadog and reasons over Datadog's own telemetry, which is a strong fit if your whole observability stack already lives in Datadog. Sherlocks AI runs inside your own VPC and investigates across your existing tools, so your raw telemetry never leaves your network and you are not required to consolidate everything into one vendor first. Pick Bits if you are all-in on Datadog. Pick Sherlocks AI if you run a mixed stack or need investigation to happen inside your own environment.
If you are evaluating AI SRE tools and you already use Datadog, Bits Investigation is one of the first options you will hit. This is a straight comparison of the two, including where Datadog is genuinely the better choice. A comparison page that pretends the competitor has no strengths is not worth reading, so this one does not do that.
Quick comparison
| Dimension | Datadog Bits Investigation | Sherlocks AI |
|---|---|---|
| Where the AI runs | Datadog's cloud | Inside your own VPC |
| Data it reasons over | Datadog platform data (cross-tool sources in Preview) | Your existing stack, tool-agnostic |
| Architecture | One agent over Datadog telemetry | 16+ domain-specialized agents in parallel |
| Prerequisite | You must be on Datadog | No observability platform required |
| Pricing shape | Consumption-based AI Credits, on top of your Datadog bill | Flat, predictable plans |
| Best fit | Teams fully committed to Datadog | Mixed stacks and VPC-first teams |
What is Datadog Bits Investigation?
Bits Investigation, formerly announced as Bits AI SRE, is Datadog's AI investigation agent. It went generally available on December 2, 2025, as Datadog's first generally available AI agent, after testing across more than 2,000 customer environments, per Datadog's GA announcement.
The way it works is clean. When a Datadog monitor fires, Bits automatically launches an investigation without waiting for an engineer to ask. It builds multiple hypotheses about the cause, checks dependencies, and exposes its reasoning in an Agent Trace view that shows each tool it called and the intermediate analysis behind every step. It reasons over the full breadth of Datadog platform data: metrics, logs, traces, dashboards, deployment changes, source code, RUM, Database Monitoring, Network Path, and Continuous Profiler.
Datadog has kept shipping since GA. A March 2026 update made investigations roughly twice as fast, with most now finishing in three to four minutes depending on complexity, and widened the data Bits reads to the set above.
Give Datadog real credit here. If your telemetry already lives in Datadog, Bits is one of the easiest ways to add autonomous investigation to your stack. There is no new tool to learn, no context switching, and it sits on top of best-in-class high-cardinality data handling. For a team that is genuinely all-in on Datadog, that native access is a real advantage.
What is Sherlocks AI?
Sherlocks AI is a purpose-built AI SRE that investigates production incidents autonomously and tells your team what broke, why, and what to do next. It is Slack-native, so the investigation happens where your team already works, and it runs the moment an incident fires rather than waiting for an engineer to start digging.
Under the hood, it runs 16+ domain-specialized agents that work in parallel, a Database agent, a Kubernetes agent, and more, each an expert in one slice of the stack rather than one general model trying to cover everything. During an incident, those specialists investigate at once and their findings are correlated into a single timeline: logs, metrics, traces, deploys, and Kubernetes events pulled together into one clear picture of the failure.
What it offers comes down to three things. First, autonomous investigation to a confirmed root cause, not just an alert or a symptom. Second, deployment inside your own VPC, so raw telemetry never leaves your network. Third, a persistent memory of your environment, so recurring incidents get faster to resolve as it learns how your systems fail and how your team fixes them. It is built investigation-first, to reach the cause the way a senior SRE would, without requiring you to move your data anywhere.
Where does the investigation actually run?
This is the core difference, and it decides most of the rest.
Bits runs in Datadog's cloud. For it to investigate, your telemetry has to be in Datadog. That is fine for many teams and a real problem for others, specifically anyone with data residency requirements, strict security review, or a policy that raw production telemetry should not leave their environment.
Sherlocks AI runs the opposite way. It sits inside your own VPC with read-only access, so raw telemetry never leaves your controlled network. The investigation comes to your data instead of your data going to the investigator. For regulated industries and security-conscious teams, that single architectural choice is often the deciding factor, and it is one Bits cannot match by design, because Bits is a SaaS product living in Datadog's cloud.
What data can each one see?
Bits is deep on Datadog data and still narrow outside it. It reasons powerfully over the Datadog platform, but pulling context from outside tools such as GitHub, ServiceNow, Grafana, Splunk, Dynatrace, and Sentry remained a Preview capability rather than generally available as of Datadog's March 2026 update. So the honest summary is that Bits is excellent within Datadog and still maturing across a mixed toolchain.
Sherlocks AI is tool-agnostic by design. It investigates across your existing stack rather than requiring everything to funnel through one platform first. If you run Datadog for some things, Grafana for others, and cloud-native tooling elsewhere, that neutrality matters, because incidents rarely respect tool boundaries. Open standards like OpenTelemetry make that cross-tool reach practical.
What does it cost, and how predictable is it?
Datadog moved Bits onto a consumption-based AI Credits model, drawing from a pool shared across the Bits agents. Datadog puts average consumption at roughly 6.5 credits per investigation and bills only investigations that reach a conclusion, though actual consumption varies with complexity. Credit Datadog here too: this replaced a much more expensive per-investigation model and cut the effective cost per investigation substantially. The structural point still stands, though. Whatever the rate, the charge stacks on top of your existing Datadog bill for hosts, APM, logs, and RUM, and it scales with incident volume, so spend climbs during exactly the bad month when you are running the most investigations.
Sherlocks AI uses flat, predictable plans rather than per-investigation billing, so a bad week does not produce a surprise invoice. We are not going to pretend Sherlocks AI is always cheaper in absolute terms, that depends on your volume and your existing Datadog spend, but the shape of the pricing is easier to forecast because it does not move with your incident count.
What about vendor lock-in?
Bits deepens your commitment to Datadog. It is most valuable when you are fully invested, which is also what makes it a lock-in decision: the more you rely on Bits, the more the whole observability stack has to stay in Datadog.
Sherlocks AI does not require you to adopt or stay on any observability platform. It works with what you have. If you switch telemetry tools later, the investigation layer does not have to move with them.
When Datadog Bits is the right choice
To be fair and direct: choose Bits if your observability stack is fully consolidated in Datadog, you want zero context switching, and you are comfortable with consumption-based pricing that scales with incidents. For a Datadog-native shop that values one vendor and one pane of glass, Bits is a strong, well-executed option with the reliability and support of a large platform behind it.
When Sherlocks AI is the right choice
Choose Sherlocks AI if any of these are true: you run a mixed toolchain and do not want investigation gated on one platform, you need the AI to run inside your own VPC so raw telemetry stays in your network, you want predictable pricing that does not spike with incident volume, or you want an investigation-first tool with real, auditable investigations rather than an AI layer added onto an observability product. Faster, more reliable diagnosis is the goal, and where the AI runs and what it can see are what get you there. For the metrics behind that goal, see our guide on MTTR, MTTD, MTTA and MTTF, and for the deeper investigation method, our writeup on root cause analysis. Reliability benchmarks like the DORA and Google SRE references are a useful frame for both tools.
Detailed comparison
| Capability | Datadog Bits Investigation | Sherlocks AI |
|---|---|---|
| Deployment model | SaaS, runs in Datadog's cloud | Runs inside your own VPC |
| Data residency | Telemetry lives in Datadog | Raw telemetry stays in your network |
| Data it reasons over | Datadog platform data | Your existing stack, tool-agnostic |
| Cross-tool reasoning | Preview for GitHub, ServiceNow, Grafana, Splunk, Dynatrace, Sentry | Generally available across your tools |
| Agent design | Single agent over Datadog data | 16+ specialized agents in parallel |
| Investigation trigger | Automatic when a Datadog monitor fires | Automatic on incident, across sources |
| Kubernetes depth | Native Datadog K8s monitoring | Dedicated K8s agent, real published RCAs |
| Reasoning transparency | Agent Trace view | Full timeline with ruled-out hypotheses |
| Pricing model | AI Credits, about 6.5 per investigation, on top of Datadog bill | Flat, predictable plans |
| Cost predictability | Scales with incident volume | Fixed, does not spike in a bad month |
| Platform requirement | Requires Datadog | No observability platform required |
| Vendor lock-in | Deepens Datadog commitment | Portable, works with what you have |
| Data control | Data processed in Datadog's cloud | Stays in your own environment |
| Proof of investigations | Agent Trace view | Public, end-to-end RCA library |
| Best fit | Teams fully committed to Datadog | Mixed stacks and VPC-first teams |
The short answer
If your entire observability stack lives in Datadog and you want AI investigation with zero context switching, Datadog Bits Investigation is a strong, native choice. If you run a mixed toolchain, need the investigation to happen inside your own VPC, or want pricing that does not spike with incident volume, Sherlocks AI is the better fit. The deciding question is simple: do you want the investigation to live in Datadog's cloud over Datadog's data, or in your own environment across your whole stack?
Frequently asked questions
Is Bits Investigation the same as Bits AI SRE?
Yes. It is Datadog's AI investigation agent, which went generally available in December 2025.
Does Datadog Bits run in my environment?
No. It runs in Datadog's cloud and reasons over telemetry stored in Datadog.
Does Sherlocks AI require Datadog?
No. Sherlocks AI is tool-agnostic and runs inside your own VPC across your existing stack.
Can Bits investigate data outside Datadog?
Cross-tool reasoning over sources like GitHub, Grafana, and Splunk is a Preview feature, not generally available.
How is Sherlocks AI priced compared to Bits?
Sherlocks AI uses flat plans. Bits draws on consumption-based AI Credits, which Datadog averages at about 6.5 credits per investigation, on top of your existing Datadog costs.
How much does a Datadog Bits investigation cost?
Datadog bills Bits Investigation in AI Credits, averaging roughly 6.5 credits per investigation, and charges only for investigations that reach a conclusion. Actual consumption varies with the complexity of the investigation.
Which is better for a mixed toolchain?
Sherlocks AI, because it does not require consolidating your telemetry into one platform first.
Comparison based on publicly available information as of 2026. Datadog product names, pricing, and Preview versus GA status change frequently, so verify current details on Datadog's site before making a decision.