PocketNOC Core diagnoses, compares, structures, plans and reports on IT incidents from measurements you provide (demonstration fixtures or a JSON bundle conforming to the Probe Protocol), via a Data Adapter.
It measures no real device and executes no action. Real measurement will go through a signed Probe (V2) that feeds the same schema without changing the engines; action execution will go through a control plane (OAuth, tenants, RBAC, audit) — later phases.
Principles: unmeasured ≠ healthy · correlation ≠ cause · no irreversible action without a verified backup and approval.
MCP endpoint: /mcp (or /api/mcp). Call pocketnoc_apercu, then most tools with {"set":"demo"} to load a demonstration incident (expired TLS certificate), or pocketnoc_liveops for the live view.