Copilot
PacketSafari Copilot is the interactive AI surface inside the analyzer. Use it when you want to ask follow-up questions, refine a hypothesis, or turn packet context into a conversational workflow.

Copilot is best when:
- you already have a question and want help answering it
- you want PacketSafari to use the selected packets as focused context
- you expect to iterate, refine, and ask follow-ups
When the exact Core generation is still queryable, Copilot can selectively use PacketQL advanced capture queries to compare or rank retained facts. PacketQL is bounded evidence retrieval; Copilot still explains the result and material conclusions remain tied to inspectable packets.
What Copilot is good at
- Summarising the current packet slice
- Suggesting filters or pivots from selected traffic
- Explaining likely failure patterns or suspicious activity
- Helping you turn packet observations into a clearer investigation path
How it differs from Upload Insights
- Upload Insights shows deterministic processing state and packet evidence as the capture becomes ready; it does not call a model.
- Copilot starts from your question and stays interactive.
If you want the first-pass orientation layer instead of a chat workflow, open Upload Insights.
Usage accounting
Every submitted Copilot question or follow-up consumes one Quick question. Lightweight standalone questions submitted through the Agent tab use this same allowance. Starting a new guided full Agent investigation instead consumes one Analysis run; follow-ups attached to that investigation are included in the run and do not consume Quick questions.
Opening Copilot, reading history, selecting packet context, or typing without submitting consumes nothing. Automatic retries, internal tool calls, and model calls are never counted as extra customer requests. The account usage view shows an individual SaaS user's used, remaining, limit, and reset date. In an organization, every member sees the same shared remaining allowance and owners/admins can inspect the member breakdown.
