I recently ran into an issue with a root aggregate becoming 100% full leading to a failover while blocks were reclaimed. The underlying problem was that the root volume became >100% it's capacity due to delayed frees (increased due to heavy churn in the root volume).
We've manually gone through several other storage nodes' root vol footprint data to try to locate any other instances. This is fairly labor intensive so was hoping that Harvest might be able to help here.
NOTE: root vol is thick provisioned so this always appears to be completely consumed from aggr0's perspective. In order to know a thick provisioned flexvol's actual utilization, vol show-footprint command can show actual util -