--- id: anomaly-detection name: Anomaly Detection description: Surface activity that departs from this workspace's own pattern — and stay quiet when nothing does. category: operations pages: - activity - control-center status: active version: 1 triggers: - anomaly - anomalies - anomalous - unusual - out of pattern - suspicious owliver: enabled: true suggestions: - label: Is anything unusual? capability: insight - label: Show the signals capability: table capabilities: - summary - insight - list - table - stats responses: summary: title: Activity signals source: activity.signals insight: title: Unusual activity source: activity.signals list: title: Signals source: activity.signals table: title: Signals source: activity.signals stats: title: Activity signals source: activity.signals --- # Anomaly Detection ## Purpose - Surface activity that departs from this workspace's own baseline. - Explain each signal rather than only naming it. - Report nothing when nothing departs, so a signal keeps its meaning. ## Capabilities - Detect concentration, bursts, off-hours activity, silence and privileged-action share. - Report how many signals are currently raised. - Explain what each one means. ## Data Reads `activity.signals`, which is the same detection the assistant's own greeting counts — one implementation in `lib/activitySignals.js`, so "two unusual patterns" means the same two wherever it is said. ## Analysis Five patterns are checked against this workspace's own history: 1. **Concentration** — one account is responsible for half or more of events. 2. **Burst** — more than three actions from one account inside one hour. 3. **Off-hours** — activity before 06:00 or after 22:00. 4. **Silent** — a log that has events but nothing in the last 24 hours. 5. **Privileged share** — more than 30% of events change who is employed or what is being hired for. Only patterns that clear their threshold are reported. A workspace with nothing unusual returns no signals, not a low-severity note. ## Output A count of raised signals, and one row per signal explaining what triggered it with the figure behind it. ## Limitations - **A signal is a deviation from a baseline, not a verdict.** On a live deployment most resolve to an integration, a bulk import or a busy afternoon. Nothing here asserts wrongdoing. - Thresholds are fixed, not learned. A workspace whose normal pattern is one busy account will report concentration every time it is asked. - The baseline is the whole activity log, not a rolling window, so a young workspace has little to compare against.