--- id: activity-analysis name: Activity Analysis description: Break down what has happened in this workspace, by kind of event and by account. category: operations pages: - activity status: active version: 1 triggers: - activity breakdown - event breakdown - what kind of events - events by type - who did what - busiest account owliver: enabled: true suggestions: - label: What kinds of event are there? capability: table - label: Summarize workspace activity capability: summary - label: Activity over recent periods capability: flow capabilities: - summary - stats - table - list - progress - flow responses: summary: title: Activity breakdown source: activity.breakdown stats: title: Activity breakdown source: activity.breakdown table: title: Events by kind source: activity.breakdown list: title: Events by kind source: activity.breakdown progress: title: Events by kind source: activity.breakdown flow: title: Activity over time source: activity.breakdown periods: - last-7-days - this-month - previous-month --- # Activity Analysis ## Purpose - Report what has happened in this workspace and in what proportion. - Count how many accounts are active. - Show activity across recent periods. ## Capabilities - Break events down by kind, with each kind's share. - Count distinct event kinds and active accounts. - Window the breakdown by period. ## Data Reads `activity.breakdown`, which counts `UserActivity` records by `event_type` and by account. ## Analysis Events are counted by kind and expressed as a share of the total, because a raw count means little without knowing whether twelve logins is most of the log or a fraction of it. Stored event names are machine keys; they are rendered as words so a reader does not have to translate `hire_candidate` in their head. ## Output Total events, number of distinct kinds, number of active accounts, then a row per kind with its count and share. ## Limitations - This describes the audit log, not the underlying records. Ten `apply_job` events mean ten logged actions, which is not a guarantee of ten applications surviving in the pipeline. - Overlapping periods are deduplicated by event, so asking for today and the last seven days together does not double-count today. - This counts activity; it does not judge it. Whether a pattern is unusual is Anomaly Detection's question.