Files
krow_backend/skills/anomaly-detection.md
2026-08-28 12:21:44 +05:30

97 lines
2.7 KiB
Markdown

---
id: anomaly-detection
name: Anomaly Detection
description: Surface activity that departs from this workspace's own pattern — and stay quiet when nothing does.
category: operations
pages:
- activity
- control-center
status: active
version: 1
triggers:
- anomaly
- anomalies
- anomalous
- unusual
- out of pattern
- suspicious
owliver:
enabled: true
suggestions:
- label: Is anything unusual?
capability: insight
- label: Show the signals
capability: table
capabilities:
- summary
- insight
- list
- table
- stats
responses:
summary:
title: Activity signals
source: activity.signals
insight:
title: Unusual activity
source: activity.signals
list:
title: Signals
source: activity.signals
table:
title: Signals
source: activity.signals
stats:
title: Activity signals
source: activity.signals
---
# Anomaly Detection
## Purpose
- Surface activity that departs from this workspace's own baseline.
- Explain each signal rather than only naming it.
- Report nothing when nothing departs, so a signal keeps its meaning.
## Capabilities
- Detect concentration, bursts, off-hours activity, silence and privileged-action share.
- Report how many signals are currently raised.
- Explain what each one means.
## Data
Reads `activity.signals`, which is the same detection the assistant's own
greeting counts — one implementation in `lib/activitySignals.js`, so "two
unusual patterns" means the same two wherever it is said.
## Analysis
Five patterns are checked against this workspace's own history:
1. **Concentration** — one account is responsible for half or more of events.
2. **Burst** — more than three actions from one account inside one hour.
3. **Off-hours** — activity before 06:00 or after 22:00.
4. **Silent** — a log that has events but nothing in the last 24 hours.
5. **Privileged share** — more than 30% of events change who is employed or
what is being hired for.
Only patterns that clear their threshold are reported. A workspace with nothing
unusual returns no signals, not a low-severity note.
## Output
A count of raised signals, and one row per signal explaining what triggered it
with the figure behind it.
## Limitations
- **A signal is a deviation from a baseline, not a verdict.** On a live
deployment most resolve to an integration, a bulk import or a busy afternoon.
Nothing here asserts wrongdoing.
- Thresholds are fixed, not learned. A workspace whose normal pattern is one
busy account will report concentration every time it is asked.
- The baseline is the whole activity log, not a rolling window, so a young
workspace has little to compare against.