97 lines
2.7 KiB
Markdown
97 lines
2.7 KiB
Markdown
---
|
|
id: anomaly-detection
|
|
name: Anomaly Detection
|
|
description: Surface activity that departs from this workspace's own pattern — and stay quiet when nothing does.
|
|
category: operations
|
|
pages:
|
|
- activity
|
|
- control-center
|
|
status: active
|
|
version: 1
|
|
triggers:
|
|
- anomaly
|
|
- anomalies
|
|
- anomalous
|
|
- unusual
|
|
- out of pattern
|
|
- suspicious
|
|
owliver:
|
|
enabled: true
|
|
suggestions:
|
|
- label: Is anything unusual?
|
|
capability: insight
|
|
- label: Show the signals
|
|
capability: table
|
|
capabilities:
|
|
- summary
|
|
- insight
|
|
- list
|
|
- table
|
|
- stats
|
|
responses:
|
|
summary:
|
|
title: Activity signals
|
|
source: activity.signals
|
|
insight:
|
|
title: Unusual activity
|
|
source: activity.signals
|
|
list:
|
|
title: Signals
|
|
source: activity.signals
|
|
table:
|
|
title: Signals
|
|
source: activity.signals
|
|
stats:
|
|
title: Activity signals
|
|
source: activity.signals
|
|
---
|
|
|
|
# Anomaly Detection
|
|
|
|
## Purpose
|
|
|
|
- Surface activity that departs from this workspace's own baseline.
|
|
- Explain each signal rather than only naming it.
|
|
- Report nothing when nothing departs, so a signal keeps its meaning.
|
|
|
|
## Capabilities
|
|
|
|
- Detect concentration, bursts, off-hours activity, silence and privileged-action share.
|
|
- Report how many signals are currently raised.
|
|
- Explain what each one means.
|
|
|
|
## Data
|
|
|
|
Reads `activity.signals`, which is the same detection the assistant's own
|
|
greeting counts — one implementation in `lib/activitySignals.js`, so "two
|
|
unusual patterns" means the same two wherever it is said.
|
|
|
|
## Analysis
|
|
|
|
Five patterns are checked against this workspace's own history:
|
|
|
|
1. **Concentration** — one account is responsible for half or more of events.
|
|
2. **Burst** — more than three actions from one account inside one hour.
|
|
3. **Off-hours** — activity before 06:00 or after 22:00.
|
|
4. **Silent** — a log that has events but nothing in the last 24 hours.
|
|
5. **Privileged share** — more than 30% of events change who is employed or
|
|
what is being hired for.
|
|
|
|
Only patterns that clear their threshold are reported. A workspace with nothing
|
|
unusual returns no signals, not a low-severity note.
|
|
|
|
## Output
|
|
|
|
A count of raised signals, and one row per signal explaining what triggered it
|
|
with the figure behind it.
|
|
|
|
## Limitations
|
|
|
|
- **A signal is a deviation from a baseline, not a verdict.** On a live
|
|
deployment most resolve to an integration, a bulk import or a busy afternoon.
|
|
Nothing here asserts wrongdoing.
|
|
- Thresholds are fixed, not learned. A workspace whose normal pattern is one
|
|
busy account will report concentration every time it is asked.
|
|
- The baseline is the whole activity log, not a rolling window, so a young
|
|
workspace has little to compare against.
|