Files
krow_backend/skills/activity-analysis.md
2026-08-28 12:21:44 +05:30

100 lines
2.5 KiB
Markdown

---
id: activity-analysis
name: Activity Analysis
description: Break down what has happened in this workspace, by kind of event and by account.
category: operations
pages:
- activity
status: active
version: 1
triggers:
- activity breakdown
- event breakdown
- what kind of events
- events by type
- who did what
- busiest account
owliver:
enabled: true
suggestions:
- label: What kinds of event are there?
capability: table
- label: Summarize workspace activity
capability: summary
- label: Activity over recent periods
capability: flow
capabilities:
- summary
- stats
- table
- list
- progress
- flow
responses:
summary:
title: Activity breakdown
source: activity.breakdown
stats:
title: Activity breakdown
source: activity.breakdown
table:
title: Events by kind
source: activity.breakdown
list:
title: Events by kind
source: activity.breakdown
progress:
title: Events by kind
source: activity.breakdown
flow:
title: Activity over time
source: activity.breakdown
periods:
- last-7-days
- this-month
- previous-month
---
# Activity Analysis
## Purpose
- Report what has happened in this workspace and in what proportion.
- Count how many accounts are active.
- Show activity across recent periods.
## Capabilities
- Break events down by kind, with each kind's share.
- Count distinct event kinds and active accounts.
- Window the breakdown by period.
## Data
Reads `activity.breakdown`, which counts `UserActivity` records by `event_type`
and by account.
## Analysis
Events are counted by kind and expressed as a share of the total, because a raw
count means little without knowing whether twelve logins is most of the log or a
fraction of it.
Stored event names are machine keys; they are rendered as words so a reader does
not have to translate `hire_candidate` in their head.
## Output
Total events, number of distinct kinds, number of active accounts, then a row
per kind with its count and share.
## Limitations
- This describes the audit log, not the underlying records. Ten `apply_job`
events mean ten logged actions, which is not a guarantee of ten applications
surviving in the pipeline.
- Overlapping periods are deduplicated by event, so asking for today and the
last seven days together does not double-count today.
- This counts activity; it does not judge it. Whether a pattern is unusual is
Anomaly Detection's question.