Files
krow_backend/skills/anomaly-detection.md
2026-08-28 12:21:44 +05:30

2.7 KiB

id, name, description, category, pages, status, version, triggers, owliver
id name description category pages status version triggers owliver
anomaly-detection Anomaly Detection Surface activity that departs from this workspace's own pattern — and stay quiet when nothing does. operations
activity
control-center
active 1
anomaly
anomalies
anomalous
unusual
out of pattern
suspicious
enabled suggestions capabilities responses
true
label capability
Is anything unusual? insight
label capability
Show the signals table
summary
insight
list
table
stats
summary insight list table stats
title source
Activity signals activity.signals
title source
Unusual activity activity.signals
title source
Signals activity.signals
title source
Signals activity.signals
title source
Activity signals activity.signals

Anomaly Detection

Purpose

  • Surface activity that departs from this workspace's own baseline.
  • Explain each signal rather than only naming it.
  • Report nothing when nothing departs, so a signal keeps its meaning.

Capabilities

  • Detect concentration, bursts, off-hours activity, silence and privileged-action share.
  • Report how many signals are currently raised.
  • Explain what each one means.

Data

Reads activity.signals, which is the same detection the assistant's own greeting counts — one implementation in lib/activitySignals.js, so "two unusual patterns" means the same two wherever it is said.

Analysis

Five patterns are checked against this workspace's own history:

  1. Concentration — one account is responsible for half or more of events.
  2. Burst — more than three actions from one account inside one hour.
  3. Off-hours — activity before 06:00 or after 22:00.
  4. Silent — a log that has events but nothing in the last 24 hours.
  5. Privileged share — more than 30% of events change who is employed or what is being hired for.

Only patterns that clear their threshold are reported. A workspace with nothing unusual returns no signals, not a low-severity note.

Output

A count of raised signals, and one row per signal explaining what triggered it with the figure behind it.

Limitations

  • A signal is a deviation from a baseline, not a verdict. On a live deployment most resolve to an integration, a bulk import or a busy afternoon. Nothing here asserts wrongdoing.
  • Thresholds are fixed, not learned. A workspace whose normal pattern is one busy account will report concentration every time it is asked.
  • The baseline is the whole activity log, not a rolling window, so a young workspace has little to compare against.