2.7 KiB
2.7 KiB
id, name, description, category, pages, status, version, triggers, owliver
| id | name | description | category | pages | status | version | triggers | owliver | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| anomaly-detection | Anomaly Detection | Surface activity that departs from this workspace's own pattern — and stay quiet when nothing does. | operations |
|
active | 1 |
|
|
Anomaly Detection
Purpose
- Surface activity that departs from this workspace's own baseline.
- Explain each signal rather than only naming it.
- Report nothing when nothing departs, so a signal keeps its meaning.
Capabilities
- Detect concentration, bursts, off-hours activity, silence and privileged-action share.
- Report how many signals are currently raised.
- Explain what each one means.
Data
Reads activity.signals, which is the same detection the assistant's own
greeting counts — one implementation in lib/activitySignals.js, so "two
unusual patterns" means the same two wherever it is said.
Analysis
Five patterns are checked against this workspace's own history:
- Concentration — one account is responsible for half or more of events.
- Burst — more than three actions from one account inside one hour.
- Off-hours — activity before 06:00 or after 22:00.
- Silent — a log that has events but nothing in the last 24 hours.
- Privileged share — more than 30% of events change who is employed or what is being hired for.
Only patterns that clear their threshold are reported. A workspace with nothing unusual returns no signals, not a low-severity note.
Output
A count of raised signals, and one row per signal explaining what triggered it with the figure behind it.
Limitations
- A signal is a deviation from a baseline, not a verdict. On a live deployment most resolve to an integration, a bulk import or a busy afternoon. Nothing here asserts wrongdoing.
- Thresholds are fixed, not learned. A workspace whose normal pattern is one busy account will report concentration every time it is asked.
- The baseline is the whole activity log, not a rolling window, so a young workspace has little to compare against.