What is an anomaly alert?¶
An anomaly alert marks activity that differs from a model's expected pattern. “Unusual” means different from that baseline; it is not a synonym for malicious.
Models compare selected features with expectations¶
The platform may assess time, location, device, volume, sequence or account behaviour against the user's history, a peer group or a statistical model. A first-time action or rare combination can trigger even when every underlying event is legitimate.
Travel, new duties, incident response and software change alter normal behaviour. New accounts, seasonal patterns, missing logs and model updates can also weaken the baseline.
Identify the difference the model actually detected¶
Preserve the score or alert, explanation fields, contributing events, baseline period and model version where available. Establish which feature changed and whether the system calculated the result at event time or revised it later.
Compare the activity with known operational changes and independent records. The alert supports that the observed feature departed from the model's expectation; compromise requires evidence explaining why.
The point to remember
An anomaly alert identifies deviation from a model, so baseline quality and the changed feature control its meaning.