Overview
Theanomalies client provides automated anomaly detection for your authorization system. It identifies unusual patterns such as rate spikes, high failure rates, new principals, and off-hours activity.
Access the anomalies client via client.anomalies.
Published grantex==0.6.1 includes get_response_policy() and
set_response_policy("alert_only") for the account-wide response to findings
from detect(). The server must enable IRREGULARITY_RESPONSE_POLICY_ENABLED=true;
older PyPI versions do not include these methods. Alert-only retains
findings but skips this detector’s automatic agent-grant revocation. It does
not bypass other security controls.
Detect
Run anomaly detection across all agents and return any detected anomalies:DetectAnomaliesResponse
List
List stored anomalies. Optionally filter to show only unacknowledged anomalies:Parameters
The parameter is keyword-only.
ListAnomaliesResponse
Acknowledge
Acknowledge an anomaly to mark it as reviewed:Anomaly with the acknowledged_at timestamp set.
Anomaly Type
TheAnomaly frozen dataclass has the following fields: