Overview
Theanomalies sub-client provides automated anomaly detection for agent activity. It identifies unusual patterns such as rate spikes, high failure rates, new principals, and off-hours activity.
Detection runs when detect() is called; listing a built-in rule is not proof of continuous monitoring. With the server’s default-off IRREGULARITY_RESPONSE_POLICY_ENABLED=true rollout, repository-source SDK clients can select an account-wide response:
revoke_agent_grants mode revokes active grants for an implicated agent on a high/critical finding. alert_only persists findings without this detector’s automatic revocation; it does not disable other controls. getResponsePolicy() and setResponsePolicy() are published in @grantex/sdk@0.7.1 and require the default-off server rollout flag.
anomalies.detect()
Run anomaly detection across all agents and return any newly detected anomalies.Response: DetectAnomaliesResponse
string
ISO 8601 timestamp when detection was run.
number
Number of anomalies detected.
string
Account response mode used for this detection run.
number
Number of active grants revoked by this detector during the run.
Anomaly[]
Array of detected anomalies.
Anomaly types
Anomaly severity levels
anomalies.list()
List stored anomalies. Optionally filter to only unacknowledged anomalies.Parameters
boolean
When
true, only return anomalies that have not been acknowledged.Response: ListAnomaliesResponse
Anomaly[]
Array of anomaly objects.
number
Total number of anomalies matching the filter.
anomalies.acknowledge()
Acknowledge an anomaly by ID. This marks it as reviewed so it no longer appears in the unacknowledged list.Parameters
string
required
The anomaly ID to acknowledge.
Response: Anomaly
Returns the updated anomaly object with the acknowledgedAt timestamp set.
Anomaly object
string
Unique anomaly identifier.
AnomalyType
The anomaly type:
'rate_spike', 'high_failure_rate', 'new_principal', or 'off_hours_activity'.AnomalySeverity
Severity level:
'low', 'medium', or 'high'.string | null
The agent associated with the anomaly, if applicable.
string | null
The user associated with the anomaly, if applicable.
string
Human-readable description of the anomaly.
Record<string, unknown>
Additional context about the anomaly (e.g. request rates, thresholds).
string
ISO 8601 timestamp when the anomaly was detected.
string | null
ISO 8601 timestamp when the anomaly was acknowledged, or
null.