metric-anomaly-detection

$npx mdskill add Significant-Gravitas/skills-catalog/metric-anomaly-detection

An anomaly is a signal that needs review, not proof of a problem or a cause.

SKILL.md

.github/skills/metric-anomaly-detectionView on GitHub ↗
---
name: "metric-anomaly-detection"
description: "Flag metric anomalies against declared baselines while separating data faults, expected seasonality, and real business changes."
triggers: ["metric anomaly", "spike", "drop", "outlier", "unexpected KPI change"]
version: "1"
---

# Metric anomaly detection

An anomaly is a signal that needs review, not proof of a problem or a cause.

## Set the detection rule first

Record the metric version, grain, eligible population, timezone, expected data
delay, baseline window, known seasonality, and alert threshold. Use a rule the
owner supplied or explain the proposed rule before applying it. Keep absolute
and relative thresholds when low volumes can distort rates.

## Check the data before the business

For every alert, test:

1. extract freshness and missing partitions;
2. schema or event-version changes;
3. duplicate or lost rows;
4. numerator and denominator movement;
5. timezone, calendar, holiday, and billing-cycle effects;
6. one large account, order, or segment dominating the move;
7. known release, campaign, price, or policy changes from supplied records.

Compare against more than one useful baseline when available: prior period,
same weekday or season, and a recent range. Do not use a model or threshold that
you cannot explain in the report.

## Return an anomaly card

Give metric, observed and expected value, size of difference, affected period,
sample, segment concentration, quality-check result, confidence, ranked
hypotheses, and one disproof test per hypothesis. Mark status as data issue,
expected pattern, possible business change, or unresolved.

Track alert status and owner. Do not close an alert because the metric returned
to normal; record whether anyone found a cause.

## Safety rules

Never label fraud, misconduct, or customer harm from an aggregate anomaly alone.
Do not expose individual records unless an approved investigation needs them.
Never hide a false positive or tune the rule after the event without recording
the change.

More from Significant-Gravitas/skills-catalog

SkillDescription
account-health-and-qbrsUse when a support account wobbles or a quarterly business review looms: read the health signals, run the success plan, and prep the review from evidence.
accounts-receivable-follow-upReview open receivables and draft factual, staged payment follow-ups without inventing status or contacting a customer.
ad-copy-variantsWrite ad variants that each test one idea, within platform limits and supported claims.
alex-getting-startedUse on the first conversation with Alex, or whenever their memory has no product preferences yet: learn what the user is building and who for, where specs, roadmap and numbers live, who decides dates and scope, and get them to a first real product deliverable.
alliance-co-commercializationUse when a strategic alliance needs joint selling governance: operating model, joint targeting, steering prep, and milestone accountability.
anika-getting-startedUse on the first conversation with Anika, or whenever their memory has no partnership preferences yet: learn which partners and alliances the user owns, what motion they run, and get one real partner read on screen in the same session.
assure-partner-led-deliveryUse when partners deliver client work in your name: own the in-flight book, run the weekly delivery review, and rescue engagements before clients feel it.
automate-finance-reportingUse to connect a number source, map an export into the finance ledger, or QA a sheet: the column mapping, the dedupe key, the load summary, and the checks that must pass before a read ships.
billing-refunds-and-exceptionsUse when money is on the table: verify the charge, check the policy, and stage a refund or exception draft that stops at the owner's yes.
board-and-investor-metrics-briefPrepare a concise board or investor metrics brief with definitions, sources, comparisons, drivers, risks, and decisions needed.