Skip to main content

What runs today

POST /v1/anomalies/detect is an authenticated, explicit detection run. It is not an always-on background monitor. A caller must schedule or invoke it. It evaluates the requesting account’s data for: The endpoint persists findings and replaces that account’s unacknowledged findings from the previous run. Acknowledged findings remain. The separate /v1/anomaly/rules catalog lists additional built-in definitions, but those definitions are not all evaluated by this detector. Custom rules and /v1/anomaly/channels are configuration records; the legacy detector does not execute custom rule conditions or dispatch to channel records. Do not rely on either as an active security control.

Account response policy

With IRREGULARITY_RESPONSE_POLICY_ENABLED=true, the account can choose one response for this detector: The mode applies to the whole account, not an individual agent or grant. It does not turn off manual revocation, independent policy checks, or other security controls. A policy change is recorded in account history and emits an irregularity.policy.updated event on a best-effort basis. If the flag is off, the policy endpoints return 404 and the detector retains its previous automatic-revocation behavior. If the flag is on but policy state is unavailable, detection fails closed with 503.
Read the policy back before relying on alert-only mode. The portal’s Irregularities page provides the same account-level control when the operator has enabled it.

Running and reviewing detection

The response includes responseMode, total, autoRevokedGrants, and anomalies. Use GET /v1/anomalies to read persisted findings and PATCH /v1/anomalies/{id}/acknowledge to acknowledge one. The separate /v1/anomaly/alerts routes provide the alert lifecycle (open, acknowledged, resolved). When the response-policy flag is enabled, each persisted finding from a detection run emits an anomaly.detected event. Subscribe through the existing event stream or a standard Grantex webhook subscription for that event type. Delivery is best-effort: query stored findings if delivery is critical to your workflow. Creating a record under /v1/anomaly/channels does not send Slack, email, or webhook notifications. PagerDuty and Datadog are not accepted channel types there. GET /v1/anomaly/metrics?window=24h returns aggregate stored-alert counts. Supported windows are 1h, 6h, and 24h; this endpoint is distinct from the Prometheus /metrics endpoint. For rollout and a runnable example, see Irregularity Detection Setup. Response-policy helpers are published in TypeScript @grantex/sdk@0.8.2, Python grantex==0.7.2, and Go v0.4.3. See Release Status.

Ownership

Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership contact: sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.
Last modified on October 4, 2026