What runs today
POST /v1/anomalies/detect is an authenticated, explicit detection run. It is not an always-on background monitor. A caller must schedule or invoke it. It evaluates the requesting account’s data for:
The endpoint persists findings and replaces that account’s unacknowledged findings from the previous run. Acknowledged findings remain. The separate
/v1/anomaly/rules catalog lists additional built-in definitions, but those definitions are not all evaluated by this detector. Custom rules and /v1/anomaly/channels are configuration records; the legacy detector does not execute custom rule conditions or dispatch to channel records. Do not rely on either as an active security control.
Account response policy
WithIRREGULARITY_RESPONSE_POLICY_ENABLED=true, the account can choose one response for this detector:
The mode applies to the whole account, not an individual agent or grant. It does not turn off manual revocation, independent policy checks, or other security controls. A policy change is recorded in account history and emits an
irregularity.policy.updated event on a best-effort basis. If the flag is off, the policy endpoints return 404 and the detector retains its previous automatic-revocation behavior. If the flag is on but policy state is unavailable, detection fails closed with 503.
Running and reviewing detection
responseMode, total, autoRevokedGrants, and anomalies. Use GET /v1/anomalies to read persisted findings and PATCH /v1/anomalies/{id}/acknowledge to acknowledge one. The separate /v1/anomaly/alerts routes provide the alert lifecycle (open, acknowledged, resolved).
When the response-policy flag is enabled, each persisted finding from a detection run emits an anomaly.detected event. Subscribe through the existing event stream or a standard Grantex webhook subscription for that event type. Delivery is best-effort: query stored findings if delivery is critical to your workflow. Creating a record under /v1/anomaly/channels does not send Slack, email, or webhook notifications. PagerDuty and Datadog are not accepted channel types there.
GET /v1/anomaly/metrics?window=24h returns aggregate stored-alert counts. Supported windows are 1h, 6h, and 24h; this endpoint is distinct from the Prometheus /metrics endpoint.
For rollout and a runnable example, see Irregularity Detection Setup. Response-policy helpers are published in TypeScript @grantex/sdk@0.8.2, Python grantex==0.7.2, and Go v0.4.3. See Release Status.