Cost Allocation & Showback Platform  ·  View 16 of 22  ·  5 · Runtime

Anomaly to Owner

An alert that cannot name a resource is a page to nobody, so attribution happens before routing.

Editable source SVG draw.io All views
Observe Daily allocated facts T+1 by 10:00 Rolling baseline 28-day, seasonal Detect Threshold + residual test 30% sustained Suppression window declared events Attribute Drill to changed dimension service, SKU, region Name the resources top contributors Route Resolve accountable owner Escalate to parent scope if unattributed Close Acknowledged & explained Feeds baseline accepted step change False positive recorded budget 5/team/quarter retune detector Anomaly to Owner — Detect, Attribute, Route, Close Data store Application we own Decision point Risk / gap failure / alternate An alert that cannot name a resource is a page to nobody, so attribution happens before routing. A suppressed detection is logged and closed without routing. v 1.0 · owner Platform Architecture · date 2026-09

Decisions

  • Detect on allocated facts, not on raw provider totals, so the alert already has an owner
  • Attribute to the most specific changed dimension the data supports before routing
  • Unattributed spend escalates to the parent scope's owner, never to a shared mailbox alone

False-positive discipline

  • Accepted step changes feed the baseline so the same growth is not alerted twice
  • Declared events (a migration, a load test, a launch) suppress detections, and every suppression is logged

Targets (stated assumptions)

  • A sustained ≥ 30% day-over-day increase detected and routed within 24 h
  • ≤ 5 false positives per team per quarter