Overview
Understand issues and anomalies
Distinguish rule-based issues from behavioral anomalies and decide which record to inspect first.
Last reviewed September 12, 2026
Investigation overview
Investigate connects a signal to the provider, resource, session, timing, network, capability, and policy context needed for a decision. Start from an Issue or Anomaly, confirm scope and recurrence, inspect linked records, assign an owner, and record the disposition.
What to review
Use the following table to understand how each area supports the task.
| Area | How to use it |
|---|---|
| Signal-to-context workflow | Compare the signal with the affected entity, linked session, timing, and expected behavior before setting its disposition. |
Issues overview
Issues are structured findings about a page or resource. Filter the Issues list by Open, Acknowledged, or Closed; narrow by page or resource type and severity; then use the first-seen and last-seen context to choose the record that needs review.
What to review
Use the following table to understand how each area supports the task.
| Area | How to use it |
|---|---|
| Search | Narrow the current project’s records before interpreting totals or opening a detail view. |
| Severity | Compare the signal with the affected entity, linked session, timing, and expected behavior before setting its disposition. |
| Type | Compare the signal with the affected entity, linked session, timing, and expected behavior before setting its disposition. |
| Status | Read the state together with its timestamps and owner action; a workflow state does not erase the original observation. |
| Timing | Compare like-for-like sessions and treat captured timing as context, not a complete causal proof. |
Anomalies overview
Anomalies surface behavioral or performance deviations that merit review. Use status and severity filters to reduce the list, then inspect the resource, detection time, behavioral analysis, sensitive access, network activity, event detail, and linked session context.
What to review
Use the following table to understand how each area supports the task.
| Area | How to use it |
|---|---|
| Behavioral | Compare the signal with the affected entity, linked session, timing, and expected behavior before setting its disposition. |
| Performance deviations | Compare like-for-like sessions and treat captured timing as context, not a complete causal proof. |
Compare issues and anomalies
Issues express a structured product finding; anomalies express a detected deviation from expected behavior. Both require context and can move through Open, Acknowledged, and Closed, but they answer different questions: an issue identifies a known condition, while an anomaly highlights behavior that changed or stands out.
What to review
Use the following table to understand how each area supports the task.
| Area | How to use it |
|---|---|
| Definitions | Compare the signal with the affected entity, linked session, timing, and expected behavior before setting its disposition. |
| Workflow | Compare the signal with the affected entity, linked session, timing, and expected behavior before setting its disposition. |
| When each appears | Compare the signal with the affected entity, linked session, timing, and expected behavior before setting its disposition. |