Skip to main content

SaaS downloads: distinguish a spike from missing collection

Atlas home · Research path · Operational families · Anomaly models · Visual index

Maintained entry path added 1 October 2026. Results below are preserved reports dated 21 September 2026, not independent replication or new engine execution. Evidence provenance.

Hypothesis​

A user’s complete observed UTC-day download count differs materially from that same tenant/user’s historical daily counts. Missing collection must remain missing, not become an observed zero.

Required fields and collection​

Normalized table: DailyDownloads. These are adapter contracts, not vendor-native connector guarantees.

TenantId:string,UserId:string,Day:datetime,Count:long,Complete:bool

Full normalized contracts · Collection requirements.

Existing query and model​

Use the existing median/MAD example and explicit zero-MAD policy over comparable complete daily rows; preserve insufficient-history and missing-telemetry states instead of dropping the entity. Counts are audit events, not unique files or bytes.

Read the maintained query in context · Download unchanged KQL.

Positive and benign or boundary fixtures​

These rows come from the existing functional report. Expected and actual values describe selected logic behavior, not real-world accuracy.

Existing fixtureExpected outputReported observed outputStatus
bulk-zero-mad-spike[["above-baseline"]][["above-baseline"]]Reported pass
bulk-zero-mad-small-change[["within-baseline"]][["within-baseline"]]Reported pass
bulk-cold-start[["insufficient-history"]][["insufficient-history"]]Reported pass
bulk-missing-history-not-zero[["insufficient-history"]][["insufficient-history"]]Reported pass
bulk-current-outage[["missing-telemetry"]][["missing-telemetry"]]Reported pass
bulk-current-null-count[["missing-telemetry"]][["missing-telemetry"]]Reported pass

Original functional report · Exact fixture construction.

Safe reproduction and limits​

Start with the offline reproduction README. Its standard-library checks parse fixtures and recorded data; they do not execute attack commands. An engine replay is a separate opt-in workflow and was not run in this change.

Approved migrations, backups and workload changes can explain a spike. The fixture threshold is illustrative. Independent completeness monitoring and a native connector adapter are required; no SaaS production negative corpus or connector is validated.

The existing seeded 2688-entity-day study is synthetic. Its gate reduced FP 85→8 and TP 18→11. This is a constructed trade-off, not an enterprise benchmark. Eight reported KQL examples and 34 functional cases do not make the 54 catalog rows validated detectors. Full validation boundaries.