SaaS downloads: distinguish a spike from missing collection
Atlas home · Research path · Operational families · Anomaly models · Visual index
Maintained entry path added 1 October 2026. Results below are preserved reports dated 21 September 2026, not independent replication or new engine execution. Evidence provenance.
Hypothesis
A user’s complete observed UTC-day download count differs materially from that same tenant/user’s historical daily counts. Missing collection must remain missing, not become an observed zero.
Required fields and collection
Normalized table: DailyDownloads. These are adapter contracts, not vendor-native connector guarantees.
TenantId:string,UserId:string,Day:datetime,Count:long,Complete:bool
Full normalized contracts · Collection requirements.
Existing query and model
Use the existing median/MAD example and explicit zero-MAD policy over comparable complete daily rows; preserve insufficient-history and missing-telemetry states instead of dropping the entity. Counts are audit events, not unique files or bytes.
Read the maintained query in context · Download unchanged KQL.
Positive and benign or boundary fixtures
These rows come from the existing functional report. Expected and actual values describe selected logic behavior, not real-world accuracy.
| Existing fixture | Expected output | Reported observed output | Status |
|---|---|---|---|
bulk-zero-mad-spike | [["above-baseline"]] | [["above-baseline"]] | Reported pass |
bulk-zero-mad-small-change | [["within-baseline"]] | [["within-baseline"]] | Reported pass |
bulk-cold-start | [["insufficient-history"]] | [["insufficient-history"]] | Reported pass |
bulk-missing-history-not-zero | [["insufficient-history"]] | [["insufficient-history"]] | Reported pass |
bulk-current-outage | [["missing-telemetry"]] | [["missing-telemetry"]] | Reported pass |
bulk-current-null-count | [["missing-telemetry"]] | [["missing-telemetry"]] | Reported pass |
Original functional report · Exact fixture construction.
Safe reproduction and limits
Start with the offline reproduction README. Its standard-library checks parse fixtures and recorded data; they do not execute attack commands. An engine replay is a separate opt-in workflow and was not run in this change.
Approved migrations, backups and workload changes can explain a spike. The fixture threshold is illustrative. Independent completeness monitoring and a native connector adapter are required; no SaaS production negative corpus or connector is validated.
The existing seeded 2688-entity-day study is synthetic. Its gate reduced FP 85→8 and TP 18→11. This is a constructed trade-off, not an enterprise benchmark. Eight reported KQL examples and 34 functional cases do not make the 54 catalog rows validated detectors. Full validation boundaries.