Anomaly Detection flags unusual sales patterns automatically, surfaced in Lark so your team can catch issues without digging through reports.
This article covers what you'll see once Anomaly Detection is set up.
Available Anomalies to Detect
When you create the base, you'll enable the anomaly types you want and set their thresholds in the Rules section.
Rule | What it does |
Frequent Customer Transactions | Alerts when a customer's transactions in a day exceed the threshold you set, across the selected stores |
Excessive Voids | Alerts when a store's void transactions in a day exceed the threshold you set |
Excessive Returns | Alerts when a store's return transactions in a day exceed the threshold you set |
Zero Sales for a Day | Alerts when a selected store records no sales for a full day |
Every rule except Zero Sales for a Day has an editable threshold (e.g., "5 voids"). You can turn each rule on or off independently.
How Detection Works
Anomaly Detection doesn't run in real time. Instead, a scheduled job runs every day at 10 AM, checking the previous day's data against your enabled rules. Anything that crosses a threshold gets logged as a new alert.
What's inside your Anomaly Detection base
Your base contains one table:
Table | What it shows you |
Alerts Log | Every anomaly type detected across your company, logged as a permanent record |
There is no 'Staff Name' prefilled for the Zero Sales Anomaly as no staff perfomed any sales.
Automatic alerts and summaries
Anomaly Alert Task Workflow: creates a Lark task the moment a new anomaly is detected, so it doesn't go unnoticed.
Weekly Anomaly Summary: a weekly, AI-generated recap of that week's anomalies, sent to whichever base users you choose.
- Resolved Date Automation: once an alert's Status is set to Resolved, its resolved timestamp is filled in automatically.
These don't run out of the box — each one needs to be manually enabled before it will start working.
Setting permissions
This base is mainly used by whoever investigates and resolves anomalies, not every outlet manager. Access is set up by your IT administrator in Lark, the same as any other base.
The following permission settings are recommended for Anomaly Detection base:
Lock every field except Status, Resolved At. These are the field meant to be edited. Everything else is system-filled and shouldn't be changed manually.
At the top of the base, find and click this icon to turn on advanced permissions.
Set that only "Status" and "Resolved At" field may be editable
Good to know- Detection runs once a day at 10 AM, checking the previous day's activity. It isn't real-time.
- Only data from after the base was created will appear. Nothing from before that is backfilled.