Understanding Anomaly Detection in Xilnex for Lark

Understanding Anomaly Detection in Xilnex for Lark

Overview

Anomaly Detection flags unusual sales patterns automatically, surfaced in Lark so your team can catch issues without digging through reports.

This article covers what you'll see once Anomaly Detection is set up.

Notes
Before you begin

You'll need a Anomaly Detection base already created. If you haven't set one up yet, see [Creating a Base in Xilnex for Lark].



Available Anomalies to Detect

When you create the base, you'll enable the anomaly types you want and set their thresholds in the Rules section.



Rule
What it does
Frequent Customer Transactions
Alerts when a customer's transactions in a day exceed the threshold you set, across the selected stores
Excessive Voids
Alerts when a store's void transactions in a day exceed the threshold you set
Excessive Returns
Alerts when a store's return transactions in a day exceed the threshold you set
Zero Sales for a Day
Alerts when a selected store records no sales for a full day

Every rule except Zero Sales for a Day has an editable threshold (e.g., "5 voids"). You can turn each rule on or off independently.



How Detection Works

Anomaly Detection doesn't run in real time. Instead, a scheduled job runs every day at 10 AM, checking the previous day's data against your enabled rules. Anything that crosses a threshold gets logged as a new alert.



What's inside your Anomaly Detection base

Your base contains one table:

Table
What it shows you
Alerts Log
Every anomaly type detected across your company, logged as a permanent record


There is no 'Staff Name' prefilled for the Zero Sales Anomaly as no staff perfomed any sales. 



Automatic alerts and summaries

  1. Anomaly Alert Task Workflow: creates a Lark task the moment a new anomaly is detected, so it doesn't go unnoticed.
  2. Weekly Anomaly Summary: a weekly, AI-generated recap of that week's anomalies, sent to whichever base users you choose.
  3. Resolved Date Automation: once an alert's Status is set to Resolved, its resolved timestamp is filled in automatically.
NotesThese don't run out of the box — each one needs to be manually enabled before it will start working.



Setting permissions


This base is mainly used by whoever investigates and resolves anomalies, not every outlet manager. Access is set up by your IT administrator in Lark, the same as any other base.

The following permission settings are recommended for Anomaly Detection base:

Lock every field except Status, Resolved At. These are the field meant to be edited. Everything else is system-filled and shouldn't be changed manually.

At the top of the base, find and click this icon to turn on advanced permissions. 

Set that only "Status" and "Resolved At" field may be editable



InfoGood to know
  • Detection runs once a day at 10 AM, checking the previous day's activity. It isn't real-time.
  • Only data from after the base was created will appear. Nothing from before that is backfilled.