← All AI agents
auto_awesome Our AI vision · In development
security

AI Anomaly Detection

The agent watches access activity 24/7 for anomalies: a user starting to log in at 3am, a sudden surge of permission requests, access from an unusual location. Suspicious patterns surface to security in real time.

The challenge

Insider threat moves faster than monthly reports

hours-days

Typical time for insider activity to escalate before detection.

no baseline

Most companies have no per-user behavioural baseline.

SIEM gaps

SAP-specific patterns rarely caught by generic SIEMs.

SIEMs and DLPs catch some things. SAP-internal anomaly detection - the kind that knows what a normal day looks like for an FI clerk vs a Basis admin - usually falls between the cracks.

How the agent works

Human-in-the-loop, every step of the way

STEP 1
visibility

Observe

Agent maintains a behavioural baseline for every user: typical hours, typical TXs, typical systems, typical volumes.

STEP 2
psychology

Evaluate

Compares live activity to baseline in near-real-time. Scores deviation. Considers cohort patterns (does the whole team show the same shift?).

STEP 3
bolt

Act or escalate

Above threshold: alert to security with full context. Below: silent log for pattern learning.

STEP 4
verified

Human reviews

Security investigates the alert. Confirms or dismisses. Agent updates the baseline with feedback.

check_circle Every agent decision is explainable, reviewable and reversible.
In the platform

Where it shows up in smartGRC

Anomaly feed - last 24h
smartReport
schedule
3
Off-hours
trending_up
2
Permission spike
public
1
Geo anomaly
priority_high
Permission spike . T. Kowalski
Granted 8 new high-risk TX codes in 2h. User profile baseline: 0 changes / month.
15 May 03:14 . confidence 0.92
schedule
Off-hours activity . J. Nowak
Logged in at 23:47 (typical: 08:00-17:00). Ran F-02, F-04, FB02 from new IP.
14 May 23:47 . confidence 0.78
public
Geo anomaly . M. Wisniewska
Login from CZ, previous 90d: only PL. Routine TX run, but worth confirming with user.
15 May 10:08 . confidence 0.65
visibility
Unusual TX combination . A. Lewicki
Ran SU01 then SE38 within 4 minutes. Pattern not seen in 365d history.
15 May 11:22 . confidence 0.71

Illustrative mockup from the smartReport anomaly feed. Each entry shows a confidence score and the baseline it deviates from.

security

Insider threat signals

Agent baselines every user's normal pattern and surfaces deviations. Off-hours work, sudden permission expansion, geographic outliers.

psychology

False positives stay low

Confidence scoring filters noise. The team sees the anomalies worth investigating - not every coffee-break login from a new device.

play_circle

See anomaly feed

Open the interactive UX preview and explore the agent end-to-end.

Sample reasoning

How the agent thinks

Every decision is accompanied by readable reasoning so your team can audit and refine the agent's behavior over time.

HIGH ANOMALY anomaly-2031
$ evaluate
user: j.example · role: Z_FI_AP_VIEWER
activity: 21 transactions at 02:14
baseline: 0 logins outside 09-17 in 6 months
$ analysis
⚠ off-hours by 9+ standard deviations
⚠ TX volume 3x peak daily for this user
⚠ no team-wide pattern (only this user)
⚠ TXs include data exports
$ decision
HIGH ANOMALY · security alerted · session locked
TEAM PATTERN anomaly-2018
$ evaluate
cohort: 11 users in FI team
activity: weekend logins · all 11 users
baseline: weekend logins rare for this team
$ analysis
✓ cohort-wide pattern (not individual)
✓ matches calendar: year-end close
✓ TXs match year-end policy
✓ all logins from office IPs
$ decision
No alert · pattern explained · baseline updated
Expected impact

What this changes for your team

Estimates based on customer interviews and benchmarking from comparable agent deployments. Real numbers will vary.

<5 min
Alert time

Anomalies surface in near-real-time, not in next month's report.

Per-user
Behavioural baseline

Anomaly defined relative to each user, not a global threshold.

Cohort-aware
Fewer false alerts

Patterns shared across a team treated as legitimate, not flagged.

SAP-native
Beyond SIEM

Knows the difference between a normal FB60 day and an unusual one.

Related agents

Other agents in smartReport

Want to know when this ships?

We are looking for design partners. If this agent matches a real pain in your operations, let's talk.

Explore other AI agents