Evidence the run may read
- Anomaly definition and time series
- Metric definition and dimensional data
- Recent source, pipeline, and business-event context
Decompose an anomalous movement across dimensions and source changes and prepare ranked explanations with uncertainty.
Search intent: AI agent for data anomaly investigation
An approved metric or dataset shows a material unexplained anomaly.
data owner
The metric owner approves the explanation, external narrative, and any corrective action.
material anomalies with reviewed explanation (percent). Measure detected material anomalies with an owner-approved evidence summary.
Each stage produces an artifact another stage can inspect. The final node is a person, not an autonomous write to an external system.
Validate and normalize the data anomaly investigation inputs.
Produce the magnitude and segment decomposition.
Produce the ranked evidence-linked explanations.
Challenge the data anomaly investigation result and prepare an approval packet.
The metric owner approves the explanation, external narrative, and any corrective action.
Source material is read-only. Drafts land in a case-specific output path. Tools may read or propose; the human gate owns the external write.
workspace/data/data-anomaly-investigation/inputs/**Read only the evidence attached to this workflow instance.
workspace/data/data-anomaly-investigation/outputs/**Write drafts and evidence artifacts without modifying source records.
data:data-anomaly-investigation:read-or-proposeInvoke only tools explicitly granted for this run; external writes remain gated.
The blueprint starts private, caps its DAG, disables replanning, and exposes no public endpoint. Add only the tools and data adapters this workflow has approved.
name: data-data-anomaly-investigation
version: 0.1.0
entrypoint: agent:BlueprintAgent
expose:
public: false
composition:
planning: deterministic_dag
max_nodes: 6
max_parallel: 3
max_replans: 0Every material conclusion cites an input artifact or a scoped tool result from this run.
The output separates correlation from cause and quantifies how much of the anomaly each supported factor explains.
The run stops at a proposal and records the human decision before any external side effect.
Containment: Return a partial result with unresolved items; do not broaden scope or perform an external write.
Operator: Attach the missing evidence, narrow the brief, or explicitly approve a new scoped run.
Containment: Stop the affected branch and preserve completed artifacts in the case output workspace.
Operator: Grant only the missing resource or continue with that branch marked out of scope.
Current platform receipts sign caller identity or classification, skill, bounded input evidence, verified grant IDs when present, outcome or result preview, and timing. Optional file, tool, artifact, handoff, evaluation, and review fields require separate instrumentation and are not populated by default. Price, fees, payouts, and later human approvals remain separate platform records.
The example uses only fields populated by the current platform sealing paths. It is illustrative, not a record of a real customer run.
{
"receipt_id": "rcpt_01J...",
"schema_version": 1,
"agent_name": "data-data-anomaly-investigation",
"caller": "user:workflow-owner",
"task_id": "case_data_anomaly_investigation",
"skill_name": "data_anomaly_investigation",
"input_hash": "4d7c...9a2f",
"grant_ids": [
"grt_case_inputs",
"grt_tool_propose"
],
"status": "ok",
"result_preview": "Output prepared: Magnitude and segment decomposition. Human decision remains separate.",
"elapsed_ms": 4218
}Correlate a data-quality alert with pipeline, lineage, freshness, and change evidence and prepare a bounded response packet.
Compare a proposed metric with source fields, grain, filters, time rules, and existing definitions before governance approval.
Review a dashboard against approved metric definitions, queries, filters, freshness, accessibility, and decision purpose.
Deploy the workflow as a bounded internal agent, verify its outputs and the receipt fields actually emitted, then expand only the scopes your acceptance test proves it needs.