Available with an Attri deployment

Cost spikes and policy breaches,filed with the evidence.

Every morning an OpenWatch agent reviews your organisation's Claude usage against its own baselines and your written AI policy. Each finding becomes a ticket that cites the sessions behind it.

An OpenWatch anomaly ticket for a cost spike, showing the baseline comparison, status, due date, five cited sessions and the ticket history

Usage reports get skimmed.Problems get found late.

  1. 01

    Nobody checks usage every day

    Dashboards show what happened if someone looks. Most weeks, nobody does until something goes wrong.

  2. 02

    The AI policy lives in a PDF

    Staff sign it once. Nothing checks real prompts against what it actually says.

  3. 03

    Alerts without evidence get ignored

    A number going up isn't actionable. The sessions and messages behind it are.

Three checks

Run every morning,or whenever an admin asks.

Cost spikes

Spend that jumps past its baseline

Each day's spend is compared with the 7-day mean. Anything more than three standard deviations above it, and over $1, becomes a finding. Five times the baseline is marked high priority.

  • 7-day rolling baseline
  • High priority above 5× baseline
  • Cites the top five sessions behind the spike

Unusual usage

Tool use that doesn't look like last week

Tool calls are compared with the baseline median. More than double it, and over 50 calls, is flagged so someone can look before it becomes a pattern.

  • Median-based tool-call baseline
  • Thresholds set per deployment
  • The same finding isn't filed twice within 7 days

Policy checks

Your AI policy, checked against real prompts

An admin uploads your AI usage policy in plain language. Claude reads recent prompts against it and files a ticket for each likely breach, citing the messages involved. Every version of the policy is kept.

  • Plain-language policy with version history
  • Reviews up to 1,000 recent prompts per run
  • Each finding cites the messages involved

Built to be trusted,not just to be loud.

  • Daily schedule

    Scans run each morning and pick up where the last one stopped.

  • Run on demand

    Admins can start a scan at any time from the dashboard.

  • Adjustable thresholds

    Baselines and multipliers are configuration, set for your deployment.

  • Tickets with citations

    Each finding lands as a ticket that links to the sessions and messages behind it.

  • No duplicate noise

    A finding already filed in the last 7 days isn't filed again.

  • Capped cost per run

    Each anomaly run is limited to $1 of Claude usage.

How it runs.

  1. Upload your AI policy

    An admin adds the policy in plain language. Changes create a new version; old ones are kept.

  2. Let the morning scan run

    The agent checks spend, tool use and prompts against baselines and the policy.

  3. Work the tickets

    Findings appear as tickets with a 3-day deadline and citations, ready to triage in the dashboard.

How each check decides.

The rules are plain enough to explain to an auditor.

CheckComparesFlags whenPriority
Cost spikeDaily spend with its 7-day meanMore than 3 standard deviations above, and over $1High above 5× baseline
Unusual usageTool calls with the baseline medianMore than 2× the median, and over 50 callsSet per finding
Policy checkRecent prompts with your written policyClaude judges a likely breachSet per finding

Thresholds are configured per deployment. Findings are deduplicated for 7 days.

Questions about anomaly detection

Does it send alerts to email, Slack or PagerDuty?

Not today. Findings are filed as tickets in the OpenWatch dashboard, where your team triages them.

Is the policy check a PII or PHI classifier?

No. Claude reviews prompts against the policy you write. It isn't a trained classifier, and it won't catch what your policy doesn't describe.

Can we change the thresholds?

Yes. The baseline multipliers and minimums are configuration values for your deployment.

What does a scan cost to run?

Each anomaly run is capped at $1 of Claude usage.

Is anomaly detection open source?

Not yet. It runs in Attri deployments. The public repository exposes past agent runs and their outputs through its API.

Someone will ask what happened.Have the answer ready.

Run OpenWatch on sample data in minutes, or have Attri deploy it inside your cloud with live data from your organisation.