AI Anomaly Detection & Triage
SecuritySystem monitors metrics continuously, AI detects deviations and classifies severity, routes alerts to appropriate human responders.
eventagenthuman
Why OSOP matters here
When your monitoring system pages someone at 3 AM, they need to know: Is this real? How severe? What changed? OSOP structures this entire flow so the on-call engineer gets context, not just noise.
Workflow Steps (5)
1
Continuous Monitoring
event2
Anomaly Detection
agent3
Classify Severity
system4
Send Alert
api5
Engineer Decision
humanConnections (4)
Continuous Monitoring→Anomaly Detectionsequential
Anomaly Detection→Classify Severityconditionalanomaly.detected == true
Classify Severity→Send Alertsequential
Send Alert→Engineer Decisionsequential
5
Steps
4
Connections
5
Node Types