> For the complete documentation index, see [llms.txt](https://knowledgebase.autorabit.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://knowledgebase.autorabit.com/product-guides/vault/vault-features/anomaly-detection.md).

# Anomaly Detection

## AutoRABIT Vault Anomaly Detection User Guide

## Purpose

AutoRABIT Vault Anomaly Detection monitors configured Salesforce data objects and metadata types for unusual changes. The feature helps identify unexpected activity, review affected records, compare snapshots, and roll back selected data changes where required. The workflow begins with configuration, continues through dashboard monitoring and anomaly review, and ends with rollback or comparison result tracking.

## Workflow Covered

* Configure anomaly detection for data and metadata.
* Select notification and exclusion settings.
* Monitor active or paused detection status from the dashboard.
* Review anomaly details and compare detected records.
* Submit rollback jobs and review rollback outcomes.
* Use job history, compare labels, export, and field-selection controls.
* Pause, stop, or restart anomaly detection.

Anomaly Detection is configured from the Anomaly Detection workspace. The configuration defines the source org, monitored data objects, monitored metadata types, threshold percentages, notification recipients, and excluded change owners. Once the configuration is saved, AutoRABIT Vault begins evaluating the selected scope based on the scheduled detection cycle.

![](/files/713244bf07a8ebc4f22c3e7cc9205103481c74da)

&#x20;                                                *Anomaly Detection landing page before configuration*

![](/files/b432eab77b6c90778bb9f61cf9e803cf2a3c9859)

&#x20;                                                *Config Creation window with Data threshold settings*

![](/files/ef21f15d72c91a8d0a5c38f577a3dc3cbb93f010)

&#x20;                                                *Data object selection for anomaly monitoring*

![](/files/bd6be492e5d4a122b7ed02b3451b4776182a49a7)

&#x20;                                                *Config Creation window with Metadata threshold settings*

![](/files/f1de1623093887fae52eee9a5d7435dcb8e928c9)

&#x20;                                                *Metadata type selection for anomaly monitoring*

![](/files/7c35e00b29a0f92d08014a28706740aaa30a00cc)

&#x20;                                                *Email Notifications and External Changes of Users options*

![](/files/12144032ace9c7a65e9b23a6602485b6d8f329a8)

&#x20;                              *User Details selection for excluding internal application users*

![](/files/4700f54837f259c86db7cc5b3223d356d3ac113d)

&#x20;                       *External Changes of Users option after selecting AutoRABIT Vault users*

![](/files/6002d82638783c4f2f0b5d0c84e335e4d5a32048)

&#x20;                                                *Salesforce User Details selection for excluding Salesforce users*

## Monitoring the Dashboard

After configuration is saved, the dashboard displays the detection status, source org, date range, and anomaly summary cards for Data and Metadata. The status indicator shows whether anomaly detection is active or paused. The dashboard presents detected data changes by severity so the investigation can continue from a summarized view into detailed records.

![](/files/e875ce8d35a6252ee78c999a868ce14fde5bacee)

&#x20;                                                *Anomaly Detection dashboard after configuration is saved*

![](/files/5b68d62a95de783c1414dfd1c54899138a005f74)

&#x20;                                                *Active anomaly detection status on the dashboard*

![](/files/ed51b565663f9fa54fd4f03e76b8abd25315cec0)

&#x20;                                                *Data anomaly summary chart for the selected object*

![](/files/673e5d61eb3ab398a69d8801996a967777cd3ffa)

&#x20;                                                *Data anomaly summary chart with severity filter*

## Reviewing Data Anomaly Details

The Data anomaly details view lists detected records for the selected source org, object, and detection period. Records can be reviewed in the table, selected for rollback, or compared for deeper field-level analysis. The system presents available actions based on the selected records and the current result state.

![](/files/6bc20e72238bcc42250dd8f1a20fd6ea4d9827db)

&#x20;                                                *Anomaly Details page with detected records*

![](/files/c1a5a8f9cbbc8c2ad2e3f1a11b9e52b973954372)

&#x20;                                                *Record selection for rollback action*

![](/files/11d99713e9a38cf6d51b257836690ff076f9f6ad)

&#x20;                                                *Rollback prerequisite and behavior information*

Rollback is initiated from the anomaly details or result views after eligible records are selected. AutoRABIT Vault presents a rollback summary before submission, including rollback options and the selected record count. Once confirmed, a rollback job is created and tracked from the Anomaly Rollback section until completion.

![](/files/7370b90acd0efa535238c37729294cf082a6ca12)

&#x20;                                           *Rollback Summary window with selected records and rollback preferences*

![](/files/5837c9fce8e821b7f965368325c64af607b0a97c)

&#x20;                                                *Rollback job submitted confirmation*

![](/files/58df7d953e253fc1782a1eec797f827e19897805)

&#x20;                                                *Anomaly Rollback job list*

![](/files/fbb39a7389070308ea74d615a36512679b9e00ec)

&#x20;                                                *Rollback job actions and progress tracking*

![](/files/68cf5a06a7a5389df592b15b0e73f683511f4343)

&#x20;                                                *Rollback result details with Follow Records tab*

![](/files/a17cff67bf1ca2c0abea04f5df51ee123b1ff7a5)

&#x20;                                                *Rollback result details with Outcome Records tab*

![](/files/81c438f1e0759f0fe71e1639860baa19924bc2c1)

&#x20;                                                *Completed rollback status in the rollback job list*

Comparison results are accessed from Anomaly Detection Job History. The results view shows detected changes by compare label and object. Field-level changes are highlighted in the results table, and detailed record comparison is available through the View Record action. Export and field-selection options support focused review of the result set.

![](/files/40cc2bb0b30b58c3e238629f828d41cd24f44e0c)

&#x20;                                                *Return to the Anomaly Detection dashboard after rollback review*

![](/files/d63d647b78c5e4542607d29fc52b851aa01c0214)

&#x20;                                                *Anomaly Details page with records selected for comparison*

![](/files/6c6a068e0725ff3dd0045acb7c849b9971ef0ae9)

&#x20;                                                *Comparison job submitted confirmation*

![](/files/2c49aa4db81243877eee5ef4ae0d6dcb2a29f139)

&#x20;                                                *Anomaly Detection Job History list*

![](/files/fbed59167557a0857a5ca8d801b0bced388765b1)

&#x20;                                                *Job history action for viewing comparison results*

![](/files/6e45a50e293550f23ec81f9eba3c072953aaa46a)

&#x20;                                                *Anomaly Detection Results page with comparison records*

![](/files/f401fc61833feeaaf7ffa8827c3fdf90273a7429)

&#x20;                                                *View Record action in the comparison results table*

![](/files/e540e5ae6bdf53711f729eee85368b9e36717282)

&#x20;                                                *View Record window showing field-level snapshot comparison*

![](/files/7e6c93e776d2d4ef46cfc030e929debb32e36875)

&#x20;                                                *Export option in Anomaly Detection Results*

![](/files/86d351fd081e71a5d271fcd4c7c05fafab875871)

&#x20;                                                *Export window with available export scope options*

![](/files/4ee6e7f3045e7354288612564c5b13a3662cbf95)

&#x20;                                                *Choose Fields option in Anomaly Detection Results*

![](/files/27e2348624e72497f20862b678beb1f01b266378)

&#x20;                                                *Fields selection window for result display*

![](/files/2250cef4242b6f201c9dc773bf5183d1ca432edf)

&#x20;                                                *Records selected for rollback from Anomaly Detection Results*

![](/files/2648ee053d1c1ae5fa405546f301799f9cda4aef)

&#x20;                                                *Rollback action from Anomaly Detection Results*

![](/files/5bde7c5dbecb7bcddd6ed0582f21c4e9378bbf3a)

&#x20;                                                *Rollback fields selection window*

![](/files/9a216beb13baf1da2825b347244762d8a637ccae)

&#x20;                                                *Rollback job submitted from comparison results*

Anomaly Detection Job History maintains the comparison and rollback activity initiated from the anomaly workflow. Each job entry provides status, timing, and action controls. Compare label actions open detailed field-level status information for the selected compare run.

![](/files/d398ed2be539f5322582b58894531f660e15ae4f)

&#x20;                                                *Job History list after rollback submission from results*

![](/files/84b6aef96194fb142fc1ae2f6c49e93fb9a67cf4)

&#x20;                                                *Job History action for compare label review*

![](/files/85bd705c4a415d6f47ee471d8d814a0ee8c622c9)

&#x20;                                                *Compare Label window showing field-level status*

![](/files/71f5574fd4770e6510a35cca898aacf303c2ba4c)

&#x20;                                                *Job History action for detailed compare label review*

![](/files/85bd705c4a415d6f47ee471d8d814a0ee8c622c9)

&#x20;                                                *Compare Label window with scrollable field status list*

## Pausing, Stopping, and Restarting Detection

Anomaly detection can be temporarily paused until a selected date or permanently turned off. A confirmation message appears before permanent changes are applied. When detection is restarted, the dashboard returns to an active monitoring state and allows the detection date range to be selected again.

![](/files/bf85360c3660bb72ea6156c3518bd75ede3443b5)

&#x20;                                                *Date picker for changing the dashboard date range*

![](/files/3d94ae83e330443e2311247f0eba48c2537ff497)

&#x20;                                                *Pause anomaly detection date selection on the dashboard*

![](/files/78a43595f65e534a42862a5f5cdcdf9c0f254bfd)

&#x20;                                                *Save action for pausing anomaly detection until a selected date*

![](/files/3bbd43849710b6811833ff68029e58f287662eb5)

&#x20;                                                *Active status after date-based anomaly detection control*

![](/files/995576acd5b132e5475f3fe100503c3ccb15598d)

&#x20;                                                *Turn off anomaly detection permanently option*

![](/files/711695e353b0bf7376e42abcd090b8867edc10ca)

&#x20;                                                *Confirmation window for turning off anomaly detection permanently*

![](/files/b68daa814a679296470fb3ae9fa0b645bcabcc90)

&#x20;                                                *Stopped anomaly detection status after permanent turn off*

![](/files/7407f90f4b4eb5e4ed69d504340f47b7875093f9)

&#x20;                                                *Confirmation window for restarting anomaly detection*

![](/files/8ef5954b88607ff749718fdc253b1cbd517f736f)

&#x20;                                                *Date picker available after anomaly detection is restarted*

## Result

After the workflow is completed, AutoRABIT Vault maintains the anomaly configuration, displays the current monitoring state on the dashboard, stores comparison jobs in job history, and tracks rollback jobs separately. This provides a controlled path to identify suspicious changes, verify field-level differences, and restore selected data where required.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://knowledgebase.autorabit.com/product-guides/vault/vault-features/anomaly-detection.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
