View anomaly details
When viewing the details of a specific anomaly, you have access to multiple resources that help you investigate and address the anomaly.
For Attribute usage anomalies, some cloud-specific features are not available on the details page. The Contributors table and the Investigate action, Explore in Reports, Add annotation, and Find in Cloud Diagrams, are not displayed. When no Investigate actions apply, the section is hidden from the side panel.
Required permissions
- Allocations Admin, Anomalies Viewer, Cloud Analytics User
View a cost anomaly
To view a specific cost anomaly:
-
Sign in to the DoiT console, select Policy and governance from the top navigation mega menu, and then select Cost anomalies.
-
On the Cost anomalies page, find the anomaly of interest.
-
Select View at the rightmost end of the anomaly entry to launch the cost anomaly details page.
An example anomaly based on billing data (daily granularity):

An example anomaly based on AWS CloudTrail events (Real-time anomaly, hourly granularity):

Summary

At the top of the anomaly details page, a header row displays the cloud provider logo, a title combining an account identifier and the service name, and a status chip indicating whether the anomaly is Active or Inactive. For Google Cloud anomalies, the title uses the Project ID when available; otherwise it uses the billing account name. For other providers, the title uses the billing account name when available, falling back to the project or account ID.
Below the header, the anomaly details page displays the following metrics:
-
Excess cost: The difference between the actual cost and the upper bound of the normal range, displayed prominently. For real-time anomalies, this value is labeled as an estimate. Next to the excess cost, the percentage by which the excess cost exceeds the expected maximum is displayed as
X%. -
Actual cost: The observed cost at the time the anomaly started.
-
Expected max: The upper bound of the normal cost range at the time the anomaly started.
-
Started at: When the anomalous usage began. For real-time anomalies, this includes the time.
-
Ended at: When the anomaly became inactive. Shows Ongoing if the anomaly is still active, or Expired if monitoring reached its time limit before the cost returned to its normal range. Hovering over Expired displays a tooltip with details about the time limit.
-
SKU: The Stock Keeping Unit associated with the anomaly. For service-level anomalies, shows the name of the contributing SKU when a single SKU is responsible, the number of contributing SKUs (for example, "3 SKUs") when multiple SKUs are involved, or an em dash when no SKU information is available. This field is not displayed for real-time anomalies.
For older anomalies that predate the current detection system, Actual cost and Expected max display a dash (—) and the deviation is hidden.
Side panel

On desktop, a side panel to the right of the main content area groups Details, Investigate, and Review status. On mobile, the same content is displayed inline below the header metrics. The Details section includes the following properties:
-
Project ID: The project or account associated with the anomaly. The label varies by provider, see Hierarchy property 2 in Provider-specific labels. For service-level anomalies, it shows the project or account ID when one resource is responsible, a provider-specific count when multiple contribute (for example, "3 projects" or "3 accounts"), or an em dash when no information is available.
-
Allocation: The allocations associated with the anomaly, if applicable. When an anomaly matches a single allocation, the allocation name is shown directly. When multiple allocations match, the field displays a count (for example, "2 allocations") with a tooltip listing all matching allocation names.
-
Billing account: The billing account, subscription, or organization associated with the anomaly. The label varies by provider. For a complete list, see Hierarchy property 1 in Provider-specific labels. For Google Cloud and Microsoft Azure, an info icon shows the billing account ID. This field is not displayed for Attribute usage anomalies.
-
Source: Whether the anomaly is based on billing data or real-time usage data.
-
Severity: The severity level of the anomaly (Info, Warning, or Critical).
-
Sensitivity: Shown only for non-default sensitivity settings. Indicates whether the anomaly was detected with low or high sensitivity. See Sensitivity.
The Investigate section provides shortcuts to explore and act on the anomaly in other parts of the console. The available actions depend on the anomaly, your permissions, and your DoiT plan:
-
Explore in Reports: Opens a pre-filtered Cloud Analytics report scoped to the anomaly's provider, service, billing account, project or account, and allocation. See Explore in Reports.
-
Add annotation: Creates a report annotation prefilled with anomaly data, when the AI assistant is available on your DoiT plan. Existing annotations linked to the anomaly are listed below the actions. See Add annotation.
-
Open a Thread: Creates a thread to track the anomaly as an issue in Jira, Linear, or GitHub, prefilled with the anomaly's details and a link back to the anomaly details page. Requires Threads on your DoiT plan and the Threads Manager permission.
-
Find in Cloud Diagrams: Locates the anomaly's resources in a cloud diagram. Shown only for Amazon Web Services, Google Cloud, and Microsoft Azure anomalies with a project or account. If Cloud Diagrams is not yet enabled for your tenant, this action is replaced by Enable Cloud Diagrams. See Find in Cloud Diagrams.
The Review status section lets you track and classify the anomaly:
-
Review status: Use the dropdown to set the investigation state to Needs review, Under review, Resolved · Anomaly confirmed, or Resolved · Not an anomaly. See Review and classify anomalies.
-
Comments: A chronological feed of comments on the anomaly. Select Add comment to post a free-form comment. To edit or delete a comment you authored, select the actions menu (⋮) on the comment card.
-
Activity history: A timeline of anomaly events, including detection, notifications (and re-notifications), review status changes, and linked anomaly events. Resolved status changes also show the resolution reason and any notes. When a linked anomaly is created after the current anomaly's detection time, a New anomaly linked entry appears in the timeline. Each entry displays the SKU or service name as a clickable link that opens the linked anomaly's detail page in a new tab, along with the monitor level (such as "SKU level cost billing anomaly", "Service level cost billing anomaly", or "Real-time service anomaly") and the date and time. When multiple linked anomalies are created close together (within 10 minutes of each other), they collapse into a single entry showing the count (for example, "3 new anomalies linked") and the time range. Select Show all to expand the group and view each linked anomaly individually, or Show less to collapse it. Any other event type occurring between consecutive linked anomaly events splits them into separate groups.
Provider-specific labels
The table below lists the provider-specific labels for the organizational hierarchy properties:
| Provider/Platform | Hierarchy property 1 | Hierarchy property 2 |
|---|---|---|
| Amazon Web Services | Management account/Account name (AWS account name) | Account number |
| Databricks | Organization | Account ID |
| Datadog | Account name | Workspace ID |
| Google Cloud | Billing account (Google Cloud Billing account display name and ID) | Project ID |
| Microsoft Azure | Subscription (Azure subscription display name and ID) | Resource group |
| MongoDB Atlas | Account name | Organization |
| OpenAI | Organization | Workspace |
| Oracle Cloud Infrastructure (OCI) | Tenancy | Compartment |
| Snowflake | Organization | Account |
Cost anomaly chart

On a cost anomaly chart, an Anomaly detected annotation indicates when a spike was identified as an anomaly. When the cost returns to its normal range, an Anomaly inactive annotation marks when the anomaly became inactive. See Dynamic updates. This marker does not appear for expired anomalies whose cost did not return to normal before monitoring ended.
The chart shows the following values for each time step:
-
Normal range: The lower and upper bounds of the expected cost range at that time step, shown as a shaded area on the chart.
-
Cost at time of detection: The cost recorded when the anomaly was first detected at that time step.
-
Cost since time of detection: Additional cost recorded after detection at that time step. The anomaly detection system keeps updating this value until the anomaly becomes
Inactive. -
Cost adjustment since time of detection: Shown only when later billing data revises the cost downward after detection. Displays as a negative value in the tooltip.
-
Total cost: The sum of the cost components shown for that time step.
Contributors
The Contributors table appears below the AI analysis section. If AI analysis is not available, the table appears directly below the chart instead. This table is not displayed for Attribute usage anomalies.
Use this table with AI analysis to see which resources drove the spike. If the anomaly spans multiple SKUs and projects/accounts, each resource row lists a contributing SKU and its associated project or account.
When labels (GCP) or cost-allocation tags (AWS/Azure) are available, they appear in the Labels/Tags column. This helps you identify the team, project, or environment responsible for the anomalous spend.
The example below shows an anomaly with multiple contributing SKUs across different projects.

Linked anomalies
If the anomaly belongs to a group of related anomalies, for example, those in the same service around the same time, you can see them under Linked anomalies. Linked anomalies lists all other anomalies in the group, sorted from newest to oldest by start time. Each row displays the same anomaly properties as a single anomaly, and selecting View on any row opens that anomaly's detail page in a new tab.
If the anomaly does not belong to a group, Linked anomalies is not displayed.
Investigate and take action
The side panel on the anomaly details page provides actions to help you investigate and respond to the anomaly.
Explore in Reports
Cloud Analytics Reports does not support real-time usage data at this time. To investigate a real-time anomaly, try AI analysis.
To decide whether a detected anomaly is really an issue in the context of your business, select Explore in Reports in the side panel. It will open a Cloud Analytics report that groups costs by SKUs and uses the provider, service, billing account, project/account ID, and allocation as filters. Select Run report to see the result.

When viewing a report, be aware that reports always use the latest usage and cost data available, while the data in cost anomaly charts is only updated until the anomaly becomes Inactive.
Find in Cloud Diagrams
If your tenant has Cloud Diagrams enabled, you can select Find in Cloud Diagrams in the side panel to locate the anomaly's resources in your cloud diagram. The diagram opens with the cost heatmap active, so you can immediately see how the anomaly relates to surrounding resources. This action is available for Amazon Web Services, Google Cloud, and Microsoft Azure anomalies that have an associated project or account.

When the anomaly maps to a single diagram, selecting the action opens it directly. When multiple diagrams match, a dropdown lets you choose which diagram to open. If no diagram exists yet for a connected project or account, the action takes you to create one.
If Cloud Diagrams is not enabled, the side panel shows Enable Cloud Diagrams instead and walks you through enabling the feature.
AI analysis
When AI-generated analysis is available, a collapsible AI analysis overview section appears below the cost anomaly chart. This section surfaces insights from the anomaly detection system directly on the page.
Available only when your organization has AI assistant access on its DoiT plan.
The overview includes:
-
SKU details: An explanation of the specific SKU or service that triggered the anomaly.
-
Next steps: Recommended actions to investigate or address the anomaly.

To explore the anomaly further, select Get deeper insights to open the AI assistant. The AI assistant receives the anomaly's metadata — including the cloud platform, service, dates, cost, and severity — so that its analysis is specific to the anomaly you're viewing.
For AWS and Google Cloud anomalies, the AI assistant also automatically pre-selects the affected account or project as a context item, scoping its responses to that particular cloud environment.

Add annotation
You can create an annotation that is pre-populated with the anomaly data by selecting Add annotation in the side panel. For detailed instructions, see Report annotations.
To create an annotation, you must have the Cloud Analytics Admin permission.
When viewing the annotation on a report, it includes a source link to the anomaly details page. The annotation also appears in the Annotations section on the anomaly details page, where you can edit or delete it.

Review and classify anomaly
Use Review status in the side panel to track your investigation and classify the anomaly. This workflow replaces the previous Acknowledge anomaly flow. See Review and classify anomalies.
Get expert advice
If you have a Cloud Intelligence Enhanced or Enterprise plan, you can get expert advice from DoiT directly from the anomaly details page. Select New expert inquiry in the header to create an expert inquiry with the anomaly's context prefilled, including the cloud platform, service, project, and excess cost.