View anomaly details
When viewing the details of a specific anomaly, you have access to multiple resources that help you investigate and address the anomaly.
Required permissions
- Allocations Admin, Anomalies Viewer, Cloud Analytics User
View a cost anomaly
To view a specific cost anomaly:
-
Sign in to the DoiT console, select Policy and governance from the top navigation mega menu, and then select Cost anomalies.
-
On the Cost anomalies page, find the anomaly of interest.
-
Select View at the rightmost end of the anomaly entry to launch the cost anomaly details page.
An example anomaly based on billing data (daily granularity):

An example anomaly based on AWS CloudTrail events (Real-time anomaly, hourly granularity):

Summary

At the top of the anomaly details page, a header row displays the cloud provider logo, a title combining an account identifier and the service name, and a status chip indicating whether the anomaly is Active or Inactive. For Google Cloud anomalies, the title uses the Project ID when available; otherwise it uses the billing account name. For other providers, the title uses the billing account name when available, falling back to the project or account ID.
Below the header, the anomaly details page displays the following metrics:
-
Excess cost: The difference between the actual cost and the upper bound of the normal range, displayed prominently. For real-time anomalies, this value is labeled as an estimate. Next to the excess cost, the percentage by which the excess cost exceeds the expected maximum is displayed as
X%. -
Actual cost: The observed cost at the time the anomaly started.
-
Expected max: The upper bound of the normal cost range at the time the anomaly started.
-
Started at: When the anomalous usage began. For real-time anomalies, this includes the time.
-
Ended at: When the anomaly became inactive. Shows Ongoing if the anomaly is still active, or Expired if monitoring reached its time limit before the cost returned to its normal range. Hovering over Expired displays a tooltip with details about the time limit.
-
SKU: The Stock Keeping Unit associated with the anomaly. For service-level anomalies, shows the name of the contributing SKU when a single SKU is responsible, the number of contributing SKUs (for example, "3 SKUs") when multiple SKUs are involved, or an em dash when no SKU information is available. This field is not displayed for real-time anomalies.
For older anomalies that predate the current detection system, Actual cost and Expected max display a dash (—) and the deviation is hidden.
Side panel

On desktop, a side panel to the right of the main content area groups Details, Investigate, and Review status. On mobile, the same content is displayed inline below the header metrics. The Details section includes the following properties:
-
Project ID: The project or account associated with the anomaly. The label varies by provider, see Hierarchy property 2 in Provider-specific labels. For service-level anomalies, it shows the project or account ID when one resource is responsible, a provider-specific count when multiple contribute (for example, "3 projects" or "3 accounts"), or an em dash when no information is available.
-
Allocation: The allocation associated with the anomaly, if applicable.
-
Billing account: The billing account, subscription, or organization associated with the anomaly. The label varies by provider. For a complete list, see Hierarchy property 1 in Provider-specific labels. For Google Cloud and Microsoft Azure, an info icon shows the billing account ID.
-
Source: Whether the anomaly is based on billing data or real-time usage data.
-
Severity: The severity level of the anomaly (Info, Warning, or Critical).
-
Sensitivity: Shown only for non-default sensitivity settings. Indicates whether the anomaly was detected with low or high sensitivity. See Sensitivity.
The Investigate section provides shortcuts to explore the anomaly in other parts of the console:
-
Open in Reports: Opens a pre-filtered Cloud Analytics report scoped to the anomaly's provider, service, billing account, project or account, and allocation. See Open in reports.
-
Open in Cloud Diagrams: Opens the anomaly's resources in a cloud diagram with the cost heatmap active, when Cloud Diagrams is enabled for your tenant. If Cloud Diagrams is not yet enabled, this section offers a link to enable it instead. See Open in Cloud Diagrams.
-
Annotate report: Creates a report annotation prefilled with anomaly data, when the AI assistant is available on your DoiT plan. Existing annotations linked to the anomaly are listed in this section. See Annotate report.
The Review status section lets you track and classify the anomaly:
-
Review status: Use the dropdown to set the investigation state to Needs review, Under review, Resolved · Anomaly confirmed, or Resolved · Not an anomaly. See Review and classify anomalies.
-
Comments: A chronological feed of comments on the anomaly. Select Add comment to post a free-form comment. To edit or delete a comment you authored, select the actions menu (⋮) on the comment card.
-
Activity history: A timeline of anomaly events, including detection, notifications (and re-notifications), and review status changes. Resolved status changes also show the resolution reason and any notes.
Provider-specific labels
The table below lists the provider-specific labels for the organizational hierarchy properties:
| Provider/Platform | Hierarchy property 1 | Hierarchy property 2 |
|---|---|---|
| Amazon Web Services | Management account/Account name (AWS account name) | Account number |
| Databricks | Organization | Account ID |
| Datadog | Account name | Workspace ID |
| Google Cloud | Billing account (Google Cloud Billing account display name and ID) | Project ID |
| Microsoft Azure | Subscription (Azure subscription display name and ID) | Resource group |
| MongoDB Atlas | Account name | Organization |
| OpenAI | Organization | Workspace |
| Oracle Cloud Infrastructure (OCI) | Tenancy | Compartment |
| Snowflake | Organization | Account |
Cost anomaly chart

On a cost anomaly chart, an Anomaly detected annotation indicates when a spike was identified as an anomaly. When the cost returns to its normal range, an Anomaly inactive annotation marks when the anomaly became inactive. See Dynamic updates. This marker does not appear for expired anomalies whose cost did not return to normal before monitoring ended.
The chart shows the following values for each time step:
-
Normal range: The lower and upper bounds of the expected cost range at that time step, shown as a shaded area on the chart.
-
Cost at time of detection: The cost recorded when the anomaly was first detected at that time step.
-
Cost since time of detection: Additional cost recorded after detection at that time step. The anomaly detection system keeps updating this value until the anomaly becomes
Inactive. -
Cost adjustment since time of detection: Shown only when later billing data revises the cost downward after detection. Displays as a negative value in the tooltip.
-
Total cost: The sum of the cost components shown for that time step.
Contributors
The Contributors table appears below the AI analysis section. If AI analysis is not available, the table appears directly below the chart instead.
Use this table with AI analysis to see which resources drove the spike. If the anomaly spans multiple SKUs and projects/accounts, each resource row lists a contributing SKU and its associated project or account.
When labels (GCP) or cost-allocation tags (AWS/Azure) are available, they appear in the Labels/Tags column. This helps you identify the team, project, or environment responsible for the anomalous spend.
The example below shows an anomaly with multiple contributing SKUs across different projects.

Investigate and take action
The side panel on the anomaly details page provides actions to help you investigate and respond to the anomaly.
Open in reports
Cloud Analytics Reports does not support real-time usage data at this time. To investigate a real-time anomaly, try AI analysis.
To decide whether a detected anomaly is really an issue in the context of your business, select Open in Reports in the side panel. It will open a Cloud Analytics report that groups costs by SKUs and uses the provider, service, billing account, project/account ID, and allocation as filters. Select Run report to see the result.

When viewing a report, be aware that reports always use the latest usage and cost data available, while the data in cost anomaly charts is only updated until the anomaly becomes Inactive.
Open in Cloud Diagrams
If your tenant has Cloud Diagrams enabled, you can select Open in Cloud Diagrams in the side panel to view the anomaly's resources in your cloud diagram. The diagram opens with the cost heatmap active, so you can immediately see how the anomaly relates to surrounding resources.

When the anomaly maps to a single diagram, selecting the button opens it directly. When multiple diagrams match, a dropdown lets you choose which diagram to open.
If Cloud Diagrams is not enabled, the side panel shows Enable Cloud Diagrams instead and walks you through enabling the feature.
AI analysis
When AI-generated analysis is available, a collapsible AI analysis overview section appears below the cost anomaly chart. This section surfaces insights from the anomaly detection system directly on the page.
Available only when your organization has AI assistant access on its DoiT plan.
The overview includes:
-
SKU details: An explanation of the specific SKU or service that triggered the anomaly.
-
Next steps: Recommended actions to investigate or address the anomaly.

To explore the anomaly further, select Get deeper insights to open the AI assistant. The AI assistant receives the anomaly's metadata — including the cloud platform, service, dates, cost, and severity — so that its analysis is specific to the anomaly you're viewing.
For AWS and Google Cloud anomalies, the AI assistant also automatically pre-selects the affected account or project as a context item, scoping its responses to that particular cloud environment.

Annotate report
You can create an annotation that is pre-populated with the anomaly data by selecting Annotate report in the side panel. For detailed instructions, see Report annotations.
To create an annotation, you must have the Cloud Analytics Admin permission.
When viewing the annotation on a report, it includes a source link to the anomaly details page. The annotation also appears in the Annotations section on the anomaly details page, where you can edit or delete it.

Review and classify anomaly
Use Review status in the side panel to track your investigation and classify the anomaly. This workflow replaces the previous Acknowledge anomaly flow. See Review and classify anomalies.
Get expert advice
If you have a Cloud Intelligence Enhanced or Enterprise plan, you can get expert advice from DoiT directly from the anomaly details page. Select New expert inquiry in the header to create an expert inquiry with the anomaly's context prefilled, including the cloud platform, service, project, and excess cost.