How It Works
Detection runs on a schedule you choose. Each scan analyzes the MCP traffic recorded since the previous scan, looks for suspicious patterns, and writes any findings into the dashboard and the audit log. Everything runs inside Ultra Hub. Your gateways forward traces to the Hub as usual — there is no anomaly configuration in your gateway files, and nothing to deploy or maintain on the gateway side.Anomalies Page
The Anomalies page (in the Hub sidebar) is the home for anomaly detection. It shows your detection settings, a 30-day summary, a risk-score trend, and the history of scan runs with their findings. A Run scan now button sits in the page header.Detection Settings
The settings card controls whether detection runs and how often. Only owners and admins can change it. A status line shows whether scheduled scans are Active or Paused, along with when the setting was last updated.Run Scan Now
The Run scan now button triggers an on-demand scan without waiting for the next scheduled run. A popover lets you pick how far back to look (15m, 30m, 1h, 4h, 12h, or 24h) before submitting. On-demand scans don’t affect your scheduled cadence — the next scheduled scan still covers the full window since the last scheduled run. The button is disabled when:- You are not an owner or admin.
- Scheduled scans are paused.
- A scan is already running for your organization.
- You triggered a scan very recently (a brief cooldown applies between manual scans).
Summary Tiles
Four tiles summarize the last 30 days:Risk Score Chart
The Risk score · last 30 days chart plots the overall risk score for each scan run. Legend pills toggle per-category series so you can isolate a single anomaly category. A subline highlights how the latest run compares to the recent average and how many recent runs crossed the alert threshold.Run History and Findings
Each scan run appears as a row showing its timestamp, the window it scanned (e.g.May 7 → May 10), whether it was scheduled or on-demand, the number of events analyzed, and the run’s maximum risk score.
Click a row to expand it and see every finding from that run. Each finding shows:
- The anomaly categories that apply (a single finding may span several)
- A risk badge and the number of affected traces
- The score, confidence, and a recommended action (block, alert, or allow)
- An explanation of the finding
- The affected users involved
- The affected traces, which link to the trace detail
Anomaly Categories
Findings are classified into the following categories, shown in finding titles and as toggleable series on the trend chart. A single finding can carry more than one category when activity matches a multi-stage pattern.Risk Levels
Each finding carries a risk level that summarizes its severity:
The vast majority of findings on healthy traffic are low or medium. High and critical findings are rare and should prompt a review of the affected traces and identities.
Permissions
Only owners and admins can:- Turn scheduled scans on or off.
- Change the detection frequency.
- Use Run scan now.
Configuration Reference
Anomaly detection is configured per organization from the Hub UI. There is no equivalent in the gateway configuration file.
The analysis model and its supporting infrastructure are fully managed by Ultra and are not exposed to organizations.
Next Steps
Dashboard
Org-wide activity and recent findings at a glance
Audit Log
Anomaly events alongside every other MCP operation
Guardrails
Inline policy enforcement that complements scheduled detection
Roles & Permissions
Who can configure detection and trigger scans