What is a Spending Anomaly?
An agent spending pattern that deviates significantly from established baselines — unusual amounts, unexpected recipients, abnormal timing, or velocity changes that may indicate compromise or malfunction.
WHY IT MATTERS
Anomaly detection goes beyond rule-based controls. Instead of checking "is this transaction within limits?" it asks "is this transaction normal for this agent?"
An agent that normally spends $10-$50 per transaction suddenly spending $49.99 (just under the $50 limit) repeatedly is anomalous — each transaction passes limits but the pattern is suspicious.
Anomalies can indicate: prompt injection attacks, agent malfunction, environmental changes (new tasks requiring different spending), or legitimate but unusual operations. Investigation is needed to determine the cause.
HOW POLICYLAYER USES THIS
PolicyLayer detects and blocks spending anomalies in real-time — using behavioral baselines to identify patterns that rule-based controls alone would miss.