Anomalies
Catch the 2am cost spike
automatically.
Learn the “normal,”
then surface only the spikes
An anomaly is an alert,
and an alert comes with evidence
Detection
Two detection engines in tandem
AWS’s ML-based detection paired with OneCloud’s rules engine — comprehensive, but not noisy.
ML
AWS Cost Anomaly Detection
Pull AWS’s ML-based anomalies (GetAnomalies) straight into OneCloud alerts and reports.
Rules
Custom rules engine
Compose thresholds (>$X), growth (>30% WoW), new-service events, and egress-share rules without writing code.
Routing
Slack, email, Webhook
Split routing per anomaly — infra to Slack #cost-alerts, finance to email, automation to Webhook.
Evidence
Line-item evidence
Every alert attaches the line items that contributed most. “Why was I paged?” is immediately visible.
Sensitivity
Per-team sensitivity
Tune sensitivity and learning windows per team or environment. Production and sandbox don’t share the same alerts.
Triage
Acknowledge & note
Mark each anomaly as acknowledged, resolved, or ignored, with notes — so context survives into the next close.