Flume

Command Center · the control layer

It notices
before you do.

Detectors run continuously across payroll, attendance, leave and overtime. They raise what looks wrong against its own baseline, and close it again on their own when the condition clears.

Payroll cost · 11 runsbaseline ± threshold
THRESHOLD +15%+22.4%
Attendance dropLeave spikeOvertime spikePayroll spikePayslip outlier

Tune it yourself

A watchlist is only useful if it is short.

Set the threshold too tight and every ordinary month alerts; too loose and you find out from the bank. Drag the payroll-spike threshold across seven real-shaped runs and watch the watchlist grow and clear — this is the same setting HR owns in the product.

Payroll spike threshold +15%

+2%+16%+30%
2026-03+2.1%
2026-04-1.4%
2026-05+3.8%
2026-06+1.2%
2026-07+6.4%
2026-08+9.1%
2026-09+22.4%

Change against the rolling baseline of the previous runs. Drag the threshold and watch the watchlist grow or clear.

runs evaluated7
open anomalies1
auto-resolved6
rows written1 per run key
Watchlist1 to reviewA condition that clears closes itself, marked auto-resolved rather than reviewed.

Each detector reads its own thresholds — multipliers, point drops, lookback windows and minimum floors — from one settings row.

What ships

A watchlist that stays short because it cleans itself up.

01

Payroll spike

Compares a run against a rolling window of previous runs and raises a percentage breach above your threshold.

02

Attendance drop

Watches present-rate per department against its own recent baseline, in points rather than a fixed floor.

03

Leave spike

Flags clustering — an unusual number of requests landing on the same date in the same team.

04

Overtime spike

Raises a department running at a multiple of its own rolling average, with a minimum-hours floor to kill noise.

05

Payslip outlier

Catches an individual payslip that departs from that employee’s own history, not just the company mean.

06

Tunable thresholds

Every detector reads its own settings — multipliers, point thresholds, lookback and minimums — from one place.

How it actually works

The mechanism, not the marketing.

Dedupe key

The same condition does not raise a hundred alerts.

Each detector writes one row per module and detection-period key — a payroll run, an ISO week, a department-week. Re-running refreshes the existing row instead of stacking duplicates, so a condition that persists for a fortnight is one item on the list, not fourteen.

Auto-resolve

A cleared condition closes itself, and says so.

When a later pass finds the condition gone, the anomaly is resolved automatically and marked as such — distinct from a human closing it. That distinction matters: "someone reviewed this" and "it went away on its own" are different facts about your operation.

Its own baseline

Every comparison is against the thing’s own history.

A maintenance department that always runs hot on overtime should not alert every week, and a small team should not be judged against the company average. Detectors compare each subject to its own rolling baseline, which is what makes the list worth reading.

Severity is state

High, medium and low are wired to what you do next.

Severity drives notification and ordering rather than decorating the row. The dashboard surfaces open anomalies most-severe-first with the count by band, so the first thing an HR lead sees in the morning is the shortest accurate list of what needs a decision.

Book a demo

Bring us your messiest month.

The fastest way to judge Flume is to run it against a period you already argued about. Send a month of punches and the payroll you produced from it, and we will show you the same month reconciled — including what the anomaly detectors flag.