01
Payroll spike
Compares a run against a rolling window of previous runs and raises a percentage breach above your threshold.
Command Center · the control layer
Detectors run continuously across payroll, attendance, leave and overtime. They raise what looks wrong against its own baseline, and close it again on their own when the condition clears.
Tune it yourself
Set the threshold too tight and every ordinary month alerts; too loose and you find out from the bank. Drag the payroll-spike threshold across seven real-shaped runs and watch the watchlist grow and clear — this is the same setting HR owns in the product.
Payroll spike threshold +15%
Change against the rolling baseline of the previous runs. Drag the threshold and watch the watchlist grow or clear.
Each detector reads its own thresholds — multipliers, point drops, lookback windows and minimum floors — from one settings row.
What ships
01
Compares a run against a rolling window of previous runs and raises a percentage breach above your threshold.
02
Watches present-rate per department against its own recent baseline, in points rather than a fixed floor.
03
Flags clustering — an unusual number of requests landing on the same date in the same team.
04
Raises a department running at a multiple of its own rolling average, with a minimum-hours floor to kill noise.
05
Catches an individual payslip that departs from that employee’s own history, not just the company mean.
06
Every detector reads its own settings — multipliers, point thresholds, lookback and minimums — from one place.
How it actually works
Each detector writes one row per module and detection-period key — a payroll run, an ISO week, a department-week. Re-running refreshes the existing row instead of stacking duplicates, so a condition that persists for a fortnight is one item on the list, not fourteen.
When a later pass finds the condition gone, the anomaly is resolved automatically and marked as such — distinct from a human closing it. That distinction matters: "someone reviewed this" and "it went away on its own" are different facts about your operation.
A maintenance department that always runs hot on overtime should not alert every week, and a small team should not be judged against the company average. Detectors compare each subject to its own rolling baseline, which is what makes the list worth reading.
Severity drives notification and ordering rather than decorating the row. The dashboard surfaces open anomalies most-severe-first with the count by band, so the first thing an HR lead sees in the morning is the shortest accurate list of what needs a decision.
Book a demo
The fastest way to judge Flume is to run it against a period you already argued about. Send a month of punches and the payroll you produced from it, and we will show you the same month reconciled — including what the anomaly detectors flag.