Ticket cluster with no alert behind it — Vela Fintech AR sign-in
22 tickets
from ≤ 5 per 6h · +4.4×
4,180
Vela Fintech AR · partner SSO
340
Modelled over 30 days
5h 40m ago
28 Aug 08:40 UTC
The tool's own detection and join coverage. Never routed to a vendor.
Triage
What is happening
22 Zendesk tickets in 6 hours all describe failing to sign in on Vela Fintech AR, and no active alert covers them. Per F2.6 this is treated as a detection gap rather than a service incident: the tool should have caught this before the users did. Firebase Auth shows a 4.1× rise in SSO handshake timeouts for the tenant, which no seeded rule currently watches.
Add a seeded rule on auth_success_rate scoped to tenant, then backtest it against the last 30 days before enabling.
What fired, and against what
Each signal names the detector that produced it, the value it saw and the value it expected. This is the part a vendor will try to take apart, so it is stated in full.
- S-8760
Unlinked ticket cluster
ZD22 ticketsexpected ≤ 5 per 6h+4.4×- Slice
- Vela Fintech AR · category: sign-in
- Detector
- Cohort decomposition
- Confidence
- 93%
- Users
- 22
- Detected
- 5h 40m ago
- S-8762
Auth handshake timeout rate
FIRE6.8%expected 1.7%+4.1×- Slice
- Vela Fintech AR
- Detector
- Seasonal baseline
- Confidence
- 90%
- Users
- 4,180
- Detected
- 5h 36m ago
Evidence
The governed query each detector ran, the rows it returned, and the fact grain underneath. Every table exports.
Ticket cluster, unmatched to any active alert
SELECT category, tenant_id, count(*) AS tickets, min(opened_at) AS first_seen FROM semantic.ticket WHERE linked_alert_id IS NULL AND opened_at >= now() - interval '6 hours' GROUP BY category, tenant_id HAVING count(*) > 5 ORDER BY tickets DESC
| category | tenant | tickets | first seen |
|---|---|---|---|
| sign-in | vela-ar | 22 | 28 Aug 08:40 |
| playback | altiplano-pe | 7 | 28 Aug 10:15 |
Route an evidence ticket
Pre-filled from the finding and addressed by fault domain. Editable before it goes.
- Ticket cluster, unmatched to any active alert (2 rows)
Timeline
- Detected28 Aug 08:40 UTC
Cohort decomposition on Tickets without a linked alert — 22 tickets against ≤ 5 per 6h
Detection engine
Related findings
Nothing related. For a first occurrence that is expected; for a recurring defect it usually means the related-findings link has not been established rather than that none exists.
Clustered support tickets
- Cannot log in with my Vela account5h 30m ago
ZD-48088 · Vela Fintech AR
- Sign in loops back to start5h 2m ago
ZD-48092 · Vela Fintech AR
- Login not working since yesterday3h 8m ago
ZD-48119 · Vela Fintech AR