LogsF-2284

Ticket cluster with no alert behind it — Vela Fintech AR sign-in

P3 · SUB-P1
Ack SLA remaining1100m 00sof 1440m 00s
Tickets without a linked alert

22 tickets

from ≤ 5 per 6h · +4.4×

Affected users

4,180

Vela Fintech AR · partner SSO

Cancels at risk

340

Modelled over 30 days

Detected

5h 40m ago

28 Aug 08:40 UTC

Attributable to
Adroit

The tool's own detection and join coverage. Never routed to a vendor.

Triage

New

What is happening

22 Zendesk tickets in 6 hours all describe failing to sign in on Vela Fintech AR, and no active alert covers them. Per F2.6 this is treated as a detection gap rather than a service incident: the tool should have caught this before the users did. Firebase Auth shows a 4.1× rise in SSO handshake timeouts for the tenant, which no seeded rule currently watches.

Suggested action

Add a seeded rule on auth_success_rate scoped to tenant, then backtest it against the last 30 days before enabling.

What fired, and against what

Each signal names the detector that produced it, the value it saw and the value it expected. This is the part a vendor will try to take apart, so it is stated in full.

2 signals
  • S-8760

    Unlinked ticket cluster

    ZD
    22 ticketsexpected ≤ 5 per 6h+4.4×
    Slice
    Vela Fintech AR · category: sign-in
    Detector
    Cohort decomposition
    Confidence
    93%
    Users
    22
    Detected
    5h 40m ago
  • S-8762

    Auth handshake timeout rate

    FIRE
    6.8%expected 1.7%+4.1×
    Slice
    Vela Fintech AR
    Detector
    Seasonal baseline
    Confidence
    90%
    Users
    4,180
    Detected
    5h 36m ago

Evidence

The governed query each detector ran, the rows it returned, and the fact grain underneath. Every table exports.

Ticket cluster, unmatched to any active alert

ZD
Query executed
SELECT category, tenant_id, count(*) AS tickets, min(opened_at) AS first_seen
FROM semantic.ticket WHERE linked_alert_id IS NULL
  AND opened_at >= now() - interval '6 hours'
GROUP BY category, tenant_id HAVING count(*) > 5 ORDER BY tickets DESC
categorytenantticketsfirst seen
sign-invela-ar2228 Aug 08:40
playbackaltiplano-pe728 Aug 10:15

Route an evidence ticket

Pre-filled from the finding and addressed by fault domain. Editable before it goes.

Evidence attached
  • Ticket cluster, unmatched to any active alert (2 rows)
Editable before send

Timeline

1 events
  1. Detected28 Aug 08:40 UTC

    Cohort decomposition on Tickets without a linked alert — 22 tickets against ≤ 5 per 6h

    Detection engine

Related findings

same slice or same error

Nothing related. For a first occurrence that is expected; for a recurring defect it usually means the related-findings link has not been established rather than that none exists.

Clustered support tickets

3 matched
  • Cannot log in with my Vela account

    ZD-48088 · Vela Fintech AR

    5h 30m ago
  • Sign in loops back to start

    ZD-48092 · Vela Fintech AR

    5h 2m ago
  • Login not working since yesterday

    ZD-48119 · Vela Fintech AR

    3h 8m ago

Sample affected users