LogsF-2308

Reported actives exceed independently observed actives by 18.4%

P2
Acked within200m 00sof 60m 00s
Reported vs. observed actives

18.4% gap

from ≤ 5% · +13.4pp

Affected users

41,200

All tenants · August · monthly actives

Cancels at risk

Not a churn-bearing finding

Detected

3d 0h ago

25 Aug 14:20 UTC

Attributable to
AWG

Commercial integrity. Entitlement, payment, subscription lifecycle, invoicing.

Triage

Investigating

What is happening

AWG's subscriber report for August names 224,100 monthly actives across the portfolio. Firebase and NPAW together observe 182,900 distinct AUMS UUIDs with at least one session in the same window — a gap of 41,200, or 18.4%. Part of the gap is measurable and expected: Tizen and tvOS telemetry is absent from the interim NPAW feed, which accounts for at most 12,400 of it. The residual 28,800 is unexplained and is the number to take into the renegotiation. This is the trust-but-verify metric, and it is stated with its own uncertainty attached rather than as a clean accusation.

Suggested action

Agree a shared definition of 'monthly active' with AWG before disputing the figure. The residual 28,800 survives any reasonable definition and is the defensible part of the claim.

What fired, and against what

Each signal names the detector that produced it, the value it saw and the value it expected. This is the part a vendor will try to take apart, so it is stated in full.

2 signals
  • S-8912

    Reported vs. observed actives

    AWG
    224,100 vs 182,900expected ≤ 5% gap+18.4%
    Slice
    Portfolio · August
    Detector
    Threshold rule
    Confidence
    94%
    Users
    41,200
    Detected
    3d 0h ago
  • S-8915

    Unmeasured platform population

    NPAW
    12,400expected 0explains 30% of gap
    Slice
    Tizen · tvOS
    Detector
    Cohort decomposition
    Confidence
    71%
    Users
    12,400
    Detected
    2d 22h ago

Evidence

The governed query each detector ran, the rows it returned, and the fact grain underneath. Every table exports.

Reported against observed, per tenant

AWG
Query executed
SELECT tenant_id, awg_reported_actives, observed_actives,
  round(100.0 * (awg_reported_actives - observed_actives) / awg_reported_actives, 1) AS gap_pct
FROM recon.actives_comparison WHERE cycle = '2026-08' ORDER BY gap_pct DESC
tenantAWG reportedobservedgap
Revolut BR84,20066,10021.5%
Nexo Bank MX48,90039,80018.6%
Praia Telecom BR31,40026,20016.6%
Andes Móvil CO27,80023,90014.0%
Vela Fintech AR18,60016,40011.8%
Sur Digital CL13,20011,50012.9%
Underlying grain — dim_user ⋈ fact_app_event, 224,100 rows

Route an evidence ticket

Pre-filled from the finding and addressed by fault domain. Editable before it goes.

1 already routed — AWG-EMAIL-0822

No agreed intakeNo agreed intake. Tickets go to a named individual and are not tracked by AWG. The ticket will be recorded here with no external reference to quote back.

Evidence attached
  • Reported against observed, per tenant (6 rows)
Editable before send

Timeline

4 events
  1. Detected25 Aug 14:20 UTC

    Threshold rule on Reported vs. observed actives — 18.4% gap against ≤ 5%

    Detection engine
  2. Acknowledged25 Aug 18:40 UTC

    260 minutes after detection, against a 60-minute target

    AWG — platform
  3. Routed25 Aug 18:40 UTC

    AWG — platform — AWG-EMAIL-0822

    M. Ferreira
  4. Rejected26 Aug 14:20 UTC

    AWG rejected on the grounds that 'monthly active' is defined differently on each side. That objection is fair for part of the gap and does not touch the residual 28,800.

    AWG — platform

Related findings

same slice or same error

Clustered support tickets

0 matched

No tickets matched. For a detection-capability finding that is expected; for a service finding it means users are affected but not yet complaining.

Sample affected users

Not attributable to individual users — this finding is scoped to a connector or a region window, not a cohort of people.