Wiv Anomaly

Know exactly what changed, why, and what it is costing you

Wiv Anomaly

Wiv turns cloud cost anomalies into actionable incidents. It identifies the affected service, explains the key cost drivers, adds business context, tracks the issue over time, and shows the financial impact before it becomes a surprise.

Wiv Anomaly
BUSINESS IMPACT

Less time investigating. Fewer noisy alerts. Faster action.

Built for FinOps and engineering teams to move from “something changed” to “this is the service, this is the driver, and this is the cost of waiting.”

Wiv Anomaly

Understand
the change

See what increased, how it compares to baseline, and whether it’s significant.

Wiv Anomaly

Find the
strongest reason

Wiv identifies the resources, operations, usage types, and regions driving the anomaly.

Wiv Anomaly

Explain the
business reason

Correlate cloud spend with deployments, activity, tickets, and business systems.

Wiv Anomaly

Measure the
cost of inaction

Track daily excess, peak impact, duration, and total cost until the anomaly is resolved.

How it works

From detection to investigation and action in five steps.

Wiv combines behavior-aware baselines with detailed cloud cost context, then keeps the incident updated as the issue evolves.

01

Detect a material change

Compare each service with previous matching weekdays, so expected weekday and weekend patterns are not mixed together.

02

Explain the anomaly

Identify the resources, operations, usage types, and regions contributing most to the increase.

03

Investigate business context

Use connected tools to correlate the spike with deployments, customer behavior, incidents, and operational changes.

04

Keep tracking it

Maintain the incident as long as the cost issue remains open, even when a detailed root cause is not yet available.

05

Notify only when it matters

Send an alert for a new issue, a meaningful increase, or a scheduled reminder—not for every repeated detection.

What the customer receives

A focused explanation, not another generic cost email.

Each alert combines service-level context, detailed cost drivers, and the financial impact accumulated so far.

screenshot
Agentic investigation

Go beyond cloud billing data and explain the business reason behind the spike.

Wiv gives the Anomaly Agent access to the tools and context it needs to investigate independently. The Agent correlates cost changes with engineering and business activity, then brings people in only when judgment, approval, or missing context is required.

screenshot
Connect the Agent to your existing tools

GitHub or GitLab

Correlate a spike with a deployment, pull
request, release, or infrastructure change.

Wiv Anomaly
Wiv Anomaly

Slack or Microsoft Teams

Ask a focused question in the right
channel only when context is still missing.

Wiv Anomaly
Wiv Anomaly

Datadog or CloudWatch

Validate whether traffic, errors, latency,
or infrastructure utilization changed.

Wiv Anomaly
Wiv Anomaly

Jira or ServiceNow

Find incidents, change requests, maintenance events, and the responsible owner.

Wiv Anomaly
Wiv Anomaly

Internal databases

Connect higher spend to a customer, tenant,
transaction volume, or product activity.

Wiv Anomaly

Wiv Datastore and APIs

Use customer-specific ownership, unit
economics, priorities, and business rules.

Wiv Anomaly
Autonomous

The Agent handles the investigation

Queries approved tools, correlates evidence, measures impact, and updates the case continuously.

Human-in-the-loop

People are asked focused questions

Escalate only when business intent is unclear, confidence is low, or additional context is needed.

Approval required

Execution stays governed

Any remediation, rollback, rightsizing, or customer-impacting action can require explicit approval.

Cumulative impact

See the full cost of an anomaly, not just today’s spike

A small daily increase can become material when it persists. Wiv shows both today’s excess and the total accumulated impact since detection.

01
Wiv Anomaly

Current daily excess

How much the incident is costing today compared with the expected baseline.

02
Wiv Anomaly

Peak daily excess

The highest daily cost increase observed while the anomaly has remained open.

03
Wiv Anomaly

Impact to date

The total excess cost accumulated since the incident was first detected.

04
Wiv Anomaly

Days detected

How long the issue has continued, helping teams prioritize persistent problems.

Noise reduction

Stay informed without training your team to ignore alerts

Wiv separates detection from notification, so ongoing issues remain visible without generating the same email every day. The current re-notification threshold is a 30% increase or at least $500 in additional daily excess cost. These thresholds are dynamic and fully configurable by customer, account, workflow, service, or business priority.

screenshot
New

A new anomaly appears

Send an immediate alert with the current service impact and the best available root cause.

Increased

The issue becomes materially worse

Notify the team again when the daily excess increases by at least 30% or $500. The threshold is dynamic and can be tuned to the customer’s environment.

Reminder

The issue remains unresolved

Send a controlled reminder after the configured interval—currently seven days— instead of repeating the same notification every day.

Agent investigates. Team acts.

Give FinOps and engineering teams the context they need to investigate less, prioritize better, and stop cost issues before they become month-end surprises.