Find record conditions that need review - without judging people
Configure explainable flags for approved workforce-record conditions, route governed alerts to authorized reviewers, support worker correction, and preserve every resolution in a traceable history.

What is an anomaly flag in ZoikoTime?
ZoikoTime creates an anomaly flag when approved record facts meet a versioned condition. A governed alert may then notify authorized reviewers according to scope, timing, routing, and escalation rules. Reviewers inspect source facts, policy context, quality, limitations, and worker input before resolving the case. ZoikoTime does not treat a flag as guilt, performance, misconduct, legal noncompliance, or an automatic payroll or disciplinary decision.
A flag is a review signal
Not a conclusion about a person. It says a configured condition was met, and points to who should look at it.
An alert routes attention
It does not make a decision. Routing, timing, and escalation determine who is notified — nothing more.
Missing data is a data state
Incomplete or conflicting sources produce a neutral data-quality condition, never an adverse inference about anyone.
No screenshots, keystroke content, URL history, application-name monitoring, or clipboard collection under any tier or configuration. This is governed review infrastructure for record conditions — not a monitoring or fraud-detection product, and it must not be deployed as one.
Define → Detect → Contextualize → Notify
→ Review → Resolve → Preserve
Seven stages. Detection is stage two of seven, which is the whole point — detecting a condition is the least significant thing this product does.
Define
An approved, versioned condition with owner, threshold, scope, purpose, and review cadence.
Detect
Governed record facts satisfy the condition. A flag instance is created with its trigger.
Contextualize
Attach policy version, jurisdiction, schedule basis, time zone, source quality, and limitations.
Notify
An alert policy routes attention to authorized recipients with priority, timing, and delivery tracking.
Review
An authorized person inspects evidence, requests information, notes context, and considers worker input.
Resolve
An accountable, reasoned outcome — including "expected variation" and "unable to determine."
Preserve
Definition version, trigger, evidence, requests, decisions, and downstream effect retained without overwrite.
There is no auto-action stage. No configuration allows a flag to change a record, adjust pay, notify a worker punitively, or trigger a disciplinary workflow on its own. Any consequential action is a separate authorized human workflow.
Twelve Condition Families — All About
Records, None About People
Read the guardrail column. Each family exists with an explicit rule about what it must not be read as.
| Condition family | Permitted examples | Required guardrail |
|---|---|---|
| Record completeness | Missing required field; incomplete source context; unlinked policy version. | Describe missing context. Do not infer worker intent. |
| Temporal consistency | Overlap; gap; duplicate; out-of-sequence boundary; time-zone ambiguity. | Show local and canonical time plus source quality. |
| Schedule alignment | Recorded boundary differs from approved schedule or shift version. | Reviewable context — not an attendance or misconduct conclusion. |
| Workflow state | Approval overdue; correction awaiting response; release acknowledgment missing. | Flag the workflow, not the person. |
| Policy context | Applicable policy unavailable; conflicting versions; effective-date mismatch. | No universal legal-compliance claim. |
| Source health | Delayed feed; stale source; failed sync; partial import; reconciliation mismatch. | Route to the source owner. Avoid worker blame. |
| Classification trace | Insufficient context; conflicting precedence; result superseded. | Link the deterministic trace. No AI or risk score. |
| Break & rest context | Eligibility window or record requires review. | Keep separate from any legal-compliance conclusion. |
| Shift integrity | Unresolved overlap, reassignment, split, cancellation, extension. | Preserve approved versions and human review. |
| Evidence continuity | Missing evidence link; delivery receipt failed; version lineage incomplete. | State the limitation. Never claim immutability or admissibility. |
| Privacy & access | Result below threshold; scope request exceeds permission; recipient access expired. | Suppress display safely and record the reason. |
| Notification health | Alert delivery failed; route unowned; coverage expired; repeated duplicate. | Protect fatigue control and routing integrity. |
Record completeness
Missing required field; incomplete source context; unlinked policy version.
Describe missing context. Do not infer worker intent.
Temporal consistency
Overlap; gap; duplicate; out-of-sequence boundary; time-zone ambiguity.
Show local and canonical time plus source quality.
Schedule alignment
Recorded boundary differs from approved schedule or shift version.
Reviewable context — not an attendance or misconduct conclusion.
Workflow state
Approval overdue; correction awaiting response; release acknowledgment missing.
Flag the workflow, not the person.
Policy context
Applicable policy unavailable; conflicting versions; effective-date mismatch.
No universal legal-compliance claim.
Source health
Delayed feed; stale source; failed sync; partial import; reconciliation mismatch.
Route to the source owner. Avoid worker blame.
Classification trace
Insufficient context; conflicting precedence; result superseded.
Link the deterministic trace. No AI or risk score.
Break & rest context
Eligibility window or record requires review.
Keep separate from any legal-compliance conclusion.
Shift integrity
Unresolved overlap, reassignment, split, cancellation, extension.
Preserve approved versions and human review.
Evidence continuity
Missing evidence link; delivery receipt failed; version lineage incomplete.
State the limitation. Never claim immutability or admissibility.
Privacy & access
Result below threshold; scope request exceeds permission; recipient access expired.
Suppress display safely and record the reason.
Notification health
Alert delivery failed; route unowned; coverage expired; repeated duplicate.
Protect fatigue control and routing integrity.
Eleven Interpretations, and Their Required
Replacements
The left column is what an anomaly product usually says. The right column is what this one says instead.
Fraud detected
“Configured record condition requires review.”
Time theft
“Recorded and expected context differ; review the source facts and applicable policy.”
High-risk employee
“Operational priority: review by [time].”
Noncompliant worker
“Applicable record or policy context is incomplete, conflicting, or awaiting review.”
Poor performer
“This page does not evaluate productivity or performance.”
Suspicious behavior
“Source-linked record condition.”
Violation confirmed
“Review state: unresolved / resolved with reason.”
Automatically rejected
“Human review required before any separate consequential action.”
AI confidence 92%
“Definition version, trigger conditions, source quality, and limitations.”
Red alert means guilty
“Colour supports operational priority only; text states meaning and status.”
The words “offender,” “suspect,” “caught,” “cheating,” “fraudulent,” “dishonest,” “noncompliant employee,” and “high-risk worker” never appear in this product's interface, notifications, documentation, or sales material — except, as above, as an example of language being replaced.
What Every Flag Carries
- Definition — name, version, owner, purpose, review date
- Trigger — the condition-level explanation of why this flag exists
- Source facts — the governed records that satisfied the condition
- Scope — organization, unit, record type, policy, jurisdiction, period
- Time — local and canonical, time zone, schedule basis
- Quality — freshness, completeness, conflicts, suppression state
- Limitations — what this flag cannot establish
- Worker-rights route — own-record view, correction, escalation
- Next action — accountable owner, reason, due state
What every alert event carries
- Alert policy and version
- Linked flag or flags
- Route, recipients, and their permission basis
- Operational priority and timing
- Delivery status and acknowledgment
- Escalation path and coverage owner
- Expiry, suppression, and withdrawal state
Quiet hours suppress delivery, not obligation. A notification held overnight does not pause the underlying review requirement or reset a due state — and suppression is time-bound, attributable, and never deletion.
Priority Describes Attention Order, Never a
Person
| Dimension | Allowed treatment | Prohibited treatment |
|---|---|---|
| Priority | Informational · review soon · time-sensitive · configured due date | Worker risk, threat, guilt, or severity about a person |
| Status | Open · acknowledged · in review · information requested · resolved · unable to determine | Pass/fail person labels |
| Colour | Blue or neutral for open; amber for due attention; red only for system delivery failure or destructive action | Red worker cards, heat maps of people, colour-only meaning |
| Ordering | Due date, definition family, workflow dependency, source outage, age, assignment | “Most suspicious” or “worst workers” |
| Counts | Flags, alert events, unresolved source issues, delivery failures | Leaderboards by worker |
| Escalation | Ownership or coverage failure, or a configured deadline | Punitive escalation based on a hidden score |
| Default sort | Due state, then created time — user-changeable within permission | Opaque “smart priority” |
Priority
Informational · review soon · time-sensitive · configured due date
Worker risk, threat, guilt, or severity about a person
Status
Open · acknowledged · in review · information requested · resolved · unable to determine
Pass/fail person labels
Colour
Blue or neutral for open; amber for due attention; red only for system delivery failure or destructive action
Red worker cards, heat maps of people, colour-only meaning
Ordering
Due date, definition family, workflow dependency, source outage, age, assignment
“Most suspicious” or “worst workers”
Counts
Flags, alert events, unresolved source issues, delivery failures
Leaderboards by worker
Escalation
Ownership or coverage failure, or a configured deadline
Punitive escalation based on a hidden score
Default sort
Due state, then created time — user-changeable within permission
Opaque “smart priority”
In the operations centre above, the only red status belongs to a failed alert delivery — a system condition. No record condition and no person is ever coloured red.
A Review Case Is a Human Workspace
Evidence, requests, notes, decisions, corrections, and resolution — all attributable, all preserved.
A reviewer can
- Acknowledge ownership
- Inspect trigger facts and source quality
- Request information with a non-adverse status
- Request a record correction
- Resolve with a reason code
- Escalate on coverage or deadline
Separation of duties
- Definition author and case reviewer separated for high-impact families
- No self-review where the reviewer is the affected record owner
- Coverage gaps escalate rather than silently expire
- Recusal creates a neutral, attributable event
Twelve states, and two that matter most
“Expected variation” and “Unable to determine”
Both are legitimate, fully-recorded outcomes. A flag that turns out to describe normal operating context resolves as expected variation with no adverse inference. A flag with insufficient or conflicting evidence resolves as unable to determine, stating the limitation and the human next action — rather than being forced into a conclusion.
Reason codes are neutral: expected variation, approved exception, corrected source, corrected record, policy clarified, definition changed. Acknowledgment records responsibility, not agreement with the signal.
The Person in the Record Is Not the Last to Know
Anomaly products usually keep flags on the manager side of a wall. This one gives the worker an authenticated view of applicable own-record flags, with correction and escalation.
See
Applicable own-record flags with plain-language explanation, definition version, scope, and current review state.
Understand
Which records and policy context produced the condition, and the stated limitations of the signal.
Correct
Request a correction or provide context with a reason. The request status is non-adverse throughout.
Escalate
A documented route where a correction is declined, plus privacy and support contacts.
A worker's flag history is never aggregated into a score, a ranking, a risk profile, or a performance signal. Having flags associated with your records means records needed review — nothing about you. Suppression never removes a worker's right to see and challenge an applicable own-record flag.
Source health & data quality
CurrentMissing · stale · duplicate · conflicting · delayed · unavailable · reconciliation required
Source conditions route to the source owner, not the worker
Affected flags carry the quality state and a stated limitation
Definition & threshold governance
CurrentOwned · tested · impact-previewed · approved · published · monitored · revised · withdrawn · preserved
How many flags a change would create or retire, before publication
A threshold change creates a new version; prior flags keep the version that created them
Routing & fatigue control
CurrentGrouping · deduplication · correlation · quiet hours · digests · rate limits · expiry
An unowned route escalates rather than dropping the signal
Delivery failures and duplicate rates are reviewed as operational conditions
Kairos boundary
Kairos may retrieve and explain a flag's definition, trigger facts, scope, source quality, limitations, and review path within the requester's existing permission — and must state when information is insufficient. It cannot resolve a case, change a status, alter a definition, suppress an alert, or decide anything.
Optional Zoiko Sema context
Zoiko Sema is an independent product. Any connection is optional, explicitly mapped, permissioned, and reviewable. Communication presence is never treated as proof of work, and connected context never creates a flag on its own.
Deterministic Time Classification behind a flag remains policy-bound, versioned, and reviewable — and is never branded as AI. There is no confidence percentage and no risk score anywhere in this product.
Where the Evidence Lives
Trust Center
Entry point for assurance evidence.
Security
Access, scoping, logging, incident readiness.
Privacy
Purpose, minimization, retention, worker rights.
Human-in-Command
Where consequential authority sits and stays.
Administrative Controls
Definition ownership, routing, and change governance.
Accessibility
Tested scope, methods, known limitations.
System Status
Authoritative operational state and delivery health.
Procurement
Controlled evidence and commercial terms.
Worth answering before you configure a single definition
- Who owns each anomaly definition, and who reviews it?
- Which reviewers have coverage, and what happens when they do not?
- How will workers be told that own-record flags exist?
- What is your escalation route when a correction is declined?
- Which source owners are accountable for feed health?
- What resolution reasons will your organization actually use?
Availability, packaging, regions, channels, connectors, retention, and service levels come from the current approved registry. This page does not state them.
Already a customer?
No customer names, logos, detection rates, benchmarks, or outcome metrics appear on this page. None has been verified for this destination — and an “anomalies caught” statistic would be exactly the wrong claim to make.
Route attention to records
that need review - and
nowhere else
See how explainable definitions, governed routing, worker correction rights, and reasoned resolution can make exception handling defensible rather than accusatory.
