ZoikoDigital
Anomaly Flags & Alerts

Find record conditions that need review - without judging people

Configure explainable flags for approved workforce-record conditions, route governed alerts to authorized reviewers, support worker correction, and preserve every resolution in a traceable history.

Review signals, not conclusions
Human decisions
Visible sources
Worker correction rights
ZoikoTime Anomaly Flags Interface

What is an anomaly flag in ZoikoTime?

ZoikoTime creates an anomaly flag when approved record facts meet a versioned condition. A governed alert may then notify authorized reviewers according to scope, timing, routing, and escalation rules. Reviewers inspect source facts, policy context, quality, limitations, and worker input before resolving the case. ZoikoTime does not treat a flag as guilt, performance, misconduct, legal noncompliance, or an automatic payroll or disciplinary decision.

A flag is a review signal

Not a conclusion about a person. It says a configured condition was met, and points to who should look at it.

An alert routes attention

It does not make a decision. Routing, timing, and escalation determine who is notified — nothing more.

Missing data is a data state

Incomplete or conflicting sources produce a neutral data-quality condition, never an adverse inference about anyone.

Binding product invariant

No screenshots, keystroke content, URL history, application-name monitoring, or clipboard collection under any tier or configuration. This is governed review infrastructure for record conditions — not a monitoring or fraud-detection product, and it must not be deployed as one.

Governed Lifecycle

Define → Detect → Contextualize → Notify → Review → Resolve → Preserve

Seven stages. Detection is stage two of seven, which is the whole point — detecting a condition is the least significant thing this product does.

01

Define

An approved, versioned condition with owner, threshold, scope, purpose, and review cadence.

Definition owner
02

Detect

Governed record facts satisfy the condition. A flag instance is created with its trigger.

System, deterministic
03

Contextualize

Attach policy version, jurisdiction, schedule basis, time zone, source quality, and limitations.

System
04

Notify

An alert policy routes attention to authorized recipients with priority, timing, and delivery tracking.

Routing policy
05

Review

An authorized person inspects evidence, requests information, notes context, and considers worker input.

Human only
06

Resolve

An accountable, reasoned outcome — including "expected variation" and "unable to determine."

Human only · reason required
07

Preserve

Definition version, trigger, evidence, requests, decisions, and downstream effect retained without overwrite.

Evidence history

There is no auto-action stage. No configuration allows a flag to change a record, adjust pay, notify a worker punitively, or trigger a disciplinary workflow on its own. Any consequential action is a separate authorized human workflow.

What May Be Flagged

Twelve Condition Families — All About Records, None About People

Read the guardrail column. Each family exists with an explicit rule about what it must not be read as.

Record completeness

Permitted examples

Missing required field; incomplete source context; unlinked policy version.

Required guardrail

Describe missing context. Do not infer worker intent.

Temporal consistency

Permitted examples

Overlap; gap; duplicate; out-of-sequence boundary; time-zone ambiguity.

Required guardrail

Show local and canonical time plus source quality.

Schedule alignment

Permitted examples

Recorded boundary differs from approved schedule or shift version.

Required guardrail

Reviewable context — not an attendance or misconduct conclusion.

Workflow state

Permitted examples

Approval overdue; correction awaiting response; release acknowledgment missing.

Required guardrail

Flag the workflow, not the person.

Policy context

Permitted examples

Applicable policy unavailable; conflicting versions; effective-date mismatch.

Required guardrail

No universal legal-compliance claim.

Source health

Permitted examples

Delayed feed; stale source; failed sync; partial import; reconciliation mismatch.

Required guardrail

Route to the source owner. Avoid worker blame.

Classification trace

Permitted examples

Insufficient context; conflicting precedence; result superseded.

Required guardrail

Link the deterministic trace. No AI or risk score.

Break & rest context

Permitted examples

Eligibility window or record requires review.

Required guardrail

Keep separate from any legal-compliance conclusion.

Shift integrity

Permitted examples

Unresolved overlap, reassignment, split, cancellation, extension.

Required guardrail

Preserve approved versions and human review.

Evidence continuity

Permitted examples

Missing evidence link; delivery receipt failed; version lineage incomplete.

Required guardrail

State the limitation. Never claim immutability or admissibility.

Privacy & access

Permitted examples

Result below threshold; scope request exceeds permission; recipient access expired.

Required guardrail

Suppress display safely and record the reason.

Notification health

Permitted examples

Alert delivery failed; route unowned; coverage expired; repeated duplicate.

Required guardrail

Protect fatigue control and routing integrity.

What a Flag Is Not

Eleven Interpretations, and Their Required Replacements

The left column is what an anomaly product usually says. The right column is what this one says instead.

Prohibited

Fraud detected

Required Replacement

“Configured record condition requires review.”

Prohibited

Time theft

Required Replacement

“Recorded and expected context differ; review the source facts and applicable policy.”

Prohibited

High-risk employee

Required Replacement

“Operational priority: review by [time].”

Prohibited

Noncompliant worker

Required Replacement

“Applicable record or policy context is incomplete, conflicting, or awaiting review.”

Prohibited

Poor performer

Required Replacement

“This page does not evaluate productivity or performance.”

Prohibited

Suspicious behavior

Required Replacement

“Source-linked record condition.”

Prohibited

Violation confirmed

Required Replacement

“Review state: unresolved / resolved with reason.”

Prohibited

Automatically rejected

Required Replacement

“Human review required before any separate consequential action.”

Prohibited

AI confidence 92%

Required Replacement

“Definition version, trigger conditions, source quality, and limitations.”

Prohibited

Red alert means guilty

Required Replacement

“Colour supports operational priority only; text states meaning and status.”

Copy lock

The words “offender,” “suspect,” “caught,” “cheating,” “fraudulent,” “dishonest,” “noncompliant employee,” and “high-risk worker” never appear in this product's interface, notifications, documentation, or sales material — except, as above, as an example of language being replaced.

Flag Anatomy

What Every Flag Carries

  • Definitionname, version, owner, purpose, review date
  • Triggerthe condition-level explanation of why this flag exists
  • Source factsthe governed records that satisfied the condition
  • Scopeorganization, unit, record type, policy, jurisdiction, period
  • Timelocal and canonical, time zone, schedule basis
  • Qualityfreshness, completeness, conflicts, suppression state
  • Limitationswhat this flag cannot establish
  • Worker-rights routeown-record view, correction, escalation
  • Next actionaccountable owner, reason, due state
Alert Anatomy

What every alert event carries

  • Alert policy and version
  • Linked flag or flags
  • Route, recipients, and their permission basis
  • Operational priority and timing
  • Delivery status and acknowledgment
  • Escalation path and coverage owner
  • Expiry, suppression, and withdrawal state

Quiet hours suppress delivery, not obligation. A notification held overnight does not pause the underlying review requirement or reset a due state — and suppression is time-bound, attributable, and never deletion.

Operational Priority, Due State & Colour

Priority Describes Attention Order, Never a Person

Priority

Allowed treatment

Informational · review soon · time-sensitive · configured due date

Prohibited treatment

Worker risk, threat, guilt, or severity about a person

Status

Allowed treatment

Open · acknowledged · in review · information requested · resolved · unable to determine

Prohibited treatment

Pass/fail person labels

Colour

Allowed treatment

Blue or neutral for open; amber for due attention; red only for system delivery failure or destructive action

Prohibited treatment

Red worker cards, heat maps of people, colour-only meaning

Ordering

Allowed treatment

Due date, definition family, workflow dependency, source outage, age, assignment

Prohibited treatment

“Most suspicious” or “worst workers”

Counts

Allowed treatment

Flags, alert events, unresolved source issues, delivery failures

Prohibited treatment

Leaderboards by worker

Escalation

Allowed treatment

Ownership or coverage failure, or a configured deadline

Prohibited treatment

Punitive escalation based on a hidden score

Default sort

Allowed treatment

Due state, then created time — user-changeable within permission

Prohibited treatment

Opaque “smart priority”

In the operations centre above, the only red status belongs to a failed alert delivery — a system condition. No record condition and no person is ever coloured red.

Human Review Workflow

A Review Case Is a Human Workspace

Evidence, requests, notes, decisions, corrections, and resolution — all attributable, all preserved.

A reviewer can

  • Acknowledge ownership
  • Inspect trigger facts and source quality
  • Request information with a non-adverse status
  • Request a record correction
  • Resolve with a reason code
  • Escalate on coverage or deadline

Separation of duties

  • Definition author and case reviewer separated for high-impact families
  • No self-review where the reviewer is the affected record owner
  • Coverage gaps escalate rather than silently expire
  • Recusal creates a neutral, attributable event
Resolution Taxonomy

Twelve states, and two that matter most

OpenAcknowledgedIn reviewInformation requestedResolved — expected variationResolved — corrected recordResolved — definition changedSuppressedExpiredWithdrawnEscalatedUnable to determine

“Expected variation” and “Unable to determine”

Both are legitimate, fully-recorded outcomes. A flag that turns out to describe normal operating context resolves as expected variation with no adverse inference. A flag with insufficient or conflicting evidence resolves as unable to determine, stating the limitation and the human next action — rather than being forced into a conclusion.

Reason codes are neutral: expected variation, approved exception, corrected source, corrected record, policy clarified, definition changed. Acknowledgment records responsibility, not agreement with the signal.

Worker Transparency & My Flagged Records

The Person in the Record Is Not the Last to Know

Anomaly products usually keep flags on the manager side of a wall. This one gives the worker an authenticated view of applicable own-record flags, with correction and escalation.

See

Applicable own-record flags with plain-language explanation, definition version, scope, and current review state.

Understand

Which records and policy context produced the condition, and the stated limitations of the signal.

Correct

Request a correction or provide context with a reason. The request status is non-adverse throughout.

Escalate

A documented route where a correction is declined, plus privacy and support contacts.

Never derived from a flag

A worker's flag history is never aggregated into a score, a ranking, a risk profile, or a performance signal. Having flags associated with your records means records needed review — nothing about you. Suppression never removes a worker's right to see and challenge an applicable own-record flag.

Source health & data quality

Current
Objective: distinguish a record condition from a pipeline condition.
States

Missing · stale · duplicate · conflicting · delayed · unavailable · reconciliation required

Routing

Source conditions route to the source owner, not the worker

Effect on flags

Affected flags carry the quality state and a stated limitation

Limitations: A count derived from a stale source is a floor, not a total, and says so. An unavailable source never silently substitutes older data.

Definition & threshold governance

Current
Objective: make every condition owned, tested, and reversible.
Lifecycle

Owned · tested · impact-previewed · approved · published · monitored · revised · withdrawn · preserved

Impact preview

How many flags a change would create or retire, before publication

Versioning

A threshold change creates a new version; prior flags keep the version that created them

Limitations: A definition is never edited in place. Retired definitions and their historical flags are preserved rather than deleted, so a resolved case still explains itself years later.

Routing & fatigue control

Current
Objective: keep alerts meaningful, because ignored alerts protect nobody.
Controls

Grouping · deduplication · correlation · quiet hours · digests · rate limits · expiry

Coverage

An unowned route escalates rather than dropping the signal

Health review

Delivery failures and duplicate rates are reviewed as operational conditions

Limitations: Deduplication groups repeated signals without deleting underlying evidence. Suppression is approved, time-bound, and audited — it is not deletion, and it does not suspend review obligations.

Kairos boundary

Kairos may retrieve and explain a flag's definition, trigger facts, scope, source quality, limitations, and review path within the requester's existing permission — and must state when information is insufficient. It cannot resolve a case, change a status, alter a definition, suppress an alert, or decide anything.

Kairos Assistant

Optional Zoiko Sema context

Zoiko Sema is an independent product. Any connection is optional, explicitly mapped, permissioned, and reviewable. Communication presence is never treated as proof of work, and connected context never creates a flag on its own.

Zoiko Sema Integration

Deterministic Time Classification behind a flag remains policy-bound, versioned, and reviewable — and is never branded as AI. There is no confidence percentage and no risk score anywhere in this product.

Trust, Enterprise Readiness & Procurement

Where the Evidence Lives

Trust Center

Entry point for assurance evidence.

Security

Access, scoping, logging, incident readiness.

Privacy

Purpose, minimization, retention, worker rights.

Human-in-Command

Where consequential authority sits and stays.

Administrative Controls

Definition ownership, routing, and change governance.

Accessibility

Tested scope, methods, known limitations.

System Status

Authoritative operational state and delivery health.

Procurement

Controlled evidence and commercial terms.

Enterprise readiness questions

Worth answering before you configure a single definition

  • Who owns each anomaly definition, and who reviews it?
  • Which reviewers have coverage, and what happens when they do not?
  • How will workers be told that own-record flags exist?
  • What is your escalation route when a correction is declined?
  • Which source owners are accountable for feed health?
  • What resolution reasons will your organization actually use?

Availability, packaging, regions, channels, connectors, retention, and service levels come from the current approved registry. This page does not state them.

Already a customer?

Customer evidence

No customer names, logos, detection rates, benchmarks, or outcome metrics appear on this page. None has been verified for this destination — and an “anomalies caught” statistic would be exactly the wrong claim to make.

Neutral by design

Route attention to records that need review - and nowhere else

See how explainable definitions, governed routing, worker correction rights, and reasoned resolution can make exception handling defensible rather than accusatory.

No fraud labels.No risk scores.No auto-action.Worker correction rights.
Dashboard preview
Direct Answers

Fourteen Questions

A source-linked review signal created when approved workforce-record facts meet a versioned condition. It is not a conclusion about a person, and it carries its definition, trigger, scope, source quality, limitations, and review path.