Capability Google TimesFM

Anomaly Detection

Catch the drop before it costs you revenue.

A break rarely announces itself in the headline number. It starts in one channel, one market, one page template — and the top-line chart quietly averages it away. So you pick the series that matter, Google’s TimesFM forecasts what each one should do next, and you hear about it only when reality leaves that range. Built for teams whose data holds more charts than anyone can watch.

How it works: you choose the metrics, we calibrate the model

Detection is only useful on metrics someone actually owns. So the pipeline starts with a decision you make — not a switch we flip.

Detection pipeline
You decisions you own We runs in your project, operated by us Sensitivity calibration is joint — see below.
  1. You 01

    Choose metrics

    You select the series worth watching — from sessions by channel down to combinations like country × device × campaign.

  2. We 02

    Read history

    TimesFM reads each series’ recent history straight from your data models. No per-customer training run.

  3. We 03

    Forecast

    The model predicts the next value of every series, with an expected range around it — zero-shot.

  4. We 04

    Compare

    An actual outside the range becomes an anomaly candidate, with its direction and size recorded.

  5. We 05

    Alert & log

    Cleared candidates go to email or Slack as one grouped alert — and every alert is appended to the alert history in your own warehouse.

The model: Google TimesFM

TimesFM is Google’s foundation model for time series. It is pretrained on a large corpus of series, so it forecasts a new metric without a per-customer training phase. Weekday rhythm, seasonality and holiday swings show up in the forecast itself — which is why there are no hand-set thresholds to maintain. The expected range moves with your data.

Calibration is a working session, not a settings page

During onboarding we review candidate anomalies with you and tune the sensitivity per metric: how large a deviation matters, how long it must persist, and a minimum-impact floor so trivially small wobbles never page anyone. Which breakdown combinations are monitored — and how deep the split goes — is decided in the same session. We revisit the calibration whenever your baseline shifts — a site migration, a new market, a tracking change.

What you control

Detection is only worth having if it fits your business rather than a vendor’s defaults. Three things are yours to decide — and one thing is worth being explicit about.

Which metrics are watched

You choose the series, down to the breakdown: revenue by channel, clicks by content group, conversions by market. Nothing gets monitored because a default said so — and nothing you didn’t add is being watched.

How sensitive it is

How large a deviation has to be, how long it must persist, and a minimum-impact floor so trivially small wobbles never page anyone. Set per metric during onboarding, and revisited whenever your baseline shifts.

How you hear about it

Cleared alerts go to email or Slack, grouped so one incident is one message. Every alert is also appended to a table in your own warehouse, so the alert history stays queryable instead of buried in an inbox.

Staying quiet is the hard part

The number-one objection to anomaly detection is noise. Here is how this one stays quiet:

Forecast ranges absorb seasonality

Weekend dips and holiday spikes sit inside the expected range, so they never fire — the classic failure mode of fixed thresholds.

Sensitivity is tuned per metric, with you

During a burn-in period you review every candidate and tell us which ones you would want again. We adjust until the stream is worth reading.

Minimum-impact floors

A statistically unusual move on a metric too small to matter is suppressed by design. Significance alone doesn’t page anyone.

Related anomalies arrive as one alert

A drop that shows up in sessions, conversions and revenue at once is one incident — you get one notification, not three.

No detector is both silent and perfect. That trade-off is real — which is exactly why sensitivity is a decision you make with us, not a default you inherit.

Where it stops

  • It flags where and when — not why.

    Root-cause analysis stays a human job. The alert points at the series and the moment; the investigation is yours.

  • It watches the metrics you selected.

    Nothing outside your chosen list is monitored — silence about a metric you never added is not a green light.

  • It is not uptime or infrastructure monitoring.

    It reads your data models, not your servers. Keep your existing ops tooling for that.

  • It sees no external data.

    No competitor benchmarks, no market indices — only series computed from your own warehouse.

  • It does not promise zero false positives.

    It promises a calibrated, reviewable alert stream — and a sensitivity knob you control.

  • It does not take your data anywhere.

    Source access is read-only, and everything the pipeline writes — the forecasts and the alert history itself — lands in your own BigQuery project. Nothing is copied out.

What it catches in practice

Detection runs on modeled series, not raw exports — which is what makes these specific enough to act on. Each one leans on a data model or a source you can read about.

  • Branded demand falls away overnight

    Branded search is the first thing to move when something goes wrong with the brand, and the last thing a topline traffic chart shows. Split brand from non-brand and each half becomes its own watched series.

    Brand vs Non-brand Queries
  • One content group slips while the site total looks flat

    Informational pages can lose a third of their clicks while commercial pages quietly cover the gap. Watched per group instead of per site, the drop has nowhere to hide.

    Content Groups
  • Page speed crosses the threshold that matters

    Core Web Vitals recorded every day become a series like any other, so a regression after a release is an alert that week rather than a discovery next quarter.

    PageSpeed Insights
  • Spend keeps running after conversions stop

    Cost and conversions watched as a pair makes the gap between them its own monitored series — which is the version of this problem that actually costs money.

    Google Ads

What an alert looks like

Every alert answers three questions before you click anything: which metric, how far off, since when. And it lands twice — pushed to email or Slack the moment it fires, and appended to an alert history in your warehouse, where every past alert stays queryable.

Anomaly alert — email / Slack Sample data
Drop detected 2026-07-14

Sessions — Organic search · mobile

Expected range

41,200 – 47,600

Actual

32,418

Deviation

−27%

Detected

2026-07-14

Open dashboard Query in BigQuery
Alert history · your warehouse Sample data
detected_at metric segment expected actual dev
2026-07-14 sessions organic · mobile 41.2k–47.6k 32.4k −27%
2026-07-06 conversion_rate paid · DE 2.1%–2.6% 3.1% +32%
2026-06-24 revenue email €8.1k–€9.4k €6.9k −21%
2026-06-11 sessions direct 5.9k–6.8k 8.3k +31%
2026-05-28 gsc_ctr /blog/* 3.4%–3.9% 2.7% −26%
2026-05-16 orders paid · mobile 310–360 262 −22%
2026-05-04 sessions referral 2.4k–2.9k 3.6k +36%
2026-04-21 conversion_rate organic · UK 1.8%–2.2% 1.4% −25%
2026-04-09 revenue paid · FR €3.2k–€3.8k €4.7k +34%

Know the day it breaks — not the week after.

Talk to us

Free discovery call · Leave with a shortlist of series worth watching