← Back to Products
AI-Powered Anomaly Detection
AICybersecurityAnomaly Detection

AI-Powered Anomaly Detection

Led the introduction of an AI-powered anomaly detection solution that automatically identifies Just-in-Time Admin sessions where activity exceeded the original scope of access — reducing manual review effort and surfacing potential privilege misuse at scale.


The Problem & User Research

Security analysts reviewing Just-in-Time Admin sessions faced a significant signal-to-noise problem. Thousands of session activity logs made it impractical to manually identify privilege misuse — sessions where admin activity exceeded the original justified scope of access. This left potential security incidents buried in data, unreviewed.


Product Strategy & Approach

I led the product initiative to introduce AI-powered anomaly detection into the Analytics product. I worked with data science and engineering to define what 'anomalous' meant in the context of JIT Admin sessions, and shaped how the LLM would reason over session activity logs. The feature was built with an AWS Bedrock integration, enabling the product to leverage foundation models at scale without managing underlying infrastructure. Working with UX, I defined the user experience for how findings would be surfaced to end users — prioritising clarity and actionability over raw data. I managed the backlog, ran stakeholder reviews, and coordinated the go-to-market plan including release notes and training materials.


Outcome & Impact

The feature significantly reduced manual review effort for security analysts by automatically flagging sessions where activity deviated from the approved justification. It enabled teams to scale their privilege access monitoring without growing headcount, and marked a significant milestone as the first EPM-specific AI-powered capability — laying the foundations for broader automation across the product.