FAQs: Anomaly Prediction For Incoming and Outgoing Tickets | Zoho Desk

FAQs: Anomaly Prediction for Incoming and Outgoing Tickets

Overview

What does anomaly prediction monitor?
Zia monitors changes in the volume of incoming tickets and outgoing responses. It compares today’s actual activity against the trend it predicts from the previous 30 days. A meaningful surge or drop is flagged as an anomaly so an administrator can investigate the operational or customer-impacting cause.

Incoming-ticket anomalies can expose emerging product issues, service failures, or customer reaction to a business change. Outgoing-response anomalies can expose changes in support activity or response patterns.
Is anomaly prediction the same as ticket-volume reporting?
No. Reporting shows historical counts; anomaly prediction evaluates whether the current count departs significantly from the expected pattern. The expected pattern is based on the prior 30 days of ticket traffic.

For example, receiving 25 tickets is not inherently unusual. If a department normally receives 20 tickets on Tuesday afternoon, and its configured threshold treats an increase of 5 as anomalous, that same count can be flagged. The context—the predicted trend and the selected trigger criteria—determines whether an alert appears.
Can incoming and outgoing activity be monitored independently?
Yes. Anomaly prediction is configured separately for incoming tickets and outgoing responses. An administrator can enable a model for incoming traffic, outgoing traffic, or both.

This distinction matters when the operational question differs by department. For example, a department focused on response workload may monitor only outgoing responses, while a department tracking product incidents may prioritize incoming tickets.
Is the setup shared across all departments?
No. Anomaly prediction is department-specific. Each department’s model can be configured according to the activity it needs to monitor. A trigger choice made for one department should not be assumed to apply to another.
Who can configure anomaly prediction?
Users must have permission to access Zia in order to configure Zia and its features. Feature availability and applicable limits should also be checked before relying on the setting for operational monitoring.

Configuration

How is anomaly prediction enabled for a department?
  1. Navigate to Setup > Zia > Anomaly.
  2. Under Prediction for Incoming Tickets, choose either:
    1. A predefined Number of tickets threshold: 5, 25, or 50; or
    2. Customize Trigger Criteria.
  3. If using custom criteria:
    1. Select the desired ticket-volume range.
    2. Select the deviation percentage.
    3. Click Apply.
  4. Enable Notification Settings for Business Hours if notifications should be tied to specific business hours.
  5. Repeat the selection for Prediction for Outgoing Tickets if outgoing-response monitoring is required.
  6. Click Save.
What are the predefined number-of-tickets thresholds?
The predefined thresholds are 5, 25, and 50 tickets. They let an administrator choose how much variation from the trend should be treated as anomalous without defining a custom combination of ticket volume and percentage deviation.

A smaller threshold can detect smaller changes, while a larger threshold focuses attention on bigger departures. The appropriate selection depends on the department’s normal volume and how quickly its team needs to react.
What is the difference between a predefined threshold and custom trigger criteria?
A predefined threshold uses one of the available ticket-count options—5, 25, or 50. Custom trigger criteria adds two required conditions: a ticket-volume range and a deviation percentage.

Use custom criteria when a department needs an alert only when activity is both large enough and sufficiently different from the trend. This avoids treating every percentage change as equally important regardless of the number of tickets involved.

Thresholds and anomaly logic

Which ticket-volume ranges are available for custom trigger criteria?
The selectable volume ranges are:
  1. 6 to 25 tickets
  2. 26 to 50 tickets
  3. 51 to 75 tickets
  4. 76 to 100 tickets
  5. More than 100 tickets
The selected range is one half of the custom condition. A custom anomaly is recognized only when the volume condition and the selected deviation condition are both met.
Which deviation percentages are available?
The available deviation choices are 10%, 25%, 50%, 100%, and dynamic. The deviation is calculated as:
Current value − Trend value
The trend is the predicted pattern based on the prior 30 days; the current value is the observed activity for the current day.
Does meeting only one custom condition generate an anomaly?
No. With custom trigger criteria, both conditions must match: the configured volume range and the configured deviation percentage. A large percentage change alone, or a matching volume range alone, is not sufficient.

For example, if the usual trend is 20 outgoing messages and the current value is 40, the deviation is 100%. The system recognizes an anomaly only when this result also satisfies the configured ticket-volume condition.
Can a decrease, rather than an increase, be flagged?
Yes. Zia flags a surge or dip when the actual activity deviates significantly from the predicted pattern. A sharp rise can point to malfunction or poor service; a significant reduction in tickets for the same issue can indicate that a fix is working or that the product is functioning as expected.
Why might a count that seems high not be marked as an anomaly?
An anomaly is not based on count alone. The current activity is evaluated relative to the 30-day predicted trend and, when custom criteria are used, must satisfy both selected conditions. A high count that is consistent with the established trend, or that does not meet both custom conditions, may not be marked.

Conversely, a comparatively modest count can be anomalous if it departs materially from what is normally expected at that time.

Notifications

Where do anomaly notifications appear?
Notifications appear on the Anomaly tab in Zia notifications. The Zia notification icon is displayed in the bottom bar.
The notification is intended to prompt a timely review; the Prediction dashboard provides the visual comparison needed to examine the actual activity against the predicted trend.
Can anomaly notifications be restricted to business hours?
Yes. Enable Notification Settings for Business Hours during configuration to trigger notifications at specific business hours. This can help ensure alerts are seen when the responsible team is available to take action.

This setting affects notification timing. It should be deliberately aligned with the department’s support coverage and escalation practice so important deviations receive prompt attention.
What should happen after an alert is received?
Use the alert as an investigation signal rather than as a diagnosis. Review whether the change affects incoming tickets, outgoing responses, or both; then compare the actual and predicted lines in the Prediction dashboard.

For example, a sudden incoming-ticket increase after a pricing change may warrant reviewing the affected requests for a common concern. A dip in tickets related to a previously recurring issue may be evidence that the deployed fix is having the intended effect.

Dashboard interpretation

What does the Prediction dashboard show?
The Prediction dashboard provides a visual representation of current trends. Its components include:
  1. Trends vs. Incoming Responses or Outgoing Responses
  2. Trending Auto Tags
  3. Sentiment Analysis
  4. Sentiment Trend Analysis
For anomaly monitoring, use the trends comparison to assess how actual ticket or response volume differs from the expected pattern.
What period is used to predict the current-day trend?
Zia analyzes ticket traffic from the last 30 days and predicts the trend for the current day. This predicted trend is the reference against which current incoming-ticket and outgoing-response activity is evaluated.
What do the colors and star marker mean in the graph?
In the Trends vs. incoming or outgoing responses graph:
  1. The yellow line is the predicted trend based on the previous 30 days.
  2. The blue line is the actual incoming-ticket count or outgoing-response count for the particular day.
  3. A star marks a significant deviation between the predicted and actual data, indicating an anomaly.
The graph plots time on the x-axis and the number of responses on the y-axis.
Does the dashboard prove why the anomaly happened?
No. The dashboard identifies and visualizes a significant difference between predicted and actual activity; it does not establish the underlying cause. Administrators should use the signal to investigate relevant ticket content and operational context.

For instance, a star aligned with a jump in incoming activity may correspond to a product malfunction, a customer-service concern, a pricing change, a new-product adoption pattern, or a product sunset. The chart shows the deviation; the surrounding ticket and business context explains it.

Operational use

Which business situations is this feature designed to help monitor?
It can help a business understand customer reaction to pricing changes, adoption of a new product, the sunset of a long-running product, and issues customers encounter in a product or service. Monitoring increases in ticket count can help teams identify potential malfunction or poor customer service in time to investigate and respond.
Does anomaly prediction automatically fix the underlying issue or change tickets?
The documented behavior is to analyze volume, mark anomalies, and notify administrators. It is an early-warning and monitoring capability. The administrator must review the anomaly and determine the appropriate corrective action.
What should a department monitor: incoming tickets, outgoing responses, or both?
Choose based on the question the department needs answered:
  1. Monitor incoming tickets to spot unusual customer demand or issue volume.
  2. Monitor outgoing responses to spot unusual changes in response activity.
  3. Monitor both when the relationship between customer demand and support output matters.
For example, an incoming surge paired with no corresponding change in outgoing responses may warrant a closer operational review; the feature itself reports the volume patterns, while the team determines the cause and response.
What are the key limitations to account for when setting expectations?
  1. Predictions are based on the last 30 days of ticket traffic.
  2. Anomaly configuration is department-specific.
  3. Custom criteria require both the selected volume range and deviation percentage to match.
  4. Notifications are delivered through the Zia Notification Center, with business-hours timing available when enabled.
  5. The anomaly marker indicates significant deviation, not a confirmed root cause.
  6. Zia access permission is required to configure the feature, and availability or limits may apply.
Info