Why doesn't one strange trace trigger a behavior drift alert?

Because drift is a property of a population’s behavior over time, not a verdict on any single trace, so one unusual session doesn’t fire it on its own.

A call site’s normal traffic already has variation in it: a retried step, a shortcut path, an edge case handled differently. Judging any one trace against a fixed threshold would either fire constantly on that ordinary variation, or get tuned so loose it catches nothing real. Tessary’s behavior_drift classifier instead watches whether an action, an order, or a path is showing up across many sessions at a rate the call site’s own history doesn’t support, which is a statement about a trend, not a ruling on one interaction.

That’s also why a new pattern doesn’t count as drift the moment it first appears. It has to recur across enough sessions to be a pattern before it’s treated as one, and only firings that clear that bar get grouped by cause and triaged.

keep reading

More on this.

Two ways to run Tessary.

Tessary is an open-source agent reliability platform. Cloud and self-hosted run the same workflow on the OpenTelemetry traces your agent already emits.

Tessary Cloud

We host it for you. Send your first trace with nothing to deploy and no model key.

what's includedper organization
traces
10,000 per calendar month
stored trace data
1 GB
retention
30 days
model credit
$10, one-time, for triage and root-cause analysis
credit card
not required

Self-hosted Tessary

Run the open-source code on your own infrastructure with one command. Add your own model key for triage and root-cause analysis.

Self-host Tessary for me by following https://github.com/tessaryai/tessary/blob/main/setup.md

docker compose -f oci://docker.io/tessaryai/tessary:compose up -d -y