Raxx · internal docs

internal · gated

DET-SIGNUP-001 — waitlist velocity per origin

Rule ID: DET-SIGNUP-001 Title: Waitlist signup rate per Origin header per minute exceeding 3σ above baseline Category: signup Last validated: 2026-06-04 (initial catalog) State: livewaitlist_signups table exists; FLAG_WAITLIST_DATASTORE-gated. Querying the table is the source.

Telemetry source

Statistical method + baseline window

Threshold + expected FP rate

Alert route

Escalation owner

Test fixture / synthetic positive

See _fixtures/waitlist_velocity_per_origin_positive.json for a synthetic 24-signup burst from source=getraxx-landing-page within 50s.

What to do when this fires

  1. Pull the 60s window's rows: emails, source, IPs (if persisted), user-agents.
  2. Cross-reference with DET-SIGNUP-002 (signup_email_pattern_anomaly) — if both fire on the same window, treat as confirmed bot signature.
  3. If emails look organic-distributed and IPs are diverse, mark as confirmed-organic and log for retro analysis.
  4. If emails share a domain pattern OR IPs cluster in one ASN, dispatch security-agent for posture review (rate limit, CF rule, captcha consideration — operator decision).

What NOT to do