Find The: Probability Of Time 
probability_of_time
Measures whether the amount of activity happening right now is normal for this entity at this point in the cycle. The Feature counts the events in a short window around the current event, the Bucket, and compares that count against the same bucket in each preceding Periodicity. Four events in the last hour means one thing for an account that averages four an hour, and something else for an account that has never had more than one.
For example:
- Is this customer paying at an hour of the day they have never paid at before?
- Is this account busier in this hour than it usually is at this hour, or on this day of the week?
Configuration
- Feature Name: The "dictionary" name under which the feature value will be stored and referenced by in rules.
- For Events:
- With The Same: The entity whose pattern of behaviour is being established. There must be at least one Identifier and only Identifier and Subject attributes can be used.
- Periodicity: How far apart the comparison windows sit. The current Bucket is compared with the same Bucket one Periodicity back, two Periodicities back, and so on. Expressed in hours, days, weeks or months. A Periodicity of one day compares this hour with the same hour yesterday and on the days before it; one week compares it with the same hour on the same day of the week in earlier weeks.
- Bucket: The window of current activity being assessed, centred on the current event. Expressed in hours, days, weeks or months.
Optional Configuration
- Default Value: A value that can be assigned to the feature if the attributes to calculate the features are not present.
- Scope: Can be used to extend the event search from the local node, to all nodes within the same organization all the way to all across customers (global).
- Condition: A Query-Language filter that can be used to refine Features for specific use cases.
- Exclude Days: Removes weekdays or weekends from the calculation, on both sides of the comparison. Use it where the behaviour being modelled only makes sense within the working week, or only outside it.
How Probability Of Time is calculated
The Bucket is the window around the event being scored, half a Bucket either side of it. Each earlier Bucket is that same window stepped back one Periodicity at a time.
So a six-hour Bucket around a payment at 21:00 runs from 18:00 to 00:00, and the Feature compares it with 18:00 to 00:00 on each earlier day.
Nothing pins those windows to the clock. The same Feature scoring a payment at 19:00 compares 16:00 to 22:00 instead.

Both halves of the comparison are published, under the Feature's own name in two different dictionaries:
outcome['CHAMPION'].features.general['<feature name>']
the count of matching events in the current Bucket
outcome['CHAMPION'].quantiles.general['<feature name>']
where that count ranks against the earlier Buckets, 0..1
Neither number is the probability that something is wrong. The name describes the statistics the Feature runs, not a risk score.
The Feature's own value is a count of events in a window, which is a velocity: the same thing Velocity Of produces, measured over the Bucket rather than over a Time Window.
The second value is a percentile rank. It goes to the same quantiles dictionary that Calculate Quantile fills for other Feature Types, and it means there what it means here: where a value sits in a distribution, from 0 to 1. However, the distribution differs.
Calculate Quantile ranks a value against a sketch of the values that Feature has taken, while Probability Of Time ranks the current count against a zero-inflated Poisson fitted to the counts the same Bucket held in earlier periods. A rank close to 1 means the Bucket holds more activity than the established pattern accounts for, and a rank in the middle of the range means the count is unremarkable. A rank of 0.99 says the fitted model puts 99% of outcomes at or below this count.
Because the Feature publishes that rank itself, Calculate Quantile is not required on it.
Consequences
Zero does not mean quieter than usual. It is what the Feature publishes for both the count and the rank in two cases: an entity with no prior events, so that a new user is not treated as anomalous, and a current event falling on a day the Exclude Days setting removes. A rule written as <= 0.05 to catch unusually quiet periods fires on both of them. Test the high end of the range, or rule 0 out explicitly.
Include Current Event decides whether this event is in its own Bucket. It is off unless it is turned on, and with it off the event being scored is not counted in the current Bucket. A lone payment at a time of day the account has never used leaves the count at 0 and the rank at 0.5, the middle of the range rather than the top. Turn it on where the question is whether this event is happening at an unusual time, and leave it off where the question is whether the current window is busier than usual, which the other events in the Bucket already answer.
A Bucket has to be wide enough to hold the behaviour when it drifts. An account that pays in the evening but at a scattered hour, say 18:50 one day and 22:40 the next, has nothing in a two-hour window on any earlier day, and the Feature reports the habit as an anomaly. Six hours holds all of it.
Probability Of Time sets its own windows, so the Feature-level settings that would otherwise fight with them are constrained. A Feature that breaks any of the following is rejected when the journey is deployed.
- Time Window must be all or left unset, because Bucket and Periodicity do the windowing.
- Periodicity must be a longer duration than Bucket, and its unit must be the same size or larger: a one-hour Bucket with a seven-day Periodicity is valid, the reverse is not. The unit rule is the stricter of the two, so a Bucket in days with a Periodicity in hours is rejected even where the hours add up to more.
- Both durations must be greater than zero.
- Because the windows move with the event, a one-day Bucket is the twelve hours either side of this event and not the calendar day, and two events an hour apart are scored against two different sets of windows.
- Two things are calendar-aware: a Periodicity in months steps by calendar months from the event's own date, and Exclude Days decides weekday from weekend in UTC, on the current event and on the history alike, whatever time zone the node or the user is in.
- How many earlier periods are compared is not a setting either: it is however far back the entity's events reach, so a long Periodicity needs a long history before the comparison has much to fit.
Use Case 1
Catch a payment made at a time of day this customer never pays at. The six-hour Bucket is the window around this payment, and the one-day Periodicity steps that window back a day at a time, so the comparison is against this part of the day rather than against the account's overall volume.
Using the Feature in Rules and Investigations
An hour with nothing in the account's record puts the probability at the top of the range:
outcome['CHAMPION'].quantiles.general['acct_payment_hour'] >= 0.9
Implementing In The Feature Editor
- name: acct_payment_hour
default_value: -1
time_window: all
starting: immediately
find_the:
probability_of_time:
for_events:
event_type:
- payment
include_current_event: true
with_the_same:
- identity['ACCOUNT'].customer_token.customer_token
bucket:
hours: 6
periodicity:
days: 1
with_scope: same_node_instance
Use Case 2
Score an account's weekend activity against the same hour on previous weekends. The seven-day Periodicity lines each Bucket up with the same hour on the same day of the week, and Exclude Days set to weekdays keeps weekday events out of the history and returns 0 for a weekday event rather than scoring it.
Using the Feature in Rules and Investigations
The count is read with feature(). The quantile has no shorthand: it is read from the quantiles dictionary under the same name. Pairing the two keeps a burst of two events off the rule when the account's pattern is one:
feature('acct_hourly_activity_wknd') > 5 AND outcome['CHAMPION'].quantiles.general['acct_hourly_activity_wknd'] >= 0.99
Implementing In The Feature Editor
- name: acct_hourly_activity_wknd
default_value: -1
time_window: all
starting: immediately
find_the:
probability_of_time:
for_events:
event_type: all
include_current_event: false
with_the_same:
- identity['ACCOUNT'].customer_token.customer_token
bucket:
hours: 1
periodicity:
days: 7
exclude: weekdays
with_scope: same_node_instance