Weekday KPI anomaly alerts from Looker to Slack and Linear

By General Input

Every weekday morning, check your core Looker metrics against the last four weeks and alert the team only when something genuinely breaks.

Integrations

  • Looker
  • Slack Bot
  • Linear

Type

Agentic Task

Categories

  • Operations
  • Engineering

Every weekday at 7am, check my core KPIs in Looker for genuine anomalies and alert me only when something is actually wrong. Run this on a schedule, Monday through Friday.

First, pull the data. Use Looker's Run Look operation for each of my saved core KPI Looks, and Run Inline Query for the metrics I track ad hoc rather than as a saved Look. For every metric, retrieve the current value alongside the trailing four weeks of that same metric, so there is a baseline to compare against instead of a single number floating on its own. Where the underlying explore supports it, also break the metric out by its main segments such as channel, region, plan tier, or product line, so a move can be attributed rather than just observed.

Then judge what you are looking at. This is the part that needs actual reasoning: do not treat every movement as an anomaly. Weekly seasonality is normal and expected, Mondays and Fridays routinely run different from midweek, and month start and month end commonly spike. Flag a metric only when the current value breaches its threshold in a way the trailing four weeks does not explain, for example a sustained direction change, a move well outside the recent range, or a clear break in an established pattern. For anything you flag, work out both the direction and the magnitude of the change, and which segment is most likely driving it by comparing segment level movement against the overall move.

For each metric that breaches its threshold, post an alert to Slack using the Slack Bot integration's Send a Message operation, into my data alerts channel. Name the metric, state the size of the delta both in absolute terms and as a percentage against the trailing four week average, and name the segment most likely driving it. Send one message per run covering every breaching metric, ranked with the most severe first, and keep it short enough to read on a phone without expanding anything.

Also open a Linear issue for the data team using Create Issue, one per breaching metric, so the investigation actually gets tracked instead of scrolling away in chat. Put the metric name and the numbers in the title and description, and include the query details needed to reproduce it: the Look ID or the inline query definition, the model and explore, the filters applied, and the date range used. Whoever picks the issue up should be able to rebuild the number without hunting for it. Reference the Slack alert in the issue where you can, so the two are connected.

One rule matters more than the rest: if nothing breaches its threshold, do nothing at all. No Slack message, no Linear issue, no all clear, no summary of what you checked. An everything is fine message every morning trains people to ignore the channel, which defeats the entire point. Silence means healthy, and an alert should always mean something needs attention.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them