Trace homepage showing the Kanto region map and ranked anomalous agents

Trace homepage showing the Kanto region map and ranked anomalous agents

Region overview — Kanto region, full agent population

The "cold start" view: all 300 flagged agents plotted across the Kanto region, colored/filtered by anomaly score (≥0.96 filter shown top-right). Demonstrates the tool scaling from "one pin" up to the full population at a glance, with density naturally clustering around real population centers (Tokyo/Yokohama).

Trace demo: agent selection

Trace demo: agent selection

Agent card popup on the homescreen map (Agent 823414)

The entry point of the whole workflow — an analyst scanning the region map hovers/clicks a flagged pin without leaving the map. The popup shows identity (Agent #1 · 823414 · Resident), a HIGH · 100 severity badge, and the Top Factors driving that score (Anomalous stays, Unusual movement pattern, Unusual visit sequence) — a named reason, not just a number — plus one-click paths into the full workspace or detailed analysis.

Trace demo: agent directory

Trace demo: agent directory

Agent Roster grid view

The alternate, scan-friendly way to browse the same 300-agent population — a searchable, filterable card grid (by class: Resident/Commuter/Tourist) instead of the map. Shows the tool supports both spatial and tabular investigation entry points depending on how the analyst thinks.

Trace demo: agent overview and anomaly factors

Trace demo: agent overview and anomaly factors

Agent Analysis — full factor breakdown (Agent 823414)

The deep-dive version of the agent card: a plain-language "Why Flagged" summary, a Ground Truth confirmation panel (validating the model's flag against injected simulation anomalies), a full 5-factor score breakdown with explanations per factor, and the complete stay-by-stay record on the right. This is where "high score" becomes a fully defensible, auditable explanation.

Trace demo: movement map

Trace demo: movement map

Workspace — Map view with Investigate panel

The main workspace for a selected agent: full route history on the map (dotted lines/all recorded stays), the agent's key stats (230 recorded stays, avg trip, peak stay score), and the four-tool Investigate navigator (Similar Agents, Stay Overlap, POI History, Pair Evidence) — the hub all the other tools branch from.

Trace demo: similar agents

Trace demo: similar agents

Similar Agents tool — routine similarity results

Answers "who else moves like this agent?" Shown mid-use: Day Type/Time filters and a ranked list of candidate agents by Routine Similarity %, each with a specific stat ("53 of 241 stays within 150m of the primary agent's stays") and a direct link into Pair Evidence — turning a vague "similar behavior" question into a concrete, filterable match list.

Trace demo: investigation details

Trace demo: investigation details

Stay Overlap tool — suggested visits

Answers "was anyone else here at this time?" without requiring the analyst to pick a stay manually first — it proactively suggests the agent's visits most likely to have co-located visitors (40 suggested visits shown), each pre-labeled with a visitor count, under the Same Time / Same Day / All History filter set.

Trace demo: location match results

Trace demo: location match results

POI History tool — shared places inventory

Answers "which of this agent's places are shared with others, historically?" A full inventory of the agent's visited POIs (14 of 24 scanned shown shared), each with a total historical visitor count — giving context (is this a busy train station or a quiet residence?) before jumping into a specific visitor list.

Trace demo: point-of-interest comparison

Trace demo: point-of-interest comparison

Pair Evidence — "why are these agents connected" (map + detail, SAME POI/SAME TIME)

The payoff view after selecting a candidate: both agents' full routes on the map (solid blue = A, dashed orange = B), the shared stay pinpointed with an exact distance ("12 M apart") and time gap, and a structured side panel listing every matching stay pair with POI IDs, timestamps, and stay IDs — concrete, inspectable evidence rather than a similarity score alone.

Trace demo: spatial comparison

Trace demo: spatial comparison

Pair Evidence — grid-cell match (zoomed map with grid overlay)

A different match type than #9: here the two agents' stays fall in the same grid cell but not the identical POI — the map draws the shared grid-cell boundary (labeled "113N-76E") around both nearby markers, visually distinguishing "same neighborhood" from "same exact spot."

Trace demo: agent pair details

Trace demo: agent pair details

Pair Evidence — SAME GRID / SAME TIME filter state

Shows the filter controls themselves: Location Match (Same Grid vs. Same POI) and Time Match (Other/Same Time/Same Day) toggles, with the matching-stays list updating live beneath — the mechanism that lets an analyst narrow "how specific is this overlap, really" from broad area down to exact location and timing.

Trace demo: daily timeline

Trace demo: daily timeline

Timeline tool — monthly stay-location view

This agent's full daily record as stacked columns (each color = a distinct stay location), with two flagged days outlined in red/pink where the normal pattern breaks — a single unfamiliar-colored block replacing the usual routine. The ranked sidebar on the right shows total dwell time per location, confirming which stay is actually "home" (91%) versus the anomaly.

Trace demo: activity log

Trace demo: activity log

Activity Log — chronological event narrative

The most granular record: a stay-by-stay, timestamped narrative log ("Agent remained here (residential) before the next recorded movement... 8h 55m, DEPARTED 23:55") with a day-summary panel and a jump-to index — for when an analyst needs the literal sequence of events rather than a visual summary.

Trace demo: agent comparison

Trace demo: agent comparison

Agent Comparison — Score Drivers panel

The explanatory layer behind a side-by-side comparison: plain-language summaries of what's driving each agent's score ("Agent 823414 has 4 driving signals, led by Anomalous stays... Agent 1126926 has one driving signal..."), followed by a factor-by-factor bar comparison (A vs. B, 0–1 scale) with a computed gap size — letting an analyst see not just that two scores differ, but exactly which behavioral signal explains the difference.

  • accessinternal demo
  • rolefull-stack engineer
  • data~200M stays
  • stackReact + PostGIS

03 / MOVEMENT-PATTERN ANALYSIS

Trace

Turning the Novateur team’s HAYSTAC simulation and anomaly data into a workspace analysts can investigate.

> PROJECT SUMMARY

The team at Novateur Research Solutions uses LLMs to simulate millions of agents for the HAYSTAC project and builds a geospatial anomaly system to identify which agents behave unusually. Trace is the application that makes those results available for investigation.

My role is to help design and build an app that presents the team’s data clearly, with tools analysts can use to assess whether an agent’s behavior is anomalous. Rankings, score explanations, maps, timelines and agent comparisons connect the system’s findings to the evidence behind them.

This is my ongoing work at Novateur. The screenshots show the internal demo; there is no public live site.

Internal work project · Demo screenshots · No public live site

The story

  • DESIGN
  • FRONT-END
  • FULL-STACK

The Novateur team’s HAYSTAC work produces simulated agent behavior and geospatial anomaly results at large scale. Trace gives analysts a way to explore that information. I help design and build the application and its investigation tools, connecting the team’s data to a clear workflow for examining an agent’s behavior.

  1. 01PURPOSEMake the team’s HAYSTAC anomaly results accessible to analysts. jumpDESIGN
  2. 02WORKFLOWMove from the most anomalous agents to the evidence behind their behavior. jumpDESIGN
  3. 03SYSTEMConnect the team’s simulation and geospatial results to the application. jumpFULL-STACK
  4. 04INTERFACEDesign maps, timelines and comparisons for analyst investigation. jumpFRONT-END
  5. 05CONTRIBUTIONHelp analysts assess whether an agent’s behavior is anomalous. jumpFULL-STACK

The problem

  • DESIGN

Problem statement

The HAYSTAC system identifies unusual behavior across millions of simulated agents. Analysts need more than a ranking: they need a clear way to inspect the underlying data and assess whether an agent’s behavior is anomalous.

User needs

  • Find the highest-ranked anomalous agents and understand why the system flagged them.
  • Distinguish an exact shared location from being in the same general area.
  • Inspect when and how often agents were near each other through maps and timelines.
  • Compare two agents’ histories without losing the pair already selected.

Architecture

  • FULL-STACK

Trace presents data from the Novateur team’s HAYSTAC simulation and geospatial anomaly system. My application work connects rankings, score explanations and movement histories through a React interface, with Flask APIs and PostgreSQL/PostGIS supporting the investigation tools. The data includes approximately 200 million stay records; the analysis cohort described here contains 300 agents.

  1. Team’s HAYSTAC data

    simulation + anomaly results

  2. Spatial analysis

    PostgreSQL + PostGIS

  3. Application API

    Flask + SQLAlchemy

  4. Analyst workspace

    React + Leaflet

Connect team data to analyst tools

The Novateur team produces simulated movement data and anomaly results. The application brings those outputs into views analysts can explore, from a ranked list to an individual agent’s locations and activity history. My work spans the interface and the supporting data access needed for that investigation.

Support investigation at different scales

An analyst can start with the analysis group, focus on one agent, then compare a pair. Spatial queries support questions about shared locations and nearby activity, while the app makes the distinction between exact co-location and proximity clear.

Keep the evidence behind the ranking accessible

Anomaly scores guide attention, and factor explanations show why an agent stands out. Location and time views give analysts the context to examine those findings and decide whether the behavior warrants further investigation.

Workflow

  • DESIGN
  • FRONT-END

The core user path in 4 steps.

  1. Triage the ranked agents

    Scan anomaly scores and inspect the behavioral factors behind a result before deciding what to investigate.

  2. Read the movement history

    Open an agent on the map and daily timeline to see where recorded stays occurred and when.

  3. Inspect a possible connection

    Review matching agents and distinguish an exact point-of-interest match from a shared grid area.

  4. Confirm and compare the pair

    Carry the selected pair into a confirmation flow, change either side only when needed, and compare histories to corroborate or rule out a connection.

See Trace in action

  • DESIGN
  • FRONT-END

Watch Trace in use as the walkthrough explains the application and its investigation tools. See how the team’s HAYSTAC data becomes an interactive workspace for exploring agent behavior.

Trace / Demo walkthroughPAUSED
0:00 / --:--
Investor demo prepared by a colleague at Novateur Research Solutions.

Investigation use cases

  1. Homescreen → Anomaly

    Start without a preselected agent. Find an unusual pin on the region map, inspect its score and open the agent card to see the factor behind it.

    Map → Agent card → Workspace map → Timeline. The map shows a stay outside the usual location cluster; the timeline shows activity outside the agent’s usual rhythm. These views give the analyst spatial and temporal evidence for the same lead.

  2. Stay Overlap & POI History

    After identifying an unusual stay, ask who else was there and whether that place is normally busy.

    Stay Overlap → POI History. Overlap results distinguish SAME TIME, SAME DAY and HISTORICAL visits. Place history supplies context: two visitors at a quiet residence mean something different from two visitors at a busy train station.

  3. Similar Agents → Pair Evidence

    Investigate whether the lead extends beyond one stay by looking for agents with overlapping movement histories, rather than similar anomaly scores.

    Similar Agents → Routine filters → Pair Evidence. Movement-overlap percentages and weekday filters help identify a candidate. Pair Evidence then lists coinciding stays across both histories, with location and time filters for inspecting the possible connection.

  4. Pair Evidence — Location Modes

    Distinguish activity in the same general area from stays assigned to the exact same place.

    SAME GRID → SAME POI. Grid matches indicate a shared neighborhood; POI matches narrow the evidence to an exact location. Analysts can also start from a map stay with “Find Other Agents Here,” then follow Stay Overlap into the same Pair Evidence workflow.

Interface

  • DESIGN
  • FRONT-END

Screens with design decisions pinned beside them.

Agent selection
Agent directory
Agent overview and anomaly factors
Movement map
Similar agents
Investigation details
Location match results
Point-of-interest comparison
Spatial comparison
Agent pair details
Daily timeline
Activity log
Agent comparison

A connected investigation workspace

The app connects rankings, maps, timelines and comparisons around the agent being investigated. Analysts can follow a lead across these tools while keeping the same context, moving from an overview to the evidence behind a result.

Make spatial evidence understandable

Maps explain where behavior occurred; timelines explain when it happened; comparisons show how two agents relate. Together, these views help analysts assess the system’s anomaly findings rather than relying on a score alone.

Stack

  • FRONT-END
  • FULL-STACK
LAYERTOOLWHY
InterfaceReact + TypeScript + ViteConnected views and shared selection state across investigation tools.
MappingLeaflet / react-leafletMovement routes, spatial matches and contextual map annotations.
APIPython / Flask + SQLAlchemyExpose agent histories, comparison data and matching results.
Spatial dataPostgreSQL + PostGISQuery stays and location relationships at large table scale.
Data repairResumable chunked migrationsCorrect historical records with recoverable progress and database verification.

Outcomes

  • DESIGN
  • FRONT-END
  • FULL-STACK
  • Analysts can review location matches based on corrected historical coordinates.
  • Exact shared locations and general-area matches have distinct meanings on the map.
  • Score breakdowns show which behavioral factors make an agent stand out.
  • A selected agent pair carries from the map into comparison, without starting the selection again.
  • A focused daily timeline gives analysts fewer unused views to navigate during an investigation.
NEXT 01 / CLOUD STORAGEmangobyte.md[ OPEN ]