- accessinternal demo
- rolefull-stack engineer
- data~200M stays
- stackReact + PostGIS
03 / MOVEMENT-PATTERN ANALYSIS
Trace
Turning the Novateur team’s HAYSTAC simulation and anomaly data into a workspace analysts can investigate.
> PROJECT SUMMARY
The team at Novateur Research Solutions uses LLMs to simulate millions of agents for the HAYSTAC project and builds a geospatial anomaly system to identify which agents behave unusually. Trace is the application that makes those results available for investigation.
My role is to help design and build an app that presents the team’s data clearly, with tools analysts can use to assess whether an agent’s behavior is anomalous. Rankings, score explanations, maps, timelines and agent comparisons connect the system’s findings to the evidence behind them.
This is my ongoing work at Novateur. The screenshots show the internal demo; there is no public live site.
Internal work project · Demo screenshots · No public live site
The story
The Novateur team’s HAYSTAC work produces simulated agent behavior and geospatial anomaly results at large scale. Trace gives analysts a way to explore that information. I help design and build the application and its investigation tools, connecting the team’s data to a clear workflow for examining an agent’s behavior.
- 01PURPOSEMake the team’s HAYSTAC anomaly results accessible to analysts. jumpDESIGN
- 02WORKFLOWMove from the most anomalous agents to the evidence behind their behavior. jumpDESIGN
- 03SYSTEMConnect the team’s simulation and geospatial results to the application. jumpFULL-STACK
- 04INTERFACEDesign maps, timelines and comparisons for analyst investigation. jumpFRONT-END
- 05CONTRIBUTIONHelp analysts assess whether an agent’s behavior is anomalous. jumpFULL-STACK
The problem
Problem statement
The HAYSTAC system identifies unusual behavior across millions of simulated agents. Analysts need more than a ranking: they need a clear way to inspect the underlying data and assess whether an agent’s behavior is anomalous.
User needs
- Find the highest-ranked anomalous agents and understand why the system flagged them.
- Distinguish an exact shared location from being in the same general area.
- Inspect when and how often agents were near each other through maps and timelines.
- Compare two agents’ histories without losing the pair already selected.
Architecture
Trace presents data from the Novateur team’s HAYSTAC simulation and geospatial anomaly system. My application work connects rankings, score explanations and movement histories through a React interface, with Flask APIs and PostgreSQL/PostGIS supporting the investigation tools. The data includes approximately 200 million stay records; the analysis cohort described here contains 300 agents.
Team’s HAYSTAC data
simulation + anomaly results
Spatial analysis
PostgreSQL + PostGIS
Application API
Flask + SQLAlchemy
Analyst workspace
React + Leaflet
Connect team data to analyst tools
The Novateur team produces simulated movement data and anomaly results. The application brings those outputs into views analysts can explore, from a ranked list to an individual agent’s locations and activity history. My work spans the interface and the supporting data access needed for that investigation.
Support investigation at different scales
An analyst can start with the analysis group, focus on one agent, then compare a pair. Spatial queries support questions about shared locations and nearby activity, while the app makes the distinction between exact co-location and proximity clear.
Keep the evidence behind the ranking accessible
Anomaly scores guide attention, and factor explanations show why an agent stands out. Location and time views give analysts the context to examine those findings and decide whether the behavior warrants further investigation.
Workflow
The core user path in 4 steps.
Triage the ranked agents
Scan anomaly scores and inspect the behavioral factors behind a result before deciding what to investigate.
Read the movement history
Open an agent on the map and daily timeline to see where recorded stays occurred and when.
Inspect a possible connection
Review matching agents and distinguish an exact point-of-interest match from a shared grid area.
Confirm and compare the pair
Carry the selected pair into a confirmation flow, change either side only when needed, and compare histories to corroborate or rule out a connection.
See Trace in action
Watch Trace in use as the walkthrough explains the application and its investigation tools. See how the team’s HAYSTAC data becomes an interactive workspace for exploring agent behavior.
Investigation use cases
Homescreen → Anomaly
Start without a preselected agent. Find an unusual pin on the region map, inspect its score and open the agent card to see the factor behind it.
Map → Agent card → Workspace map → Timeline. The map shows a stay outside the usual location cluster; the timeline shows activity outside the agent’s usual rhythm. These views give the analyst spatial and temporal evidence for the same lead.
Stay Overlap & POI History
After identifying an unusual stay, ask who else was there and whether that place is normally busy.
Stay Overlap → POI History. Overlap results distinguish SAME TIME, SAME DAY and HISTORICAL visits. Place history supplies context: two visitors at a quiet residence mean something different from two visitors at a busy train station.
Similar Agents → Pair Evidence
Investigate whether the lead extends beyond one stay by looking for agents with overlapping movement histories, rather than similar anomaly scores.
Similar Agents → Routine filters → Pair Evidence. Movement-overlap percentages and weekday filters help identify a candidate. Pair Evidence then lists coinciding stays across both histories, with location and time filters for inspecting the possible connection.
Pair Evidence — Location Modes
Distinguish activity in the same general area from stays assigned to the exact same place.
SAME GRID → SAME POI. Grid matches indicate a shared neighborhood; POI matches narrow the evidence to an exact location. Analysts can also start from a map stay with “Find Other Agents Here,” then follow Stay Overlap into the same Pair Evidence workflow.
Interface
Screens with design decisions pinned beside them.
A connected investigation workspace
The app connects rankings, maps, timelines and comparisons around the agent being investigated. Analysts can follow a lead across these tools while keeping the same context, moving from an overview to the evidence behind a result.
Make spatial evidence understandable
Maps explain where behavior occurred; timelines explain when it happened; comparisons show how two agents relate. Together, these views help analysts assess the system’s anomaly findings rather than relying on a score alone.
Stack
| LAYER | TOOL | WHY |
|---|---|---|
| Interface | React + TypeScript + Vite | Connected views and shared selection state across investigation tools. |
| Mapping | Leaflet / react-leaflet | Movement routes, spatial matches and contextual map annotations. |
| API | Python / Flask + SQLAlchemy | Expose agent histories, comparison data and matching results. |
| Spatial data | PostgreSQL + PostGIS | Query stays and location relationships at large table scale. |
| Data repair | Resumable chunked migrations | Correct historical records with recoverable progress and database verification. |
Outcomes
- Analysts can review location matches based on corrected historical coordinates.
- Exact shared locations and general-area matches have distinct meanings on the map.
- Score breakdowns show which behavioral factors make an agent stand out.
- A selected agent pair carries from the map into comparison, without starting the selection again.
- A focused daily timeline gives analysts fewer unused views to navigate during an investigation.