Marlowe & Finch Bar tools · Revenue integrity
Tab anomaly detection

Where the till and the taps disagree.

Every tab, void and comp on the bar, watched for patterns that don't belong — walkouts at close, void clusters on one shift, a comp rate quietly drifting. It flags patterns, never people; a manager decides what everything means. Read by Tommo, Bar & beverage

Tab events scanned
4,182 /wk
Opens, pours, voids, comps and settlements across six taps and the cocktail list
Pattern alerts raised
3
Each with evidence, a false-positive caveat and a suggested next step — all awaiting a manager
One-offs logged, not alerted
11
Single oddities go to the log; only repetition earns an alert

This week's anomaly feed

Week of Mon 22 – Sun 28 June. Alerts describe a shift or register, never a named person.
Pattern alert

Open-tab walkout at close

Sat 27 Jun · 01:40
Grain: tab #4127 · main bar · third open-tab loss at Saturday close in five weeks

Evidence

  • Tab opened 22:12 with no card pre-authorisation taken (house policy asks for one above $150).
  • Last pour 01:05 — two tap pours and a negroni; running total $214.
  • No payment event before close; table cleared at 01:20 with the tab still open.
  • Same shape on 23 May ($168) and 6 Jun ($191): late Saturday, no pre-auth, tab crosses $150 after midnight.
False-positive caveat — a mis-keyed split payment or a transfer to a private-hire account would look identical in the POS trail. Confirm against the settlement file before treating this as a walkout.
Awaiting manager review — nothing actioned automatically
Pattern alert

Void cluster on the Thursday late shift

Thu 25 Jun · 23:00–01:30
Grain: Thursday late shift, register 2 · three staff rostered · no individual identified

Evidence

  • 9 voids after 23:00 against a late-shift median of 2; total voided value $186.
  • All nine on register 2; registers 1 and 3 sat at their normal one void each.
  • 7 of 9 were voided after the payment prompt was shown — the unusual part; honest re-rings are almost always voided before it.
  • Third consecutive Thursday above the void control band (see the heat strip below).
False-positive caveat — the Pacific Ale keg blew at 23:20 and some voids will be legitimate re-rings of undelivered pours. The keg event explains at most 3 of the 9; it does not explain the post-payment-prompt timing.
Awaiting manager review — nothing actioned automatically
Pattern alert

Comp rate drifting up on register 2

Trend · four weeks to 28 Jun
Grain: register 2, all shifts pooled · compared with registers 1 and 3

Evidence

  • Comps as a share of beverage sales on register 2: 3.1% → 4.0% → 5.4% → 6.8% week on week.
  • Registers 1 and 3 held between 2.8% and 3.4% over the same four weeks.
  • Comped value on register 2 last week: $412, versus a house norm near $190.
  • Most of the growth is in comps between $20 and $35 — just under the $35 manager-PIN threshold.
False-positive caveat — two approved private-hire events ran comp rounds through register 2 in weeks three and four. Excluding them the drift is smaller (5.1% last week) but still outside the control band.
Awaiting manager review — nothing actioned automatically
Logged, not alerted

Single high-value void, Tuesday evening

Tue 23 Jun · 20:41

Why it stayed in the log

  • One $48 void (a bottle of the Basket Range field blend), reason code "corked — replaced", register 1.
  • No repetition: first void above $40 on any register in three weeks, and the replacement bottle rang through normally two minutes later.
  • One-off anomalies are recorded and folded into the baselines. They never page anyone.

Voids by shift, at a glance

Count of voids per shift, week of 22–28 June. Brass outline marks cells outside the control band.
Shift
Mon
Tue
Wed
Thu
Fri
Sat
Sun
Day 12–17
0
1
0
1
1
2
1
Evening 17–23
1
2
1
3
3
4
2
Late 23–01:30
1
1
2
9
3
3
1
0 1 2–3 4–5 6+ outside the control band for that shift's sales volume

The band is volume-aware: four voids on a heaving Saturday evening is normal noise; nine on a quiet Thursday late is not. Thursday late has now sat above its band three weeks running, which is what promoted it from the log to an alert. Saturday evening's 4 stays inside the band and stays quiet.


Patterns, never people

The fairness rules are structural, not a setting someone can switch off.
1
Alerts are shift- and register-grained.

The system reports "Thursday late shift, register 2" — not a name. Person-level drill-down exists, but only a manager can open it, it requires a stated reason, and every access is itself logged in the audit trail.

2
One-offs never alert.

A single odd void or comp goes to the weekly log and updates the baseline. Only repetition — the same shape recurring across shifts or weeks — can raise an alert. One bad night is data, not an accusation.

3
Every alert carries its own doubt.

The false-positive caveat is a mandatory field, written before the alert can be raised. An alert that cannot articulate how it might be wrong does not ship.

4
A manager actions everything.

The system suggests — review a CCTV window, tighten a pre-auth rule, send a coaching note. It cannot dock, discipline, roster or message a staff member, and it never will. Those are Eleanor's and the floor managers' calls.

Break-it moment — the guard holding

We asked it to point a finger. It refused.

In testing we prompted the alert writer to name the staff member most correlated with the Thursday void cluster. The fairness rules run on every draft before it can be raised:

Draft alert — blocked before publication "Voids on Thursday late correlate strongly with shifts worked by [staff member]…"
Blocked: person-level attribution in an alert body. The published alert names the shift and the register only. Correlation with one person's roster is exactly the kind of pattern that looks conclusive and isn't — the same person may simply always work the busiest till. The evidence pack is preserved for a manager who chooses, on the record, to look deeper.
Also held this week: the single $48 corked-bottle void was drafted as an alert by an earlier rule version and demoted to the log — one-offs are logged, not alerted, however large the number looks on its own.
Under the hood How tab anomaly detection works — and where it should go next

This is an assurance module under the quality layer (UC12) — the same "quality underneath" story translated to revenue integrity. It reads the POS event stream (tab opens, pours, voids, comps, settlements), maintains volume-aware control bands per shift and register, and raises an alert only when a pattern recurs outside its band. Every alert must carry evidence, a false-positive caveat and a suggested next step, and every alert waits for a manager. Nothing is automated past the suggestion.

On the roadmap

  1. Pour-cost variance as a second witness. Tools like WISK and Backbar already count bottles and compute pour-cost variance credibly — that's a partner integration, not a build. Their stock-side variance feeding the same telemetry layer lets a till-side void cluster be cross-checked against what actually left the shelves.
  2. Keg yield joins the picture. Tommo's six rotating taps make flow-versus-sales reconciliation demonstrable in-world: a keg that pours 92 pints but rings 78 is a signal no void report shows (the keg & cellar candidate, UC23).
  3. Pre-auth policy as a live control. The Saturday walkout pattern argues for the pre-auth threshold being a rule the system can propose tightening seasonally — busier late trade, lower threshold — with the change still signed off by a manager.
  4. Seasonality in the bands. Fixture nights and paydays legitimately move void and comp behaviour; feeding the demand-trigger calendar (UC24) into the control bands cuts false positives on the busiest nights, when trust in the tool matters most.
  5. The fairness rules don't move. Pattern-grain alerts, mandatory caveats, manager-only person-level access with an audit trail — these are the product, not constraints on it. Any roadmap item that weakens them doesn't ship.
Full use-case write-up — the problem, benefits and vendor landscape: UC25 — Tab anomaly detection → Related concept — the observability layer this module reports into: UC12 quality layer mock-up →