a change needs a release
By the time the rule ships, the pattern moved.
Transaction alerts scored, branched and routed by rules you draw yourself. Amount, channel, direction, country and customer risk are all fields you can condition on.
A threshold set for last year’s volume is a noise generator this year. The problem is not that rules are wrong, it is that changing one means a ticket, a release and a week.
By the time the rule ships, the pattern moved.
Nobody wants to tune a live rule, so nobody tunes it.
Two systems reach two verdicts about the same customer on the same day.
The alert carries score, amount, direction, channel, country and the customer’s risk level.
It weighs the transaction against the customer’s own baseline, not an industry average.
Branch on amount, channel or country. Set a status, convert to case, or fire a webhook to your own system.
Leave it in dry run and read what it would have done across a week of real traffic.
The same canvas, conditioned on transaction fields instead. Leave it in dry run and read what it would have done.
Drag a trigger, a condition and an action onto the canvas. No scripting, no deploy.
Confidence score, match status, risk level, entity type, amount, channel, article count and more.
Equals, greater than, between, in, is true and the rest, so a rule reads like a sentence.
Close, set status, set risk, assign, tag, note, notify, convert to case, webhook, toggle monitoring.
One canvas can hold several outcomes: close the clear ones, route the rest, escalate the few.
Run the rule against live traffic without touching a single case, then read what it would have done.
An agent that acts without a trail is a finding waiting to happen. Each execution writes what it saw, what it decided and what it changed.
Only where you let it. Every action is a node you place yourself, and you can leave a rule in dry run indefinitely.
Confidence is a number you can branch on. Most teams auto-close above a high threshold, route the middle band to an operator and escalate the rest.
Every execution writes a log entry: which rule, which node, what it saw, what it changed, and whether it applied, simulated, skipped or failed.
Set the rule to draft and it stops immediately. The log stays, so an auditor can still read what happened while it was on.
Bring a sample file. We will draw one rule, simulate it and show you the alert volume it removes.